<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA server placement. Inside or DMZ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-server-placement-inside-or-dmz/m-p/17801#M1301</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a) OK, let's put it another way, would the designer put NT Primary Domian Controller on the DMZ? No, of course he wouldn't, because the DMZ is accessible by all, and the device holds secure information.&lt;/P&gt;&lt;P&gt;b) Not enough information to fully comment, but yes, but getting the pix involved in direct authentication is usually hard work. Although a simple filter rule allowing AAA traffic (tac\ radius) between the 3660 and the AAA server (which is on the internal LAN) should surfice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Oct 2001 00:09:39 GMT</pubDate>
    <dc:creator>p.jacques</dc:creator>
    <dc:date>2001-10-30T00:09:39Z</dc:date>
    <item>
      <title>AAA server placement. Inside or DMZ</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-placement-inside-or-dmz/m-p/17800#M1296</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry if this is has been discussed but if it has please just point me in the right direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assisting on a RAS install using SecureID tokens using a 3660 PRI and PIX 525. The current design places the AAA server in the DMZ with the 3660 and only controlling traffic on the 3660, i.e. allowing all traffic from the 3660 to the internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My issue is a) wouldn't it be more secure to place the AAA server on the inside network and b) wouldn't it be sensible to extend the AAA control to the PIX in case the 3660 is compromised.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am about to suggest this to the designer but I would really appreciate any feedback before i go stepping on any toes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ian Castleman&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-placement-inside-or-dmz/m-p/17800#M1296</guid>
      <dc:creator>castlei</dc:creator>
      <dc:date>2020-02-21T17:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server placement. Inside or DMZ</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-placement-inside-or-dmz/m-p/17801#M1301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a) OK, let's put it another way, would the designer put NT Primary Domian Controller on the DMZ? No, of course he wouldn't, because the DMZ is accessible by all, and the device holds secure information.&lt;/P&gt;&lt;P&gt;b) Not enough information to fully comment, but yes, but getting the pix involved in direct authentication is usually hard work. Although a simple filter rule allowing AAA traffic (tac\ radius) between the 3660 and the AAA server (which is on the internal LAN) should surfice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2001 00:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-placement-inside-or-dmz/m-p/17801#M1301</guid>
      <dc:creator>p.jacques</dc:creator>
      <dc:date>2001-10-30T00:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server placement. Inside or DMZ</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-placement-inside-or-dmz/m-p/17802#M1304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;WEll the suggested approach is a quite meaningfull one, you might face problems when you are extending the AAA capabiliteies to further do direct authentication for the PIX.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2001 09:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-placement-inside-or-dmz/m-p/17802#M1304</guid>
      <dc:creator>vipin</dc:creator>
      <dc:date>2001-10-30T09:38:46Z</dc:date>
    </item>
  </channel>
</rss>

