<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA CTP https direct auth in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-ctp-https-direct-auth/m-p/2949344#M38995</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I've configured the following to enable CTP on Cisco ASA (identity configuration was already in place),&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;aaa authentication listener https INSIDE port 5601&lt;BR /&gt;access-list INSIDE_authentication line 1 extended permit tcp host 10.15.196.129 host 10.0.1.129 eq 5601&lt;BR /&gt;aaa authentication match INSIDE_authentication INSIDE user-identity&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;It works but my concern relates to some commands that I do not understand what exactly serve, or if they can be useful to force authentication exclusively in https or encrypted which actually should already be guaranteed with "aaa authentication listener https". For instance redirect option in "aaa authentication listener command is it used to redirect in case INSIDE_authentication access-list contains other ip for which authentication is required ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Then from &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/access_fwaaa.html#66940" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/access_fwaaa.html#66940&lt;/A&gt; also aaa authentication secure-http-client ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks for your help&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:56:38 GMT</pubDate>
    <dc:creator>giuseppe parlato</dc:creator>
    <dc:date>2019-03-11T06:56:38Z</dc:date>
    <item>
      <title>ASA CTP https direct auth</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-ctp-https-direct-auth/m-p/2949344#M38995</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I've configured the following to enable CTP on Cisco ASA (identity configuration was already in place),&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;aaa authentication listener https INSIDE port 5601&lt;BR /&gt;access-list INSIDE_authentication line 1 extended permit tcp host 10.15.196.129 host 10.0.1.129 eq 5601&lt;BR /&gt;aaa authentication match INSIDE_authentication INSIDE user-identity&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;It works but my concern relates to some commands that I do not understand what exactly serve, or if they can be useful to force authentication exclusively in https or encrypted which actually should already be guaranteed with "aaa authentication listener https". For instance redirect option in "aaa authentication listener command is it used to redirect in case INSIDE_authentication access-list contains other ip for which authentication is required ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Then from &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/access_fwaaa.html#66940" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/access_fwaaa.html#66940&lt;/A&gt; also aaa authentication secure-http-client ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks for your help&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:56:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-ctp-https-direct-auth/m-p/2949344#M38995</guid>
      <dc:creator>giuseppe parlato</dc:creator>
      <dc:date>2019-03-11T06:56:38Z</dc:date>
    </item>
  </channel>
</rss>

