06-15-2001 10:11 AM - edited 02-21-2020 09:57 AM
I knew that AAA can be easily set to control VPN connection from outsite. How about controlling traffic from inside to outside?
06-21-2001 12:16 PM
Most firewalls support outbound authentication with AAA. We use the PIX and Cisco Secure ACS for outbound authentication. Works well. It might be a little trickier with controlling outbound VPN since the PIX doesnt have anyway to proxy the authentication for that but you can use http, ftp or telnet to authenticate the user first, then open the VPN ports/protocols.
06-22-2001 10:46 AM
As your message mentioned, PIX support outbound authentication with AAA. Should it be done to all outbound traffic including VPN outbound?
BTW, can PIX support outbound authentication with Microsoft Radius? Must user authenticate on screen instead of passing workstations' login information when outbound connection is going to make?
06-25-2001 12:44 PM
If you want to authenticate outbound VPN on the PIX then youll have to authenticate everything outbound and use http, telnet or ftp to authenticate your outbound traffic. Once authenticated, all ports and protocols will open and the user can setup and use VPN. You can build AAA exception statements for specific hosts like mail servers and/or administrators. Im not familiar with Microsofts RADIUS but I would guess its standard RADIUS, which is supported by the PIX. You might look at Cisco Secure ACS. It integrates with the Microsoft domain authentication database smoothly.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide