<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA authentication proxy using ACS for authorization in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-authentication-proxy-using-acs-for-authorization/m-p/998723#M938947</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;I configured the ASA as an authentication proxy. So any user want to telnet to using port 3001, or using port 23 should first authenticate to virtual telnet address and then ACS will authorized the user: &lt;/P&gt;&lt;P&gt;aaa authentication include telnet 0 0 10.1.1.1 TAC &lt;/P&gt;&lt;P&gt;aaa authorizaion include telnet inside 0 0 TAC &lt;/P&gt;&lt;P&gt;aaa authorization include tcp/3000 inside 0 0 TAC &lt;/P&gt;&lt;P&gt;virtual telnet 10.1.1.1 &lt;/P&gt;&lt;P&gt;I configured the acs as the following: &lt;/P&gt;&lt;P&gt;enable shell with privilage 15 &lt;/P&gt;&lt;P&gt;permit command telent (permit any urgments) &lt;/P&gt;&lt;P&gt;permit command 6/3001 (permit any arguments). &lt;/P&gt;&lt;P&gt;So I am authenticated with virtual telnet and can do telnet only with port 23 but not with port 3001. I double my configuration a lot and didn't find any mistake. According to Cisco documentation I should add command 6/3001 (6 is tcp protocol number) but it is not working with me. So please advice !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:34:27 GMT</pubDate>
    <dc:creator>abdullah-asi</dc:creator>
    <dc:date>2019-03-11T12:34:27Z</dc:date>
    <item>
      <title>ASA authentication proxy using ACS for authorization</title>
      <link>https://community.cisco.com/t5/network-security/asa-authentication-proxy-using-acs-for-authorization/m-p/998723#M938947</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;I configured the ASA as an authentication proxy. So any user want to telnet to using port 3001, or using port 23 should first authenticate to virtual telnet address and then ACS will authorized the user: &lt;/P&gt;&lt;P&gt;aaa authentication include telnet 0 0 10.1.1.1 TAC &lt;/P&gt;&lt;P&gt;aaa authorizaion include telnet inside 0 0 TAC &lt;/P&gt;&lt;P&gt;aaa authorization include tcp/3000 inside 0 0 TAC &lt;/P&gt;&lt;P&gt;virtual telnet 10.1.1.1 &lt;/P&gt;&lt;P&gt;I configured the acs as the following: &lt;/P&gt;&lt;P&gt;enable shell with privilage 15 &lt;/P&gt;&lt;P&gt;permit command telent (permit any urgments) &lt;/P&gt;&lt;P&gt;permit command 6/3001 (permit any arguments). &lt;/P&gt;&lt;P&gt;So I am authenticated with virtual telnet and can do telnet only with port 23 but not with port 3001. I double my configuration a lot and didn't find any mistake. According to Cisco documentation I should add command 6/3001 (6 is tcp protocol number) but it is not working with me. So please advice !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:34:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-authentication-proxy-using-acs-for-authorization/m-p/998723#M938947</guid>
      <dc:creator>abdullah-asi</dc:creator>
      <dc:date>2019-03-11T12:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA authentication proxy using ACS for authorization</title>
      <link>https://community.cisco.com/t5/network-security/asa-authentication-proxy-using-acs-for-authorization/m-p/998724#M938948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try putting fixup protocol telnet 3001&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 12:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-authentication-proxy-using-acs-for-authorization/m-p/998724#M938948</guid>
      <dc:creator>rkalia1</dc:creator>
      <dc:date>2008-04-22T12:20:59Z</dc:date>
    </item>
  </channel>
</rss>

