<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local AAA server configuration for https authentication prox in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260069#M367332</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You probably did not understand that i want to use the authentication proxy feature.I dont want to use lock-and-key.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Nov 2009 13:22:47 GMT</pubDate>
    <dc:creator>k.protopapas</dc:creator>
    <dc:date>2009-11-25T13:22:47Z</dc:date>
    <item>
      <title>Local AAA server configuration for https authentication proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260067#M367251</link>
      <description>&lt;P&gt;I have the following scenario:I require to set up a transparent firewall using a Cisco 1841 router with 2 Fast Ethernet interfaces with IOS version 12.4(15)T9 Advanced Security.The project also calls for authenticating users using the ip auth-proxy feature.The users should use https to connect to an internal server.The IP addresses of the users are dynamic (i.e. they may authenticate from the Internet).I have set up successfully the ip auth-proxy feature using an external ACS server using TACACS+.However, i want to use the AAA local server feature in order to implement this project instead of using an external AAA server.&lt;/P&gt;&lt;P&gt;The question is how to configure the local AAA attributes in order to have the same functionality as when using an external AAA server(i.e dynamic proxy ACL entries permitting specific IP addresses and protocols) without using one(i.e using only the local AAA server feature of Cisco IOS).&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260067#M367251</guid>
      <dc:creator>k.protopapas</dc:creator>
      <dc:date>2019-03-10T23:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Local AAA server configuration for https authentication prox</title>
      <link>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260068#M367277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AFAIK, the auth-proxy feature is only supported using an external AAA. If you need to use the local dat&lt;/P&gt;&lt;P&gt;abase, you have to look at the lock-n-key feature, please see these links:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_cfg_authen_prxy.html#wp1054354"&gt;http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_cfg_authen_prxy.html#wp1054354&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_lock_key_secrty_ps6350_TSD_Products_Configuration_Guide_Chapter.html"&gt;http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_lock_key_secrty_ps6350_TSD_Products_Configuration_Guide_Chapter.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Nov 2009 13:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260068#M367277</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-11-25T13:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Local AAA server configuration for https authentication prox</title>
      <link>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260069#M367332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You probably did not understand that i want to use the authentication proxy feature.I dont want to use lock-and-key.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Nov 2009 13:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260069#M367332</guid>
      <dc:creator>k.protopapas</dc:creator>
      <dc:date>2009-11-25T13:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Local AAA server configuration for https authentication prox</title>
      <link>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260070#M367362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out the table on the first link comparing auth-proxy and lock-n-key, it clearly states that local authentication is not supported with auth-proxy. this is from Cisco not me &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Nov 2009 17:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260070#M367362</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-11-27T17:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Local AAA server configuration for https authentication prox</title>
      <link>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260071#M367448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know about that.But Cisco also states that the Local AAA server can be used instead of an external AAA server.So,stop posting unless you have a solution to my problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Nov 2009 08:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-aaa-server-configuration-for-https-authentication-proxy/m-p/1260071#M367448</guid>
      <dc:creator>k.protopapas</dc:creator>
      <dc:date>2009-11-30T08:39:57Z</dc:date>
    </item>
  </channel>
</rss>

