<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa authentication for inbound in PIX 6.1.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-for-inbound-in-pix-6-1-1/m-p/25982#M775</link>
    <description>&lt;P&gt;I want to configure authentication in the PIX(6.1.1) but cannot get a prompt for authentication. please give me an advise what's wrong for the following scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server-(1.1.1.0)-PIX-(2.2.2.0)-VPN3030--Internet--PIX515-(3.3.3.0)-Client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. IP for server1=1.1.1.1, ACS server=1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. PIX configuration.&lt;/P&gt;&lt;P&gt;static (inside,dmz) 2.2.2.2 1.1.1.1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;conduit permit tcp host 2.2.2.2 eq telnet 3.3.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa-server test protocol radius&lt;/P&gt;&lt;P&gt;aaa-server test (inside) host 1.1.1.2 PASSWORD timeout 10&lt;/P&gt;&lt;P&gt;aaa authentication include telnet outside 2.2.2.2 255.255.255.255 3.3.3.0 255.255.255.0 test&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;3. PIX515 connected to VPN3030's base group using IPSec tunnel&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;4. try telnet to 2.2.2.2 from client(3.3.3.3), then direct show up the telnet screen without any authentication prompt.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;** PIX log**&lt;/P&gt;&lt;P&gt;302001: Built inbound TCP connection 2704306 for faddr 3.3.3.3/2511 gaddr 2.2.2.2/23 laddr 1.1.1.1/23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:04:35 GMT</pubDate>
    <dc:creator>cjrchoi11</dc:creator>
    <dc:date>2020-02-21T18:04:35Z</dc:date>
    <item>
      <title>aaa authentication for inbound in PIX 6.1.1</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-for-inbound-in-pix-6-1-1/m-p/25982#M775</link>
      <description>&lt;P&gt;I want to configure authentication in the PIX(6.1.1) but cannot get a prompt for authentication. please give me an advise what's wrong for the following scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server-(1.1.1.0)-PIX-(2.2.2.0)-VPN3030--Internet--PIX515-(3.3.3.0)-Client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. IP for server1=1.1.1.1, ACS server=1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. PIX configuration.&lt;/P&gt;&lt;P&gt;static (inside,dmz) 2.2.2.2 1.1.1.1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;conduit permit tcp host 2.2.2.2 eq telnet 3.3.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa-server test protocol radius&lt;/P&gt;&lt;P&gt;aaa-server test (inside) host 1.1.1.2 PASSWORD timeout 10&lt;/P&gt;&lt;P&gt;aaa authentication include telnet outside 2.2.2.2 255.255.255.255 3.3.3.0 255.255.255.0 test&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;3. PIX515 connected to VPN3030's base group using IPSec tunnel&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;4. try telnet to 2.2.2.2 from client(3.3.3.3), then direct show up the telnet screen without any authentication prompt.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;** PIX log**&lt;/P&gt;&lt;P&gt;302001: Built inbound TCP connection 2704306 for faddr 3.3.3.3/2511 gaddr 2.2.2.2/23 laddr 1.1.1.1/23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-for-inbound-in-pix-6-1-1/m-p/25982#M775</guid>
      <dc:creator>cjrchoi11</dc:creator>
      <dc:date>2020-02-21T18:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authentication for inbound in PIX 6.1.1</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-for-inbound-in-pix-6-1-1/m-p/25983#M776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 2.2.2.2 1.1.1.1 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;aaa authentication include telnet outside 2.2.2.2 255.255.255.255 3.3.3.0 255.255.255.0 test &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your static says that connections for 2.2.2.2 will be coming in on the dmz interface, yet your  authentication line is saying that it's coming in on the outside interface.  Which is it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's the DMZ, then you need to change the above lines to read:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 2.2.2.2 1.1.1.1 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;aaa authentication include telnet dmz 2.2.2.2 255.255.255.255 3.3.3.0 255.255.255.0 test &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's the outside, then you need to change the above lines to read:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 2.2.2.2 1.1.1.1 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;aaa authentication include telnet outside 2.2.2.2 255.255.255.255 3.3.3.0 255.255.255.0 test &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2002 23:06:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-for-inbound-in-pix-6-1-1/m-p/25983#M776</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2002-10-23T23:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authentication for inbound in PIX 6.1.1</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-for-inbound-in-pix-6-1-1/m-p/25984#M777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;another issue that I'll assign one userID to the remote site and let them share the UserID and only allow 3 http sessions concurrently(three stations will use same UserID). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried "Max session=3" on the ACS(2.6) but never can authenticated from ACS with message "User exceeded max sessions" even only one user trying access. only "unlimited" can made authentication successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the "ACS for Unix with DSM" solution ? please guide me how to implement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2002 19:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-for-inbound-in-pix-6-1-1/m-p/25984#M777</guid>
      <dc:creator>cjrchoi11</dc:creator>
      <dc:date>2002-10-28T19:00:03Z</dc:date>
    </item>
  </channel>
</rss>

