show aaa

Prev Next

Shows authentication, authorization, and accounting settings.

Syntax

show aaa

Parameters

None

Example

The following example displays the AAA settings and requires the user to log in to the Web UI using a client X.509 certificate:

hostname # show aaa
User session termination log-out message enabled: no

Authentication method(s):
   local

Authorization settings:
   Default User: monitor
   Map Order: remote-first
No accounting methods configured.

AAA authorization rules: Enabled
Number of AAA authorization rules: 0

Web UI client certificate-based authentication: required
Web UI client oidc-based authentication: disabled

Output fields

The following table describes the output fields for the show aaa command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

User session termination log-out message enabled

Whether the display of the log out message is enabled or disabled.

Authentication method(s)

Type of remote authentication method:

  • Local—The appliance authenticates users against the local username database.

  • RADIUS—The appliance authenticates users against a remote RADIUS security server.

  • TACACS+—The appliance authenticates users against a remote TACACS+ security server.

  • LDAP—The appliance authenticates users against a remote LDAP server.

Authorization settings

Default local user account that the user logs in to if the user does not have a local account and is authenticated by RADIUS, TACACS+, or Active Directory through LDAP. This field also displays the mapping behavior when authenticating users with a remote authentication server.

AAA authorization rules

Whether the authorization rules are enabled or disabled.

Number of AAA authorization rules

Number of new authorization rules that are created.

Web UI client certificate-based authentication

Policy settings of the Web UI for certificate authentication:

  • allowed—Users log in to the Web UI either using the user name and password provided by their administrator or using an optional client X.509 certificate for user authentication.

  • required—Users log in to the Web UI using a certificate when a client X.509 certificate is mandatory for user authentication.

  • disabled—Policy settings of the Web UI are disabled and do not accept a certificate.

Web UI client oidc-based authentication

Policy settings of the Web UI for single sign-on:

  • allowed—SSO login is optional.

  • disabled—SSO login is not accepted for authentication.

  • required—SSO login is mandatory for authentication.

User role

Admin, Operator, or Monitor

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Before release 6.4. The command output was enhanced to display the log out message setting in Release 8.2.

  • Central Management System: Before release 6.4. The command output was enhanced to display Web UI client certificate-based authentication field to support certificate authentication in Release 7.9.1. The command output was enhanced to display the log out message setting in Release 8.3.

  • Email Security — Server: Before release 6.4

  • File Protect: Before release 6.4. The command output was enhanced to display the log out message setting in Release 8.2.

  • Endpoint Security (HX): Release 2.5

  • Network Security: Before release 6.4. The command output was enhanced to display Web UI client certificate-based authentication field to support certificate authentication in Release 7.9.1. The command output was enhanced to display the log out message setting in Release 8.2.

  • Intelligent Virtual Execution - Server: Release 7.9. The command output was enhanced to display Web UI client certificate-based authentication field to support certificate authentication in Release 7.9.1. The command output was enhanced to display the log out message setting in Release 8.2.