<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Authentication Exclude in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-exclude/m-p/509239#M1569</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;  Use aaa authentication match "ACL" &lt;/P&gt;&lt;P&gt;In this match mathod you can deny all the traffic which you doen't require to authenticate. This is more controlable mathod.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mustafa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Sep 2006 07:04:42 GMT</pubDate>
    <dc:creator>mustafa_nbk</dc:creator>
    <dc:date>2006-09-06T07:04:42Z</dc:date>
    <item>
      <title>AAA Authentication Exclude</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-exclude/m-p/509237#M1566</link>
      <description>&lt;P&gt;I have enabled "aaa authentication exclude" commad statement on PIX (6.3).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This excludes the Hosts for which the Firewall doesnot prompt for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to add more lines into it.Do i have to remove all the commands and then all the old and new commands.I added one host in the list for exclution,but the PIX still prompts for username/password.&lt;/P&gt;&lt;P&gt;aaa authentication exclude https outside x.x.x.x 255.255.255.255 a.b.c.d 255.255.255.255 authserv&lt;/P&gt;&lt;P&gt;aaa authentication exclude http outside x.x.x.x 255.255.255.255 a.b.c.d 255.255.255.255 authserv&lt;/P&gt;&lt;P&gt;aaa authentication exclude tcp/25 1.1.1.1 255.255.255.255 192.168.25.1 255.255.255.255 authserv&lt;/P&gt;&lt;P&gt;aaa authentication exclude tcp/25 1.1.1.2 255.255.255.255 192.168.25.2 255.255.255.255 authserv&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-exclude/m-p/509237#M1566</guid>
      <dc:creator>rpsrekhi3</dc:creator>
      <dc:date>2020-02-21T18:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authentication Exclude</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-exclude/m-p/509238#M1568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Replace tcp/25 with tcp/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please review the tcp port. The pix does not support tcp/25 (smtp) specified in your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tcp/0 option enables authentication for all TCP traffic, which includes FTP, HTTP, HTTPS, and Telnet. When a specific port is specified, only the traffic with a matching destination port is included or excluded for authentication. Note that FTP, Telnet, HTTP, and HTTPS are equivalent to tcp/21, tcp/23, tcp/80, and tcp/443, respectively. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/ab.htm#wp1111727" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/ab.htm#wp1111727&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 12:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-exclude/m-p/509238#M1568</guid>
      <dc:creator>mpalardy</dc:creator>
      <dc:date>2006-08-17T12:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authentication Exclude</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-exclude/m-p/509239#M1569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;  Use aaa authentication match "ACL" &lt;/P&gt;&lt;P&gt;In this match mathod you can deny all the traffic which you doen't require to authenticate. This is more controlable mathod.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mustafa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2006 07:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-exclude/m-p/509239#M1569</guid>
      <dc:creator>mustafa_nbk</dc:creator>
      <dc:date>2006-09-06T07:04:42Z</dc:date>
    </item>
  </channel>
</rss>

