<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict RDP access with local credentials in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/restrict-rdp-access-with-local-credentials/m-p/1389402#M735443</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you're looking for the ASA Firewall Session Authentication feature (cut-through proxy features on PIX)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It requires the user to authenticate before passing any traffic through the ASA.&lt;/P&gt;&lt;P&gt;The only issue is that you do need a AAA server.&amp;nbsp; Can't be done against the local database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Mar 2010 22:33:48 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-03-12T22:33:48Z</dc:date>
    <item>
      <title>Restrict RDP access with local credentials</title>
      <link>https://community.cisco.com/t5/network-security/restrict-rdp-access-with-local-credentials/m-p/1389401#M735415</link>
      <description>&lt;P&gt;I have a client who is using an ASA5510 and wants to limit RDP access to a specific server by login credentials.&amp;nbsp; They don't use any AAA servers for authentication now, just local accounts created on the firewall.&amp;nbsp; Configuring the static NAT and the ACL to allow RDP to the server from the outside isn't an issue but I don't know how to make the firewall check for credentials before it allows the connection.&amp;nbsp; Is this possible?&amp;nbsp; If so, can I use local users?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restrict-rdp-access-with-local-credentials/m-p/1389401#M735415</guid>
      <dc:creator>qbakies11</dc:creator>
      <dc:date>2019-03-11T17:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict RDP access with local credentials</title>
      <link>https://community.cisco.com/t5/network-security/restrict-rdp-access-with-local-credentials/m-p/1389402#M735443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you're looking for the ASA Firewall Session Authentication feature (cut-through proxy features on PIX)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It requires the user to authenticate before passing any traffic through the ASA.&lt;/P&gt;&lt;P&gt;The only issue is that you do need a AAA server.&amp;nbsp; Can't be done against the local database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Mar 2010 22:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restrict-rdp-access-with-local-credentials/m-p/1389402#M735443</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-03-12T22:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict RDP access with local credentials</title>
      <link>https://community.cisco.com/t5/network-security/restrict-rdp-access-with-local-credentials/m-p/1389403#M735478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you can authenticate a user directly against a virtual server (the ASA itself), via HTTP/HTTPS, telnet or FTP to be able to redirect it to any other service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_fwaaa.html#wp1046750"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_fwaaa.html#wp1046750&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Mar 2010 22:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restrict-rdp-access-with-local-credentials/m-p/1389403#M735478</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-03-12T22:47:21Z</dc:date>
    </item>
  </channel>
</rss>

