04-12-2002 11:52 PM - edited 02-21-2020 09:59 AM
Dear All,
How do we authenticate a citrix ica traffic (port 1494) across the pix (from outside to inside using a public ip address). I have cisco acs authenticating the http/ftp but i dont know how to authenticate based on a port 1494 access ?
when a user initialises to connect using a ica client - i want pix to throw an authentication window like how it does for the web client (http) access.
Thanks & Regards
Fiyaz
04-22-2002 06:05 AM
The PIX can only authenticate against HTTP, Telnet or FTP. Youll have to authenticate your users against one of those. We use http and redirect them to Citrix after authentication.
04-22-2002 08:14 AM
How did you do that? I am trying to get users on my internal network to be able to connect using a terminal server client (port 3389), but want them to authenticate as they pass the firewall.
04-24-2002 05:51 AM
Just have your user browse to a web server setup with AAA and then after successful authentication
04-24-2002 05:41 AM
What we do here is:
1) NAS (or PIX) Authenticate the client on port 80.
2) NAS (or PIX) Authorize the client on port 1494.
3) Define these NAS AAA-rules in ACS for the specific Domain-Group.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide