<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Any type of agent/client that makes end users authenticate? in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211341#M601</link>
    <description>&lt;P&gt;We are using transparent domain authentication, so the user credentials are passed through to authenticate/log/report the end users web activity.  Problem is, we have a couple generic accounts on some of the multi-user PCs (500+ hosts) for our nurses to use, so that they don't have to windows login everyt time they need to document something, the PC is just left logged in (restricted and locked down, of course)&lt;BR /&gt;&lt;BR /&gt;We need to be able to report on those staff members though, and we can't remove internet access, and we can't force them to windows login as themself (corporate policy, they say it takes to long)  &lt;BR /&gt;&lt;BR /&gt;So, the question is, is there a software client that will prompt the generic machines to log into ironport when they try to access internet resources?  We still want to maintain the pass-thru authentication for everyone else, just make it prompt for the machines that are logged in as a generic user.  It would be WAY simpler to deploy a client software them manually reconfigure every one of those network ports to a separate VLAN/Subnet.&lt;BR /&gt;&lt;BR /&gt;Any other ways to make this happen?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for your good news  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2009 22:07:39 GMT</pubDate>
    <dc:creator>Jtruxton_ironport</dc:creator>
    <dc:date>2009-04-29T22:07:39Z</dc:date>
    <item>
      <title>Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211341#M601</link>
      <description>&lt;P&gt;We are using transparent domain authentication, so the user credentials are passed through to authenticate/log/report the end users web activity.  Problem is, we have a couple generic accounts on some of the multi-user PCs (500+ hosts) for our nurses to use, so that they don't have to windows login everyt time they need to document something, the PC is just left logged in (restricted and locked down, of course)&lt;BR /&gt;&lt;BR /&gt;We need to be able to report on those staff members though, and we can't remove internet access, and we can't force them to windows login as themself (corporate policy, they say it takes to long)  &lt;BR /&gt;&lt;BR /&gt;So, the question is, is there a software client that will prompt the generic machines to log into ironport when they try to access internet resources?  We still want to maintain the pass-thru authentication for everyone else, just make it prompt for the machines that are logged in as a generic user.  It would be WAY simpler to deploy a client software them manually reconfigure every one of those network ports to a separate VLAN/Subnet.&lt;BR /&gt;&lt;BR /&gt;Any other ways to make this happen?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for your good news  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2009 22:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211341#M601</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-04-29T22:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211342#M602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the WSA perspective, the only way to differentiate these shared computers vs. the regular users, is via subnet / IP. &lt;BR /&gt;&lt;BR /&gt;They wouldn't necessarily have to all be assigned to a new subnet, they'd just need static IPs.&lt;BR /&gt;&lt;BR /&gt;You can enter all of the IPs into a custom identity that uses basic credentials (NTLM basic or LDAP).&lt;BR /&gt;&lt;BR /&gt;There is no proxy client software that we can provide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2009 22:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211342#M602</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2009-04-30T22:52:21Z</dc:date>
    </item>
    <item>
      <title>Dang, i was afraid of that</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211343#M603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess we will set up a different VLAN for our regular users and then set our filters up.  Thank you for your reply...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2009 23:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211343#M603</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-04-30T23:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211344#M604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are very close to releasing the 6.0 version of the WSA code, which has a feature called "re-authentication" which may help in your case.  &lt;BR /&gt;&lt;BR /&gt;Basically, you set up the generic accounts that these workstations are logged into Windows as to have no web privileges.  With the new feature, the "block" page from the WSA will have a button the user can push to provide their authentication credentials directly in the browser.  We designed it in response to some of our other health care customers who have almost exactly your requirements.  Best part - no client software needed!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 May 2009 00:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211344#M604</guid>
      <dc:creator>David Paschich</dc:creator>
      <dc:date>2009-05-01T00:42:01Z</dc:date>
    </item>
    <item>
      <title>how close is very close?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211345#M605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like next month?  next 3 months?  it sounds perfect and no work on my part other than the upgrade, I think I can handle that   &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 May 2009 00:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211345#M605</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-05-01T00:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211346#M606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah! Yeah, the re-auth should work rather nicely in your case!&lt;BR /&gt;&lt;BR /&gt;6.0 is scheduled for release in, oh... 4 days, but don't quote me on that &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt; &lt;BR /&gt;&lt;BR /&gt;It's an unofficial ETA, but we expect it to be release in the very near near future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 May 2009 22:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211346#M606</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2009-05-01T22:09:19Z</dc:date>
    </item>
    <item>
      <title>Just downloaded it</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211347#M607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just acquired teh update, and I think this will work just fine  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  I will have to do some testing of course, but it looks perfect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2009 03:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211347#M607</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-05-06T03:37:17Z</dc:date>
    </item>
    <item>
      <title>works....but here is a question</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211348#M608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The button to reauthenticate is working very well, and we have our SSO working so it clicks that button and signs in for them.  &lt;BR /&gt;&lt;BR /&gt;Now, the question is, can we change the text on the notification page so that our nurses wont be confused where it says "This Page Cannot Be Displayed"&lt;BR /&gt;&lt;BR /&gt;Is there anyway to edit that page?  I believe it is automatically generated, I am thinking if there is a path to that template, i could maybe edit it directly?  &lt;BR /&gt;&lt;BR /&gt;OR, we could link to a custom page, but how would we get the reauthentication button?  Is there a direct link to call the login box?   It looks like the URL it calls is different everytime...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 May 2009 04:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211348#M608</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-05-14T04:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211349#M609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jtruxton,&lt;BR /&gt;&lt;BR /&gt;You can combine the custom EUN pages with re-authentication. Please see page 244 in the 6.0 User Guide for how to enable custom EUN pages. &lt;BR /&gt;&lt;BR /&gt;The values for enabling reauth in a custom page is %r and %R. Please see the code below for an example:&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;I can't seem to get this forum page to display code without messing it up...&lt;BR /&gt;&lt;/B&gt;&lt;BR /&gt;&lt;I&gt;If you send me an email to josh @@ ironport .. com I'll send you sample code which works.&lt;/I&gt;&lt;BR /&gt;&lt;BR /&gt;This will present a generic button for re-auth. Note that in order for this to be displayed, re-auth will need to be enabled from the authentication settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 May 2009 22:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211349#M609</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2009-05-18T22:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211350#M610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Josh, I sent you an email, i was reading the manual there but it didn't make much sense to me...  Hoping you can help with a snippet of code   &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 May 2009 00:40:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211350#M610</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-05-19T00:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211351#M611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Hi Josh, I sent you an email, i was reading the manual there but it didn't make much sense to me...  Hoping you can help with a snippet of code   &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;I'm sorry the WSA User Guide didn't help much. The piece of code Josh sent you will be included in the WSA User Guide for the next release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 May 2009 05:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211351#M611</guid>
      <dc:creator>JennieMorton</dc:creator>
      <dc:date>2009-05-21T05:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211352#M612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did not receive your email for some reason. Please try sending another one to me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 May 2009 22:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211352#M612</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2009-05-21T22:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211353#M613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Josh, not sure why that email didn't work..  Anyhow, I did get a reply to my case from a fellow name Madhura, and it detailed teh correct code snippet, I am putting it inot the page now to see if this will get it to work as we hope.  Thanks for all your time, I am optimistic that this will solve the issue we are having.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 May 2009 22:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211353#M613</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-05-21T22:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211354#M614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This solution worked, we are getting ready to deploy, thank you for your time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 May 2009 01:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211354#M614</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-05-27T01:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211355#M615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 May 2009 22:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211355#M615</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2009-05-27T22:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Any type of agent/client that makes end users authenticate?</title>
      <link>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211356#M616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, soooo......   I didn't care about this new twist personally, but the boss wanted to find out if this could be done.  The issue, when our end users click the button to reauthenticate for a website that we very specifically block (example:  facebook.com) it brings the login prompt back up, 4 times, before teh user gets the denied page.  Is there a way to limit how many times the user is prompted for differnt credentials?  I figure it might be based on the limit of failed attempts to the domain, but I could be wrong.   Anyhow... what do you think?  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 May 2009 02:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/any-type-of-agent-client-that-makes-end-users-authenticate/m-p/1211356#M616</guid>
      <dc:creator>Jtruxton_ironport</dc:creator>
      <dc:date>2009-05-29T02:41:43Z</dc:date>
    </item>
  </channel>
</rss>

