<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 5525 Authenticated User Access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043182#M396373</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jonhil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Read the following, It will answer your questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/access_idfw.html#wp1324095"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/access_idfw.html#wp1324095&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the section:&lt;/P&gt;&lt;H3 style="font-size: 12.800000190734863px; color: #336666; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; background-color: #ffffff;"&gt;Configuring Cut-through Proxy Authentication&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts ( If you do not know how to rate a post just let me know)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Nov 2012 17:45:53 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-11-02T17:45:53Z</dc:date>
    <item>
      <title>5525 Authenticated User Access</title>
      <link>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043179#M396355</link>
      <description>&lt;P&gt;We've just replaced our Fortinet Firewalls with 5525's but are struggling to get a feature working that worked great on the Fortinet firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All our users use a proxy for internet access that's configured in IE but from time to time some users need to remove this proxy and go directly out to the internet, with the Fortinet devices we created a rule right at the bottom of the inside access out rule that had it authenticate users via TACACS which worked a treat and could be used from PC or laptop. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to do a similar thing on the 5525 and I thought the Authenticated user would give me this access but I don't seem to be able to get it to work. I've got the AD side of it working fine the ASA can pull user and groups from AD but I'm struggling to get this working for a user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created a rule at the bottom of the inside access in ACL that has any source and any destination but has my AD user as a user in the rule but when I try and test it it doesn't work and when I have a look in monitoring it says no IP address associated with user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to be able to pick and choose which users have this access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I get this working the way I want it to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043179#M396355</guid>
      <dc:creator>jonhill</dc:creator>
      <dc:date>2019-03-12T00:17:11Z</dc:date>
    </item>
    <item>
      <title>5525 Authenticated User Access</title>
      <link>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043180#M396369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jonh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you trying to authenticate users to allow them to go to the internet??? If this is the case cut-trough proxy is what you are looking for!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080ba6110.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080ba6110.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if I understood your query,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 18:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043180#M396369</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-01T18:52:34Z</dc:date>
    </item>
    <item>
      <title>5525 Authenticated User Access</title>
      <link>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043181#M396372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply, I am trying to authenticate users to allow them to go to the internet but I don't want to have authentication for all users as the majority of them use a proxy for access and that how we want it. The authentication is for a few users who need access directly out of the firewall bypassing the proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried the cut-through proxy but that authenticated all users including the ones using the proxy, how can I restrict this to just authenticating a group of users based on either an AD username or&amp;nbsp; AD group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Nov 2012 07:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043181#M396372</guid>
      <dc:creator>jonhill</dc:creator>
      <dc:date>2012-11-02T07:50:19Z</dc:date>
    </item>
    <item>
      <title>5525 Authenticated User Access</title>
      <link>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043182#M396373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jonhil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Read the following, It will answer your questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/access_idfw.html#wp1324095"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/access_idfw.html#wp1324095&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the section:&lt;/P&gt;&lt;H3 style="font-size: 12.800000190734863px; color: #336666; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; background-color: #ffffff;"&gt;Configuring Cut-through Proxy Authentication&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts ( If you do not know how to rate a post just let me know)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Nov 2012 17:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-authenticated-user-access/m-p/2043182#M396373</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-02T17:45:53Z</dc:date>
    </item>
  </channel>
</rss>

