<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix, ACS, and Citrix Users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-acs-and-citrix-users/m-p/32181#M9592</link>
    <description>&lt;P&gt;I have a Cisco pix that is authenticating outbound users via Cisco Secure ACS.  The problem is with Citrix users.  When one user logs into the Citrix server and starts Internet Explorer, he gets an authentication window.  He puts in a username, password, etc., and gets through fine.  Subsequent users do not get an authentication window -- they just go straight through.  My guess is that the Pix does not differentiate different sessions but instead sees them all coming from the Citrix server and does not bother authenticating different sessions.  My questions are:  is my thinking correct,  is this behavior expected, and is there anything I can do about it?  Ideally, I would like to get every Citrix user to authenticate, but I don't think it's possible in this environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any input!!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:02:44 GMT</pubDate>
    <dc:creator>marcs</dc:creator>
    <dc:date>2020-02-21T18:02:44Z</dc:date>
    <item>
      <title>Pix, ACS, and Citrix Users</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-acs-and-citrix-users/m-p/32181#M9592</link>
      <description>&lt;P&gt;I have a Cisco pix that is authenticating outbound users via Cisco Secure ACS.  The problem is with Citrix users.  When one user logs into the Citrix server and starts Internet Explorer, he gets an authentication window.  He puts in a username, password, etc., and gets through fine.  Subsequent users do not get an authentication window -- they just go straight through.  My guess is that the Pix does not differentiate different sessions but instead sees them all coming from the Citrix server and does not bother authenticating different sessions.  My questions are:  is my thinking correct,  is this behavior expected, and is there anything I can do about it?  Ideally, I would like to get every Citrix user to authenticate, but I don't think it's possible in this environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any input!!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:02:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-acs-and-citrix-users/m-p/32181#M9592</guid>
      <dc:creator>marcs</dc:creator>
      <dc:date>2020-02-21T18:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Pix, ACS, and Citrix Users</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-acs-and-citrix-users/m-p/32182#M9593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try implementing VIRTUAL TELNET on the pix. This way, you can force the users to telnet to the virtual IP configured on the pix to authenticate first, and then browse port 80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/atp52.html#telnet" target="_blank"&gt;http://www.cisco.com/warp/public/110/atp52.html#telnet&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;R/Yusuf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Aug 2002 08:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-acs-and-citrix-users/m-p/32182#M9593</guid>
      <dc:creator>yusuff</dc:creator>
      <dc:date>2002-08-11T08:45:13Z</dc:date>
    </item>
  </channel>
</rss>

