Specifications
Configuring per-User Configuration
Per-User Configuration Overview
DC-683
Cisco IOS Dial Technologies Configuration Guide
Supported Attributes for AV Pairs
Table 37 provides a partial list of the Cisco-specific supported attributes for AV pairs that can be used
for per-user virtual interface configuration. For complete lists of Cisco-specific, vendor-specific, and
TACACS+ supported attributes, see the Cisco IOS Security Configuration Guide and Cisco IOS Security
Command Reference.
Table 37 Partial List of Cisco-Specific Supported AV Pair Attributes
Attribute Meaning
inacl# An input access list definition. For IP, standard or extended access list syntax can
be used, although you cannot mix them within a single list. For Internet Protocol
Exchange (IPX), only extended syntax is recognized. The value of this attribute
is the text that comprises the body of a named access list definition.
outacl#
1
1. The “outacl” attribute still exists and retains its old meaning.
An output access list definition. For IP, standard or extended access list syntax
can be used. For IPX, only extended syntax is recognized. The value of this
attribute is the text that comprises the body of a named access list definition.
rte-fltr-in# An input route filter. For IP, standard or extended access list syntax can be used,
although you cannot mix them within a single list. For IPX, only extended syntax
is recognized. The first line of this filter must specify a routing process.
Subsequent lines comprise the body of a named access list.
rte-fltr-out# An output route filter. For IP, standard or extended access list syntax can be used,
although you cannot mix them within a single list. For IPX, only extended syntax
is recognized. The first line of this filter must specify a routing process.
Subsequent lines comprise the body of a named access list.
route#
2
2. The “route” attribute, without a trailing #, is still recognized for backward compatibility with the TACACS+ protocol
specification, but if multiple static routes are required in TACACS+, full “route#” names will need to be employed.
Static routes, for IP and IPX.
The value is text of the form destination-address mask [gateway].
sap# IPX static Service Advertising Protocol (SAP). The value is text from the body
of an ipx sap configuration command.
sap-fltr-in# IPX input SAP filter. Only extended access list syntax is recognized. The value
is text from the body of an extended IPX access-list configuration command.
(The Novell socket number for SAP filtering is 452.)
sap-fltr-out# IPX output SAP filter. Only extended access-list command syntax is recognized.
The value is text from the body of an extended IPX access-list configuration
command.
pool-def# An IP pool definition. The value is text from the body of an ip local pool
configuration command.
pool-timeout An IP pool definition. The body is an integer representing a timeout, in minutes.