Cisco Systems Servers Manuale Utente

Pagina di 654
5-3
Cisco Secure ACS 3.0 for Windows 2000/NT Servers User Guide
78-13751-01, Version 3.0
Chapter 5      Setting Up and Managing Shared Profile Components
Downloadable PIX ACLs
ACLs entered into the Cisco Secure ACS are protected by whatever backup or 
replication regime you have established for the Cisco Secure ACS. After you 
configure an ACL as a named shared profile component, you can include that 
ACL in any Cisco Secure ACS user, or user group, profile. When 
Cisco Secure ACS returns an attribute with a named ACL as part of a user’s 
session RADIUS access accept packet, the PIX Firewall applies that ACL to that 
user’s session. Cisco Secure ACS employs a versioning stamp for ensuring that 
the PIX Firewall has cached the latest ACL version. If a PIX Firewall responds 
that it does not have the current version of the named ACL in its cache (that is, 
the ACL is new or has changed), Cisco Secure ACS automatically uploads the 
ACL update to the PIX Firewall cache.
After you configure a downloadable PIX ACL, it can be applied against any 
number of single users or user groups.
Downloadable PIX ACL Configuration
This section contains the following procedures:
Adding a Downloadable PIX ACL
To add a downloadable PIX ACL, follow these steps:
Step 1
In the navigation bar, click Shared Profile Components.
Result: The Shared Profile Components page appears.
Step 2
Click Downloadable PIX ACLs.
Step 3
Click Add.
Result: The Downloadable PIX ACLs page appears.
Step 4
In the Name: box, type the name of the new PIX ACL.