Configure advanced AAA settings

Configure advanced AAA settings to customize authentication behavior and improve password management for remote access VPN users.

Before you begin

  1. Configure the protocols and devices, and the connection profile for a remote access VPN policy as described in Configure a remote access VPN policy.

  2. Configure the authentication method, and the AAA servers as described in Configure AAA settings for a remote access VPN policy.

Procedure


Step 1

Click the edit icon next to the remote access VPN policy.

Step 2

Click the edit icon next to the connection profile.

Step 3

Click the AAA tab.

Step 4

In Advanced Settings, configure these parameters:

  • (Optional) Check the Strip Realm from username check box to remove the realm from the username before sending it to the AAA server for authentication. By default, this feature is disabled.

    If you select this option and provide a username in the domain\username format, the AAA server receives only the username.

  • (Optional) Check the Strip Group from username check box to remove the group name from the username before sending it to the AAA server for authentication. By default, this feature is disabled.

    Note
    A realm is an administrative domain used to manage authentication. When you enable these options, users can authenticate using only their username. You can select any of these options. If your server does not support delimiter parsing, enable both check boxes to ensure authentication.
  • Check the Enable Password Management check box to configure the notification settings for the remote access VPN users about password expiry. Configure one of these options:

    • In the Notify User – days ahead of password expiry field, enter the number of days for password expiry notification.

    • Select Notify user on the day of password expiration.

Step 5

Click Save.