<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with Cut Through Proxy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673481#M55479</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My setup is Internet-----Juniper F/W--------Cisco ASA&lt;/P&gt;&lt;P&gt;I have configured cut through proxy on ASA 5525X version 9.x. So, when a user tries to access a web server from internet he gets a prompt to enter his username and password. It works fine the issue that I have arises when a home user is coming from behind his router and he is using multiple devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the first access user gets a prompt to enter username and password. Once he authenticates himself he lands on the web page. When another user&amp;nbsp;tries to access the web site from the same location he does not get prompted to enter credentials and he can access the website immediately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess that uauth is tied up with the source ip address only, is there anyway to change this behaviour??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saurav&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:44:38 GMT</pubDate>
    <dc:creator>saurav.khanna</dc:creator>
    <dc:date>2019-03-11T05:44:38Z</dc:date>
    <item>
      <title>Issue with Cut Through Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673481#M55479</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My setup is Internet-----Juniper F/W--------Cisco ASA&lt;/P&gt;&lt;P&gt;I have configured cut through proxy on ASA 5525X version 9.x. So, when a user tries to access a web server from internet he gets a prompt to enter his username and password. It works fine the issue that I have arises when a home user is coming from behind his router and he is using multiple devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the first access user gets a prompt to enter username and password. Once he authenticates himself he lands on the web page. When another user&amp;nbsp;tries to access the web site from the same location he does not get prompted to enter credentials and he can access the website immediately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess that uauth is tied up with the source ip address only, is there anyway to change this behaviour??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saurav&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673481#M55479</guid>
      <dc:creator>saurav.khanna</dc:creator>
      <dc:date>2019-03-11T05:44:38Z</dc:date>
    </item>
    <item>
      <title>Yes, proxy authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673482#M55480</link>
      <description>&lt;P&gt;Yes, proxy authentication only uses the source address to allow the traffic once authenticated, this i believe can't be changed.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2015 21:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673482#M55480</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-05-21T21:32:31Z</dc:date>
    </item>
    <item>
      <title>I guess this can't be changed</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673483#M55481</link>
      <description>&lt;P&gt;I guess this can't be changed. But imagine a scenario in which there are 100 people sitting behind a patting device. If on authenticates to a site via 2FA like in my case, then all rest 99 are allowed to go through....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 06:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673483#M55481</guid>
      <dc:creator>saurav.khanna</dc:creator>
      <dc:date>2015-05-26T06:06:04Z</dc:date>
    </item>
    <item>
      <title>Yup, but this is where you</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673484#M55482</link>
      <description>&lt;P&gt;Yup, but this is where you would use something like a web proxy device like an Ironport or Firepower for ASA, not an regular ASA firewall, the cut-through-proxy feature is old, and hasn't had any enhancement for many years.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2015 14:47:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-cut-through-proxy/m-p/2673484#M55482</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-05-27T14:47:43Z</dc:date>
    </item>
  </channel>
</rss>

