cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1375
Views
1
Helpful
2
Replies

config of authentication proxy

peter.brooks
Level 1
Level 1

Feature: IOS firewall - Authentication Proxy

Question 1: Can Auth Proxy be configured on a Tunnel interface ?

Question 2: Can an Auth Proxy ACL be configured such that a specific destination address or network will trigger the auth proxy rather than a specific source address ?

peteb

2 Replies 2

gfullage
Cisco Employee
Cisco Employee

1. No, the packet will be a GRE packet, not a HTTP packet. Actually, I can't say I've ever tried it, but I doubt it would work.

2. No, the ACL is only a standard IP ACL, not an extended one, and it only looks at the source address of the packet to match the ACL entry.

Your answer 1 -

What if the Tunnel is on my inside interface and I configure the auth-proxy command & ACL on the Tunnel originating end to intercept traffic from the inside to the outside, can't I make the auth-proxy command process before the tunnel encapsulation ?