<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Identity-Based Internet Access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-identity-based-internet-access/m-p/903341#M421413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use HTTP cut through proxy feature for this. Cut through proxy would give users a log-in prompt when they try to access the web through the ASA. You can configure that login prompt to point to an authentication server. If they have a valid user name and password, it will let them through. If they don't, it will block access from their IP. There are basically two parts of configuration that you will need to do.&lt;/P&gt;&lt;P&gt;1) HTTP Proxy&lt;/P&gt;&lt;P&gt;2) LDAP setup on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The document link below shows how to configure an ASA to use LDAP as an authentication server&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/extsvr.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/extsvr.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Oct 2007 18:06:37 GMT</pubDate>
    <dc:creator>didyap</dc:creator>
    <dc:date>2007-10-15T18:06:37Z</dc:date>
    <item>
      <title>ASA Identity-Based Internet Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-identity-based-internet-access/m-p/903340#M421412</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;A client of mine is looking at controlling user access to the Internet based on identity. I know Microsoft ISA and other proxy solutions would do.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;However, I am looking at leveraging their present installation of ASA and Microsoft AD to provide them with this function. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I know for sure that the ASA can be used to authenticate users on a web page against the AD and apply access rules accordingly (Identity-Based Access).&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Unfortunately, I dont seem to be getting much info on the setup and configuration of this requirement.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;If anyone knows of any source, please let me have the links. (I am not referring to authenticating telnet/ssh sessions on the ASA against AD tho).&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Felix&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-identity-based-internet-access/m-p/903340#M421412</guid>
      <dc:creator>felixnkansah</dc:creator>
      <dc:date>2020-02-21T09:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Identity-Based Internet Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-identity-based-internet-access/m-p/903341#M421413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use HTTP cut through proxy feature for this. Cut through proxy would give users a log-in prompt when they try to access the web through the ASA. You can configure that login prompt to point to an authentication server. If they have a valid user name and password, it will let them through. If they don't, it will block access from their IP. There are basically two parts of configuration that you will need to do.&lt;/P&gt;&lt;P&gt;1) HTTP Proxy&lt;/P&gt;&lt;P&gt;2) LDAP setup on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The document link below shows how to configure an ASA to use LDAP as an authentication server&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/extsvr.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/extsvr.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2007 18:06:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-identity-based-internet-access/m-p/903341#M421413</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2007-10-15T18:06:37Z</dc:date>
    </item>
  </channel>
</rss>

