cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
448
Views
0
Helpful
1
Replies

AAA/RADIUS/IAS Authorization

Phil Williamson
Level 1
Level 1

I have my ASA5510 configured to authenticate VPN clients against an internal Win2003 IAS server. This works fine - users authenticate and can reach inside network. I have the ASA configured to allow HTTPS/ASDM access from the same inside net the users connect to - this is by necessity at this time, but I know not a good practice. The VPN clients once authenticated/connected to inside net can now https://ASA_Inside_Interface and authenticate with same credentials.

How do I prevent this?

Thx,

Phil

1 Reply 1

carenas123
Level 5
Level 5

The HTTPS/ASDM pane provides a table that specifies the addresses of all the hosts or networks that are allowed access to the ASDM using HTTPS. You can use this table to add or change the hosts or networks that are allowed access.Refer the URL

http://www.cisco.com/en/US/products/ps6121/products_user_guide_chapter09186a00806a2f1a.html#wp1218686