<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Client Authentication, one URL possible? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aaa-client-authentication-one-url-possible/m-p/1023515#M939570</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can prevent unauthorized users from reconfiguring your switch and viewing configuration information. Typically, you want network administrators to have access to your switch while you restrict access to users who dial from outside the network through an asynchronous port, connect from outside the network through a serial port, or connect through a terminal or workstation from within the local network &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_35_se/configuration/guide/swauthen.html" target="_blank"&gt;http://cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_35_se/configuration/guide/swauthen.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Apr 2008 12:04:43 GMT</pubDate>
    <dc:creator>ebreniz</dc:creator>
    <dc:date>2008-04-15T12:04:43Z</dc:date>
    <item>
      <title>AAA Client Authentication, one URL possible?</title>
      <link>https://community.cisco.com/t5/network-security/aaa-client-authentication-one-url-possible/m-p/1023514#M939569</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a FWSM in use with some 3.1.x software on it. The clients are authenticated via http AAA login box.&lt;/P&gt;&lt;P&gt;We would love to switch to https instead of http.&lt;/P&gt;&lt;P&gt;My tests have shown now that the https URL is always the one the client typed in into his browser. This produces an "invalid certificate" message on his browser. This is something which we can't use, so I try to get a signed certificate on the FWSM.&lt;/P&gt;&lt;P&gt;The problem now is, this URL is random and won't be changed to the hostname of the FWSM. Is it possible to change that behaviour?&lt;/P&gt;&lt;P&gt;Something like: &lt;/P&gt;&lt;P&gt;- client opens http(s)://&lt;A href="http://www.test.com" target="_blank"&gt;www.test.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- client gets redirected to &lt;A class="jive-link-custom" href="https://fwsm.domain.com" target="_blank"&gt;https://fwsm.domain.com&lt;/A&gt; and gets no invalid certificate message (because fwsm.domain.com has a valid certificate)&lt;/P&gt;&lt;P&gt;- after valid authentification gets back to http(s)://&lt;A href="http://www.test.com" target="_blank"&gt;www.test.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that somehow possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-client-authentication-one-url-possible/m-p/1023514#M939569</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-03-11T12:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Client Authentication, one URL possible?</title>
      <link>https://community.cisco.com/t5/network-security/aaa-client-authentication-one-url-possible/m-p/1023515#M939570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can prevent unauthorized users from reconfiguring your switch and viewing configuration information. Typically, you want network administrators to have access to your switch while you restrict access to users who dial from outside the network through an asynchronous port, connect from outside the network through a serial port, or connect through a terminal or workstation from within the local network &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_35_se/configuration/guide/swauthen.html" target="_blank"&gt;http://cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_35_se/configuration/guide/swauthen.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Apr 2008 12:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-client-authentication-one-url-possible/m-p/1023515#M939570</guid>
      <dc:creator>ebreniz</dc:creator>
      <dc:date>2008-04-15T12:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Client Authentication, one URL possible?</title>
      <link>https://community.cisco.com/t5/network-security/aaa-client-authentication-one-url-possible/m-p/1023516#M939571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's absolutely not what I need. &lt;/P&gt;&lt;P&gt;Please read my post again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do client authentication through tacacs over http on the FWSM.&lt;/P&gt;&lt;P&gt;After the client is successfully authenticated, he gets an xlate in the FWSM and is allowed to use the network.&lt;/P&gt;&lt;P&gt;We'd like to switch that authentication now to https.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Apr 2008 14:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-client-authentication-one-url-possible/m-p/1023516#M939571</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2008-04-15T14:16:15Z</dc:date>
    </item>
  </channel>
</rss>

