<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Simple IAS Authentication issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946661#M407324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi , i haven't read all the links  related to this post but here is a couple of hints , hope they can&lt;/P&gt;&lt;P&gt;help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;But the issue is that username&amp;amp;password pop-up. It supposed to pop-up when a client which &lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;is not joined to domain, or logged on locally not to domain. But it pops when the user is already logged&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;with domain credidentals. I dont want to type it again when trying to browse for the first time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure your browser is configure to pass the credentials;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IE6&lt;/P&gt;&lt;P&gt;Internet Options -Advanced -Security - Enable Integrated Windows Authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt;aaa authentication include tcp/0 inside 0.0.0.0 0.0.0.0 RADIUS-GROUP &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"reference cisco:  Although you can configure the security appliance to require authentication for network &lt;/P&gt;&lt;P&gt;access to any protocol or service, users can authenticate directly with HTTP, HTTPS, Telnet, or FTP only. &lt;/P&gt;&lt;P&gt;A user must first authenticate with one of these services before the security appliance allows other traffic &lt;/P&gt;&lt;P&gt;requiring authentication. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you have to make sure that your first request is either  http,https,telnet or ftp   to trigger the&lt;/P&gt;&lt;P&gt;authentication. If your DNS is outside your firewall ,  browsing  &lt;A class="jive-link-custom" href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;   would not trigger&lt;/P&gt;&lt;P&gt;the authentication , since the first request would be a dns request to resolve  &lt;A class="jive-link-custom" href="http://www.google.com." target="_blank"&gt;www.google.com.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;With no resolution  ,  no following  http request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Jun 2008 14:19:26 GMT</pubDate>
    <dc:creator>michelcaissie</dc:creator>
    <dc:date>2008-06-04T14:19:26Z</dc:date>
    <item>
      <title>Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946653#M407316</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;  I configured Cisco ASA 5540 with Active Directory integrated IAS. Authentication for all tcp traffic is enabled in ASA by following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication include tcp/0 inside 0.0.0.0 0.0.0.0 RADIUS-GROUP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also configured dACL in IAS with AV-Pairs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever a user tries to connect to internet, a "HTTP Authentication" window pops up and asks for username password. I enter the username&amp;amp;password which is alreaddy logged in to domain, then everything works perfect. dACLs works too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the issue is that username&amp;amp;password pop-up. It supposed to pop-up when a client which is not joined to domain, or logged on locally not to domain. But it pops when the user is already logged with domain credidentals. I dont want to type it again when trying to browse for the first time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any comments&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:45:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946653#M407316</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2019-03-10T22:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946654#M407317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are some update.&lt;/P&gt;&lt;P&gt;  I disabled IAS and configured Cisco Secure ACS 4.2 trial. I did the necessary config change in ASA.&lt;/P&gt;&lt;P&gt;  I tested an Active Directory account in CLI, authentication is successfull. Account also appears as dynamic in ACS Users, thats all fine.&lt;/P&gt;&lt;P&gt;  But AGAIN! whenever I try to browse the net, I get that "HTTP Authentication" pop-up. If I enter the domain user credidentals, all works fine.&lt;/P&gt;&lt;P&gt;  So I still have the same problem that I encountered above. Should I be using certificates? Any ideas, thoughts are much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Mar 2008 19:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946654#M407317</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-03-29T19:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946655#M407318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Huseyin, well this one is a tricky one.., at least I amd pushing this thread back to the begining of all AAA threads sort of to not let it lose momentum so that some expert can shed some light :-),  I just loaded some docs to understand the implementation, I could be wrong but you have conducted two different implementations using two platforms IAS and cisco ACS and same outcome but this seems to nawrrow down a bit the issue more in ASA configuration side, I still need to read a bit more on asa authentication include exclude type of services requiering autentication and other optional parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think when a user is autenticated through the widows DOMAIN ASA is still responding as a http proxy, so I wander if by adding aaa autentication exclude http inside etc.. would make a difference, well maybe Im off on this one but let me re-read this several times, in the meantime perhaps someone may join the cause.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link Im using if anyone wants to join this thread to resolve this. &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/a1_72.html#wp1437563" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/a1_72.html#wp1437563&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Mar 2008 19:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946655#M407318</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-03-30T19:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946656#M407319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jorge,&lt;/P&gt;&lt;P&gt;  Thanks for sticking with me on this issue m8, much appreciated.&lt;/P&gt;&lt;P&gt;  Here is a little background about what I am trying to achieve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc00e8c" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc00e8c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cbe94a0" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cbe94a0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   And they haven't got any response &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;   But you know what, I think you pointed me to the obvious, that I didnt see. I always answer the askers that ASA is not a proxy itself, but without exxcluding http, I am configuring the device as a proxy!. This something which Websense can handle. I wish to see everything works fine tonight when I exclude http. I will keep you posted m8.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Mar 2008 13:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946656#M407319</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-03-31T13:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946657#M407320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah.. I read the sencond thread..woow, you indeed have done some serious testing with acs, and what is left is this authentication pop-up thing,  I would bet it must have to do with that asa statement and optional parameters for certain protocols..  let me know how it goes with the exclude..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 01:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946657#M407320</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-04-01T01:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946658#M407321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No cigar...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;109023 &lt;/P&gt;&lt;P&gt;Error Message    %PIX-3-109023: User from src_IP_Adress/src_port to &lt;/P&gt;&lt;P&gt;dest_IP_Address/dest_port on interface outside must authenticate before using this &lt;/P&gt;&lt;P&gt;service.&lt;/P&gt;&lt;P&gt;Explanation    This is a AAA message. Based on the configured policies, you need to be authenticated before you can use this service (port). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I exclueded http traffic, and got the above log in syslog when I try to RDP or somethn else&lt;/P&gt;&lt;P&gt;And here is the recommended action? Lol?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Action    Have the user authenticate using Telnet, FTP or HTTP before attempting to use the above service (port). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 20:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946658#M407321</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-01T20:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946659#M407322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ... your aaa stmt essentially says authen all outbound conn's via the RADIUS-GROUP aaa servers. Check a few things ... 1: what does a show acl look like after you built the first outbound connection? What are the UAUTH timers set at? If you do a debug on aaa authen ... does the next connection want an authen because its new ports?  I suspect that's the case ... check to see what the show acl looks like after the first connection has been logged off ... is the uauth entry still there ?  Have you tried to do the second connection while the first one is stillup? What happens ... you can email me directly. ... TomH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 21:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946659#M407322</guid>
      <dc:creator>Hunter</dc:creator>
      <dc:date>2008-04-01T21:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946660#M407323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everybody for your efforts, but this will stay as a mystery.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 04:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946660#M407323</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-27T04:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IAS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946661#M407324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi , i haven't read all the links  related to this post but here is a couple of hints , hope they can&lt;/P&gt;&lt;P&gt;help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;But the issue is that username&amp;amp;password pop-up. It supposed to pop-up when a client which &lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;is not joined to domain, or logged on locally not to domain. But it pops when the user is already logged&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;with domain credidentals. I dont want to type it again when trying to browse for the first time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure your browser is configure to pass the credentials;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IE6&lt;/P&gt;&lt;P&gt;Internet Options -Advanced -Security - Enable Integrated Windows Authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt;aaa authentication include tcp/0 inside 0.0.0.0 0.0.0.0 RADIUS-GROUP &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"reference cisco:  Although you can configure the security appliance to require authentication for network &lt;/P&gt;&lt;P&gt;access to any protocol or service, users can authenticate directly with HTTP, HTTPS, Telnet, or FTP only. &lt;/P&gt;&lt;P&gt;A user must first authenticate with one of these services before the security appliance allows other traffic &lt;/P&gt;&lt;P&gt;requiring authentication. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you have to make sure that your first request is either  http,https,telnet or ftp   to trigger the&lt;/P&gt;&lt;P&gt;authentication. If your DNS is outside your firewall ,  browsing  &lt;A class="jive-link-custom" href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;   would not trigger&lt;/P&gt;&lt;P&gt;the authentication , since the first request would be a dns request to resolve  &lt;A class="jive-link-custom" href="http://www.google.com." target="_blank"&gt;www.google.com.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;With no resolution  ,  no following  http request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jun 2008 14:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/simple-ias-authentication-issue/m-p/946661#M407324</guid>
      <dc:creator>michelcaissie</dc:creator>
      <dc:date>2008-06-04T14:19:26Z</dc:date>
    </item>
  </channel>
</rss>

