本文转自:https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-extserver.html Chapter: Configure an External AAA Server for VPN Chapter Contents About External AAA ServersGuidelines For Using External AAA ServersConfigure Multiple Certificate AuthenticationConfigure LDAP Authorization for VPNActive Directory/LDAP VPN Remote Access Authorization Examples About External AAA Servers This ASA can be configured to use an external LDAP, RADIUS, or TACACS+ server to support Authentication, Authorization, and Accounting (AAA) for the ASA. The external AAA server enforces configured permissions and attributes. Before you configure the ASA to use an external server, you must configure the external AAA server with the correct ASA authorization attributes and, from a subset of these attributes, assign specific permissions to individual users. Understanding Policy Enforcement of Authorization Attributes Understanding Policy Enforc......Read More>