<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting up 2 factor authentication to a PIX? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577036#M5718</link>
    <description>&lt;P&gt;Hi guys, is it possible to set up 2 factor authentication using a tacacs+ server in the pix firewall?  only want to use a tacacs+ server using aaa on the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:16:01 GMT</pubDate>
    <dc:creator>nathan</dc:creator>
    <dc:date>2020-02-21T18:16:01Z</dc:date>
    <item>
      <title>Setting up 2 factor authentication to a PIX?</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577036#M5718</link>
      <description>&lt;P&gt;Hi guys, is it possible to set up 2 factor authentication using a tacacs+ server in the pix firewall?  only want to use a tacacs+ server using aaa on the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577036#M5718</guid>
      <dc:creator>nathan</dc:creator>
      <dc:date>2020-02-21T18:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up 2 factor authentication to a PIX?</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577037#M5720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is dependant on your TACACS server having the 2 factor support. The PIX sends athentication request to the aaa server for serial|telnet|ssh|http|enable that I know of. If you are authenticating vpn clients via TACACS I am not sure off the top of my head. &lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2006 19:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577037#M5720</guid>
      <dc:creator>brian.r.johns</dc:creator>
      <dc:date>2006-06-02T19:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up 2 factor authentication to a PIX?</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577038#M5721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are running accross the same thing here, my question is what tacacs+ or tacacs server supports two factor authentication?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2006 20:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577038#M5721</guid>
      <dc:creator>vayusa1234</dc:creator>
      <dc:date>2006-06-02T20:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up 2 factor authentication to a PIX?</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577039#M5723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;according to this article: "The Power Behind RSA SecurID® Two-factor User Authentication: RSA ACE/Server"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;page 4of11 it seems that tacacs+ supports server sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.opsec.com/solutions/partners/downloads/rsa_securid_whitepaper.pdf" target="_blank"&gt;http://www.opsec.com/solutions/partners/downloads/rsa_securid_whitepaper.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Most leading remote access server, firewall,&lt;/P&gt;&lt;P&gt;VPN and router products have built-in RSA ACE/Agents for compatibility with RSA SecurID two-factor authentication. In addition, both TACACS+ and RADIUS authentication support RSA ACE/Server sessions."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyways, in general, what is the best way to set up 2 factor authentication on a pix ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2006 22:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577039#M5723</guid>
      <dc:creator>nathan</dc:creator>
      <dc:date>2006-06-02T22:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up 2 factor authentication to a PIX?</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577040#M5724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi  .. the best two factor authentication that I have come across is always RSA secureID.  Basically you configure the AAA options in your PIX  as radius client while the RSA ACE is the radius server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a quick example that I have set up in the past using an ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps ..  please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server RADIUS_SERVERS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS_SERVERS host RSA_SERVER&lt;/P&gt;&lt;P&gt; timeout 5&lt;/P&gt;&lt;P&gt; key ********&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group GT_VPN_RSA type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group GT_VPN_RSA general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN_rsa_pool&lt;/P&gt;&lt;P&gt; authentication-server-group RADIUS_SERVERS&lt;/P&gt;&lt;P&gt;tunnel-group GT_VPN_RSA ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For configurating on a PIX running 6.XX  you can check the command reference under aaa-server and vpngroup commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_book09186a008017284e.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_book09186a008017284e.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ... please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Jun 2006 09:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577040#M5724</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-06-03T09:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up 2 factor authentication to a PIX?</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577041#M5725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well, I dont want to radius at all if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you dont have a radius server, what are my options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Jun 2006 15:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-2-factor-authentication-to-a-pix/m-p/577041#M5725</guid>
      <dc:creator>nathan</dc:creator>
      <dc:date>2006-06-03T15:53:47Z</dc:date>
    </item>
  </channel>
</rss>

