<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX and FreeRADIUS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765552#M420483</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And yes, as you are using FreeRadius server, then you would be required to use cisco av pair to get the acls downloaded on per user/group basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 10 Jun 2007 18:54:08 GMT</pubDate>
    <dc:creator>Premdeep Banga</dc:creator>
    <dc:date>2007-06-10T18:54:08Z</dc:date>
    <item>
      <title>PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765545#M420476</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a PIX 515E 6.3(5). Currently i am using the local PIX database to authenticate the Remote Access VPN users. I would now like to authenticate and authorize users with a AAA server. I already have FreeRADIUS installed and tested on my network.&lt;/P&gt;&lt;P&gt;Could anyone please assist me in configuring the PIX to use the FreeRADIUS for authentication and authorization.&lt;/P&gt;&lt;P&gt;thanks. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765545#M420476</guid>
      <dc:creator>owais.ahsan</dc:creator>
      <dc:date>2019-03-10T22:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765546#M420477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go through these two links,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806de37e.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806de37e.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Above links are with IAS, but will help you understand the concept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2007 11:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765546#M420477</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-07T11:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765547#M420478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Prem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went through the document, it was good help but it only demonstrates authentication, my main concern is authorization.&lt;/P&gt;&lt;P&gt;Can you please provide me with details on authorization?&lt;/P&gt;&lt;P&gt;Thanx in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2007 11:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765547#M420478</guid>
      <dc:creator>owais.ahsan</dc:creator>
      <dc:date>2007-06-07T11:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765548#M420479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Prem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went through the document, it was good help but it only demonstrates authentication, my main concern is authorization.&lt;/P&gt;&lt;P&gt;Can you please provide me with details on authorization?&lt;/P&gt;&lt;P&gt;Thanx in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2007 11:47:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765548#M420479</guid>
      <dc:creator>owais.ahsan</dc:creator>
      <dc:date>2007-06-07T11:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765549#M420480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Authorization" available on ASA under tunnel-group is used for Remote Access VPN when we are using Certificates (correct me if I am wrong).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise if you are looking for something like downloadable ACL's etc, that works with "authentication" being specified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Get things working with authentication first. Also, any specific requirement, as why you need authorization as well for Remote Access VPN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2007 12:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765549#M420480</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-07T12:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765550#M420481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx again for your reply. I have an application server that is running on a specific tcp port. Business partners and clients access that port through Site - to - Site and remote access VPN. My concerns are about the remote access VPN clients, if i am using PIX 515E 6.3(5) how can i restrict the clients to use only that specific host, hence the need for the authorization, yes, RADIUS is definitely an overkill right now for me, but it is a step in the right direction, as more and more partners and clients are required access to the application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if i am wrong,&lt;/P&gt;&lt;P&gt;Thanx again,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2007 04:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765550#M420481</guid>
      <dc:creator>owais.ahsan</dc:creator>
      <dc:date>2007-06-10T04:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765551#M420482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you are looking for is know as Downloadable IP ACLs, you do not need to configure any authorization command on the device. You simply need authentication, when a remote Access VPN user connects with the firewall, and if we have downloadable IP acls configured, it will get downloaded for that client dynamically. And user access to the network can be governed using that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Downloadable IP ACLs&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/spc.htm#wp696775" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/spc.htm#wp696775&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try that out and let me know,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2007 06:31:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765551#M420482</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-10T06:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765552#M420483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And yes, as you are using FreeRadius server, then you would be required to use cisco av pair to get the acls downloaded on per user/group basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2007 18:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765552#M420483</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-10T18:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765553#M420484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx prem, I got it to authenticate and authorize through FreeRADIUS, but instead of using downloadable ACLs i used local ACLs configured on the PIX and it works great. The FreeRADIUS sends the name of the ACL using the "Filter-Id" attribute.&lt;/P&gt;&lt;P&gt;I would like to achieve this by using downloadable ACLs though, but the procedure it not really very clear, would be glad if you would shed some light on that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2007 04:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765553#M420484</guid>
      <dc:creator>owais.ahsan</dc:creator>
      <dc:date>2007-06-13T04:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and FreeRADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765554#M420485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this whole section out, it will give you ample idea on how to configure downloadable ACLs,&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/fwaaa.htm#wp1043588" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/fwaaa.htm#wp1043588&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 04:07:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-and-freeradius/m-p/765554#M420485</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-14T04:07:21Z</dc:date>
    </item>
  </channel>
</rss>

