<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authenticating multiple users from the same IP Address ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticating-multiple-users-from-the-same-ip-address/m-p/150985#M6303</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a situation where I need to authenticate inside http users before going on the Internet.  Easy enough with the PIX or the &amp;#147;Authentication proxy feature&amp;#148; on the IOS Firewall combined with a Tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is : All users appear as the same IP Address to the Firewall,  since Citrix servers are used on the inside.  The firewall sees traffic just if it had just passed a NAT : the same IP address for everyone but only multiplexed on a port basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking of using the &amp;#147;Authentication proxy feature&amp;#148; on the IOS Firewall but I&amp;#146;ve noticed the following in the &amp;#147;Restrictions&amp;#148; section :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7c7.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7c7.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;#147;The authentication proxy does not support concurrent usage; that is, if two users try to log in from the same host at the same time, authentication and authorization applies only to the user who first submits a valid username and password.&amp;#148;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which I think defeats what I&amp;#146;m trying to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question : Is there anyone with a similar situation ?  If yes, did you find any features that would support such an environment ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Saindon&lt;/P&gt;&lt;P&gt;Network Consultant&lt;/P&gt;&lt;P&gt;Interreseau-Conseils Inc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:05:35 GMT</pubDate>
    <dc:creator>steve.saindon</dc:creator>
    <dc:date>2020-02-21T18:05:35Z</dc:date>
    <item>
      <title>Authenticating multiple users from the same IP Address ?</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticating-multiple-users-from-the-same-ip-address/m-p/150985#M6303</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a situation where I need to authenticate inside http users before going on the Internet.  Easy enough with the PIX or the &amp;#147;Authentication proxy feature&amp;#148; on the IOS Firewall combined with a Tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is : All users appear as the same IP Address to the Firewall,  since Citrix servers are used on the inside.  The firewall sees traffic just if it had just passed a NAT : the same IP address for everyone but only multiplexed on a port basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking of using the &amp;#147;Authentication proxy feature&amp;#148; on the IOS Firewall but I&amp;#146;ve noticed the following in the &amp;#147;Restrictions&amp;#148; section :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7c7.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7c7.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;#147;The authentication proxy does not support concurrent usage; that is, if two users try to log in from the same host at the same time, authentication and authorization applies only to the user who first submits a valid username and password.&amp;#148;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which I think defeats what I&amp;#146;m trying to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question : Is there anyone with a similar situation ?  If yes, did you find any features that would support such an environment ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Saindon&lt;/P&gt;&lt;P&gt;Network Consultant&lt;/P&gt;&lt;P&gt;Interreseau-Conseils Inc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticating-multiple-users-from-the-same-ip-address/m-p/150985#M6303</guid>
      <dc:creator>steve.saindon</dc:creator>
      <dc:date>2020-02-21T18:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating multiple users from the same IP Address ?</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticating-multiple-users-from-the-same-ip-address/m-p/150986#M6304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you have to have a separate internal proxy server that sees all users' IP addresses the way they are. The server then direct them to the internet based upon the correct user/password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2002 19:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticating-multiple-users-from-the-same-ip-address/m-p/150986#M6304</guid>
      <dc:creator>rais</dc:creator>
      <dc:date>2002-12-04T19:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating multiple users from the same IP Address ?</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticating-multiple-users-from-the-same-ip-address/m-p/150987#M6305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Salut Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even to surf the Web, your client is forcing users to pass through the Citrix server(s) ?  This seems a little bit strange.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About the restriction, i've got the same one before and i didn't find a solution with the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since users connect to Citrix before, and i suppose that users have been authentified there, you may leave all traffics from Citrix servers pass through without auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Salut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benoît&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2002 21:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticating-multiple-users-from-the-same-ip-address/m-p/150987#M6305</guid>
      <dc:creator>bdube</dc:creator>
      <dc:date>2002-12-04T21:24:58Z</dc:date>
    </item>
  </channel>
</rss>

