cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1151
Views
0
Helpful
5
Replies

HTTP Auth-proxy on Cisco Routers

dardanarusha
Level 1
Level 1

Imagine a scenario like this: behind the AP there is a Cisco Router. When clients hooked up to the AP try to open a web page, the Cisco Router asks them to authentificate. The users enter their username and password, the router checks this with the RADIUS and authorizes the users.

You can do something like this with the ip auth-proxy, but it works only for HTTP traffic. What about any traffic? Whats the Cisco solution for these kind of scenarios?

Thanks in advance,

Dardan

5 Replies 5

a.awan
Level 4
Level 4

It seems as if you want user authentication to happen before a user can basically start using the network ... right? There is a solution for this kind of requirement but it is not a Cisco proprietary solution, rather it is a standards based solution and goes by the name of 802.1x. Cisco does support this feature on most of its switches and also on Access Points. In your particular case it will be the access point authenticating the users via a Radius backend rather than the router. One thing to keep in mind is that the users will require an 802.1x client on their machines to be able to authenticate using this technology.

Yes and no. We want basically to allow users to associate and synchronize with the AP and the router, through RADIUS checking of the username and password to authorize users to use network resources. On some of Cisco documents we saw that Cisco has a solution with AZRs and SSGs etc, but not so sure as how it is done, hardware and software wise.

From what you describe it seems as you are trying to deploy a PWLAN (Public Wireless LAN) setup. Yes Cisco has a solution for that and it does use SSGs and AZRs amongst other devices based on requirements.

http://www.cisco.com/en/US/partner/netsol/ns341/ns396/ns177/ns436/networking_solutions_package.html

If you requirement is not a PWLAN then can you specify exactly what you want to accomplish?

Yes, I have read something for PWLAN and it fits our needs perfectly. I want to read more about the details. This link doesn't work for me, I enter two CCO accounts usernames and passwords we have but with both of them I get "Authentication Required/Forgotten Password". The username/passwords work elsewhere in Cisco site.

Please advise further,

Dardan

Sorry about that. I forgot i was logged on when i browsed that link. The following link is a public version of the same:

http://www.cisco.com/en/US/netsol/ns341/ns396/ns177/ns436/networking_solutions_package.html

It is probably not going to be all that you are looking for but the pdf version of the power point intended for technical decision makers will provide you with more insight into Cisco's solution for this service.