<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS &amp; PIX authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-pix-authentication/m-p/27432#M7097</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When Authentication is configured on the PIX, the user attempts to get past the pix and is prompted for username &amp;amp; password authentication credentials.  Those credentials are passed on to (in your case) Cisco Secure ACS and checked against the domain database.  If okay, the PIX caches this username and password (see the show uauth command) along with the IP address of the authenticated host.  When that source IP address hits the PIX again, no re-authentication will be necessary as long as his credentials are in the cache (timeout uauth &lt;OPTIONS&gt; adjusts these timers).  Now you can go a step further and configure Authorization on the PIX and Cisco Secure ACS to limit the access the user has after authentication occurs. I&amp;#146;m pretty sure you can restrict his/her access based on source IP address among other authorizations.  Here&amp;#146;s some reference and sample config URL's for both products:  &lt;/OPTIONS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Software:Cisco_Secure_ACS_NT" target="_blank"&gt;http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Software:Cisco_Secure_ACS_NT&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Hardware:PIX" target="_blank"&gt;http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Hardware:PIX&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Nov 2001 19:57:16 GMT</pubDate>
    <dc:creator>p.krane</dc:creator>
    <dc:date>2001-11-07T19:57:16Z</dc:date>
    <item>
      <title>ACS &amp; PIX authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-pix-authentication/m-p/27431#M7096</link>
      <description>&lt;P&gt;We are running ACS 2.6 for authentication with a PIX515 ver 6.1&lt;/P&gt;&lt;P&gt;our customer want to authenticate users based on their Name, PassWord and IP&lt;/P&gt;&lt;P&gt;address or netbios name. we have configured the ACS to use the NT Database,&lt;/P&gt;&lt;P&gt;we belive that with this configuration the user is authenticated used just&lt;/P&gt;&lt;P&gt;his name and password without any restriction based on IP address or netbios&lt;/P&gt;&lt;P&gt;name.&lt;/P&gt;&lt;P&gt;please can you get us with any solution for our customer problem .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-pix-authentication/m-p/27431#M7096</guid>
      <dc:creator>ytalibi</dc:creator>
      <dc:date>2020-02-21T17:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS &amp; PIX authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-pix-authentication/m-p/27432#M7097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When Authentication is configured on the PIX, the user attempts to get past the pix and is prompted for username &amp;amp; password authentication credentials.  Those credentials are passed on to (in your case) Cisco Secure ACS and checked against the domain database.  If okay, the PIX caches this username and password (see the show uauth command) along with the IP address of the authenticated host.  When that source IP address hits the PIX again, no re-authentication will be necessary as long as his credentials are in the cache (timeout uauth &lt;OPTIONS&gt; adjusts these timers).  Now you can go a step further and configure Authorization on the PIX and Cisco Secure ACS to limit the access the user has after authentication occurs. I&amp;#146;m pretty sure you can restrict his/her access based on source IP address among other authorizations.  Here&amp;#146;s some reference and sample config URL's for both products:  &lt;/OPTIONS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Software:Cisco_Secure_ACS_NT" target="_blank"&gt;http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Software:Cisco_Secure_ACS_NT&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Hardware:PIX" target="_blank"&gt;http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Hardware:PIX&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2001 19:57:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-pix-authentication/m-p/27432#M7097</guid>
      <dc:creator>p.krane</dc:creator>
      <dc:date>2001-11-07T19:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS &amp; PIX authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-pix-authentication/m-p/27433#M7099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok p.krane &lt;/P&gt;&lt;P&gt;but i have 600 users. therefore I must create 600 user on my ACS and 600 named acl on my pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2001 08:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-pix-authentication/m-p/27433#M7099</guid>
      <dc:creator>ytalibi</dc:creator>
      <dc:date>2001-11-09T08:45:53Z</dc:date>
    </item>
  </channel>
</rss>

