05-16-2003 06:59 AM - edited 02-21-2020 10:06 AM
Feature: IOS firewall - Authentication Proxy
Question 1: Can Auth Proxy be configured on a Tunnel interface ?
Question 2: Can an Auth Proxy ACL be configured such that a specific destination address or network will trigger the auth proxy rather than a specific source address ?
peteb
05-19-2003 12:02 AM
1. No, the packet will be a GRE packet, not a HTTP packet. Actually, I can't say I've ever tried it, but I doubt it would work.
2. No, the ACL is only a standard IP ACL, not an extended one, and it only looks at the source address of the packet to match the ACL entry.
05-19-2003 05:57 AM
Your answer 1 -
What if the Tunnel is on my inside interface and I configure the auth-proxy command & ACL on the Tunnel originating end to intercept traffic from the inside to the outside, can't I make the auth-proxy command process before the tunnel encapsulation ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide