<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX FTP authentication feature in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-ftp-authentication-feature/m-p/587141#M5745</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My apologies, I missed my typo.  The correct version of PIX OS is 6.3(4)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 May 2006 13:06:39 GMT</pubDate>
    <dc:creator>dcarrion</dc:creator>
    <dc:date>2006-05-18T13:06:39Z</dc:date>
    <item>
      <title>PIX FTP authentication feature</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ftp-authentication-feature/m-p/587139#M5743</link>
      <description>&lt;P&gt;We currently went from using 4 /24 networks as our NAT pools for Internet access.  We just added a PAT address as the NAT pools were full, and now any FTP requires authentication even if the user is alrady authenticated.  HTTP and telnet are fine.  We are using RADIUS authentication with dynamic ACL's on a PIX 525 running 5.3(4).  Anyone else experience this?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ftp-authentication-feature/m-p/587139#M5743</guid>
      <dc:creator>dcarrion</dc:creator>
      <dc:date>2020-02-21T18:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: PIX FTP authentication feature</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ftp-authentication-feature/m-p/587140#M5744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ..  you can try excluding FTP from triggering aaa authentication. ( Note: Your PIX version is old so I hope these commands are available )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication exclude tcp/21 interface x.x.x.x 255.255.255.0 aaa-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where interface is the interface from where your radius can be reached i.e inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;x.x.x.x is the IP address of your Radius server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-group is the group name assigned by aaa-server command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or you could exclude your outbound connections from triggerring the authention by using an access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list yourlist deny ftp x.x.x.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list yourlist permit tcp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication match yourlist outbound radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ...  please rate it if it does !!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 May 2006 11:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ftp-authentication-feature/m-p/587140#M5744</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-05-13T11:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX FTP authentication feature</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ftp-authentication-feature/m-p/587141#M5745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My apologies, I missed my typo.  The correct version of PIX OS is 6.3(4)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 May 2006 13:06:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ftp-authentication-feature/m-p/587141#M5745</guid>
      <dc:creator>dcarrion</dc:creator>
      <dc:date>2006-05-18T13:06:39Z</dc:date>
    </item>
  </channel>
</rss>

