11-02-2004 01:50 AM - edited 03-10-2019 01:52 PM
I'm running authentication proxy on an IOS firewall. Is it possible to have it interact with ACS 3.2 on windows so that incoming HTTP users are aoffered the possibility to change their password either when it expires or when they log on for the first time (apply password change rule checked in on ACS)
11-08-2004 07:00 AM
To configure the ACS 3.2 User-Changeable Passwords feature, please refer to the document at http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs32/ucp.htm. Also, I dont see why you feel that the IOS firewall might not work with ACS. I guess that normal commandnecessary to configure AA on a router should be sufficient.
11-08-2004 08:01 AM
I feel it might not work because:
1) Imagine I create a new user and give him a password that must be changed at first log in.
2) When the user wants to access my internal HTTP servers his request is intercepted by the Auth-Proxy and he is prompted by a Log-In windows that sends its userID/Password to ACS for authentication.
3) from the tests I've made it is not possible for the user to change his password from the Log-in windows sent by the Auth-Proxy (my IOS firewall). The result is that the user is not able to log in to my internal HTTP servers and is disabled by ACS?
Therefore as you suggested, I must install UCP but have it accessible before the HTTP request reaches by IOS Firewall. This is technically feasible but I'm reluctant to have an HTTP server so "easily" accessible from outside.
But I may have missed something too .....
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide