<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: telnet auth proxy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727130#M421059</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had the same problem with IOS 12.3(19). FTP and Telnet never worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Herbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 May 2007 10:08:35 GMT</pubDate>
    <dc:creator>herbert.aichhorn</dc:creator>
    <dc:date>2007-05-31T10:08:35Z</dc:date>
    <item>
      <title>telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727127#M421053</link>
      <description>&lt;P&gt;hi i was trying to configure auth proxy in my router .. with acs using tacacs+.. but somewhere the authentication was failing..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i had configured acs as required and i dont find any problem with it as it is succefully working with http auth proxy..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configuration for router for telnet auth is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group aaa_serv group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default aaa_serv&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip auth-proxy name telnet_auth telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs+ host 10.1.1.3 key xxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ aaa_serv&lt;/P&gt;&lt;P&gt;server 10.1.1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface fastetherne 0/0&lt;/P&gt;&lt;P&gt;ip auth-proxy telnet_auth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727127#M421053</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2019-03-10T22:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727128#M421055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The authentication proxy feature allows users to log in to a network or access the Internet via HTTP, with their specific access profiles automatically retrieved and applied from a TACACS+ or RADIUS server. The user profiles are active only when there is active traffic from the authenticated users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration_example09186a008017b2a4.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration_example09186a008017b2a4.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2007 12:35:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727128#M421055</guid>
      <dc:creator>thomas.chen</dc:creator>
      <dc:date>2007-04-19T12:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727129#M421057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Bro, I think that we can do auth proxy with telnet also .. i can do successful authentication with http auth proxy, but not with telnet.&lt;/P&gt;&lt;P&gt;         &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2007 13:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727129#M421057</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2007-04-19T13:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727130#M421059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had the same problem with IOS 12.3(19). FTP and Telnet never worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Herbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2007 10:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727130#M421059</guid>
      <dc:creator>herbert.aichhorn</dc:creator>
      <dc:date>2007-05-31T10:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727131#M421060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me give it a try,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just did a test few days before. I have all the setup intact. It wont harm adding Telnet and FTP. Will give it a try, but only in Monday, on weekends no work =D&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2007 23:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727131#M421060</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-01T23:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727132#M421061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most probably I'll try this today. In meanwhile do look into this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall Authentication Proxy for FTP and Telnet Sessions:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios123/123newft/123_1/ftp_tel.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios123/123newft/123_1/ftp_tel.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Authentication proxy is subjected only to the traffic that passes through the router; traffic that is destined for the router continues to be authenticated by the existing authentication methods that are provided by Cisco IOS."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2007 04:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727132#M421061</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-04T04:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727133#M421062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So Finally,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it is,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when you configure New Services on ACS, from Itnerface Configuration &amp;gt; TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;specify "auth-proxy" for Service and "ip" for Protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It a one step more then HTTP auth proxy, where we only need to specify "auth-proxy" for Service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you do not do that, and try to do telnet auth proxy you'll get following error on FAiled Attempts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Author-Failure-Code : Service denied&lt;/P&gt;&lt;P&gt;Author-Data : service=auth-proxy protocol=ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what happens when its successful,&lt;/P&gt;&lt;P&gt;------------------&lt;/P&gt;&lt;P&gt;Firewall authentication&lt;/P&gt;&lt;P&gt;Username:test&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;Firewall authentication Success.&lt;/P&gt;&lt;P&gt;Connection will be closed if remote server does not respond&lt;/P&gt;&lt;P&gt;Connecting to remote server...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: admin&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch&amp;gt;&lt;/P&gt;&lt;P&gt;------------------&lt;/P&gt;&lt;P&gt;So summarizing IT WORKS!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2007 22:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727133#M421062</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-05T22:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727134#M421063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi prem, thanks a ton man for finding out the solution..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 06:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727134#M421063</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2007-06-06T06:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727135#M421064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please you can you provide the following information:&lt;/P&gt;&lt;P&gt;- is the protocol "ip" necessary wirh service auth-proxy on ACS&lt;/P&gt;&lt;P&gt;- which IOS on what plattform have you tested ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Herbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 07:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727135#M421064</guid>
      <dc:creator>herbert.aichhorn</dc:creator>
      <dc:date>2007-06-06T07:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727136#M421065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ip is neccessary only when we want to use ftp or telnet, for http we dont need.. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 09:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727136#M421065</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2007-06-06T09:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: telnet auth proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727137#M421066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Herbert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diptanshu is correct, we need it if we are using FTP or Telnet, not HTTP, as I have mentioned earlier. I guess I tested it on 12.4(x) IOS. Have to look into. Will let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark this thread as solved, so that others can benefit from it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have more questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 11:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/telnet-auth-proxy/m-p/727137#M421066</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-06T11:10:03Z</dc:date>
    </item>
  </channel>
</rss>

