<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cut-through proxy configuration issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cut-through-proxy-configuration-issue/m-p/1914538#M203618</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Nevermind, I've gotten this to work.&amp;nbsp; I switched from RADIUS to TACACS+, and then followed the directions here: &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-14695"&gt;https://supportforums.cisco.com/docs/DOC-14695&lt;/A&gt;.&amp;nbsp; I still had issues afterwards where the browser would say "Looking up INTERNALGATEWAY, then time out before loading the authentication prompt.&amp;nbsp; I ended up adding an A record to our DNS server named INTERNALGATEWAY with the IP address of our internal network interface, and now I get the authentication prompt.&amp;nbsp; Just wanted to post this here in case anyone else had this issue as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Mar 2012 15:56:41 GMT</pubDate>
    <dc:creator>DevinHill</dc:creator>
    <dc:date>2012-03-14T15:56:41Z</dc:date>
    <item>
      <title>Cut-through proxy configuration issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cut-through-proxy-configuration-issue/m-p/1914537#M203603</link>
      <description>&lt;P&gt;I am having issues setting up cut-through proxy on an ASA 5510 running version 8.4 (2).&amp;nbsp; All I'm trying to do is make it so user's have to log in to access external websites (both http and https), based on an Active Directory group called "InternetAccess".&amp;nbsp; If a user is in that group, they can access the internet, if they aren't they are blocked.&amp;nbsp; I've checked several links recommended in the support forums, but I can't seem to get this to work properly.&amp;nbsp; Also, I'm using a Windows Server 2008R2 RADIUS server for authenticatiom, via the Windows Network Policy and Access Services.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far, here is what I've tried.&lt;BR /&gt;-Configured a RADIUS server group on the ASA.&lt;BR /&gt;-Added the IP address to the radius server.&lt;BR /&gt;-Tested Authentication via the Test button is ASDM and entered my Active Directory credentials.&amp;nbsp; The test is successful.&amp;nbsp; The Authorization test fails.&lt;BR /&gt;-Configured the RADIUS server Connection Request Policy to allow the ASA as a client via friendly name.&lt;BR /&gt;-Configured the RADIUS server Network Policy to allow the "InternetAccess" group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA, typed the following commands:&lt;BR /&gt;access-list myauth permit tcp internalIPrange netmask any eq 80&lt;BR /&gt;access-list myauth permit tcp internalIPrange netmask any eq 443&lt;BR /&gt;aaa authentication match myauth inside RADIUSSERVERNAME&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After running these commands, HTTPS sites give an "invalid certificate error" and then the standard "Internet Explorer couldn't load this page" if you click through to ignore the certificate error.&amp;nbsp; HTTP sites just go straight to the "Internet Explorer couldn't load this page" error.&amp;nbsp; I'm never prompted for login information.&amp;nbsp; Is there something else I'm missing?&amp;nbsp; Should I be using the Cisco Active Directory agent at all?&amp;nbsp; There's a lot of information on this topic and quite honestly I'm a bit lost when it comes to confguring this.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cut-through-proxy-configuration-issue/m-p/1914537#M203603</guid>
      <dc:creator>DevinHill</dc:creator>
      <dc:date>2019-03-11T01:53:06Z</dc:date>
    </item>
    <item>
      <title>Cut-through proxy configuration issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cut-through-proxy-configuration-issue/m-p/1914538#M203618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Nevermind, I've gotten this to work.&amp;nbsp; I switched from RADIUS to TACACS+, and then followed the directions here: &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-14695"&gt;https://supportforums.cisco.com/docs/DOC-14695&lt;/A&gt;.&amp;nbsp; I still had issues afterwards where the browser would say "Looking up INTERNALGATEWAY, then time out before loading the authentication prompt.&amp;nbsp; I ended up adding an A record to our DNS server named INTERNALGATEWAY with the IP address of our internal network interface, and now I get the authentication prompt.&amp;nbsp; Just wanted to post this here in case anyone else had this issue as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2012 15:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cut-through-proxy-configuration-issue/m-p/1914538#M203618</guid>
      <dc:creator>DevinHill</dc:creator>
      <dc:date>2012-03-14T15:56:41Z</dc:date>
    </item>
  </channel>
</rss>

