<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic remote proxy authentication with ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/remote-proxy-authentication-with-acs/m-p/313035#M430097</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco Hardware ACS 3.2 behind a Pix 515E. I am trying to setup remote authentication from Sprints Dial-up authentication servers. I opened ports 1645 and 1646 from the outside to the ACS inside, but when they send a test, they get nothing in reply and I see nothing on ACS for failed or anything. Is there something I have to do on the Pix515E to allow these requests to get to the ACS on the inside network? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 20:56:29 GMT</pubDate>
    <dc:creator>rbolyard</dc:creator>
    <dc:date>2019-03-10T20:56:29Z</dc:date>
    <item>
      <title>remote proxy authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/remote-proxy-authentication-with-acs/m-p/313035#M430097</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco Hardware ACS 3.2 behind a Pix 515E. I am trying to setup remote authentication from Sprints Dial-up authentication servers. I opened ports 1645 and 1646 from the outside to the ACS inside, but when they send a test, they get nothing in reply and I see nothing on ACS for failed or anything. Is there something I have to do on the Pix515E to allow these requests to get to the ACS on the inside network? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remote-proxy-authentication-with-acs/m-p/313035#M430097</guid>
      <dc:creator>rbolyard</dc:creator>
      <dc:date>2019-03-10T20:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: remote proxy authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/remote-proxy-authentication-with-acs/m-p/313036#M430098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Radius works on ports 1645/1646 (older systems generally), and on the proper ports of 1812/1813 (initially Radius was given 1645/1646 to use but then IETF realised another system used it, so they changed the "official" Radius ports to 1812/1813 ata later date).  Depending on what ports the Sprint dial-up system uses you will probably need to open up those ports through the PIX.  ACS automatically listens on both 1645/1646 and 1812/1813 for Radius authentication requests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2004 04:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remote-proxy-authentication-with-acs/m-p/313036#M430098</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-12-24T04:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: remote proxy authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/remote-proxy-authentication-with-acs/m-p/313037#M430099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so far this is where we are, i had tcp and not udp ports open. i have made that change. Now they go thru the pix to the ACS. however they are trying to login with &lt;A href="mailto:username@domain.ext"&gt;username@domain.ext&lt;/A&gt; and they only authenticate against the default group in the ACS. I am seeing if Sprint will try domain\username so that way it will go to the correct group and work. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2004 15:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remote-proxy-authentication-with-acs/m-p/313037#M430099</guid>
      <dc:creator>rbolyard</dc:creator>
      <dc:date>2004-12-27T15:23:49Z</dc:date>
    </item>
  </channel>
</rss>

