cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1941
Views
0
Helpful
4
Replies

pix authenticate port 1494

aneadmin
Level 1
Level 1

Dear All,

How do we authenticate a citrix ica traffic (port 1494) across the pix (from outside to inside using a public ip address). I have cisco acs authenticating the http/ftp but i dont know how to authenticate based on a port 1494 access ?

when a user initialises to connect using a ica client - i want pix to throw an authentication window like how it does for the web client (http) access.

Thanks & Regards

Fiyaz

4 Replies 4

s-doyle
Level 3
Level 3

The PIX can only authenticate against HTTP, Telnet or FTP. You’ll have to authenticate your users against one of those. We use http and redirect them to Citrix after authentication.

How did you do that? I am trying to get users on my internal network to be able to connect using a terminal server client (port 3389), but want them to authenticate as they pass the firewall.

Just have your user browse to a web server setup with AAA and then after successful authentication

mpalardy
Level 3
Level 3

What we do here is:

1) NAS (or PIX) Authenticate the client on port 80.

2) NAS (or PIX) Authorize the client on port 1494.

3) Define these NAS AAA-rules in ACS for the specific Domain-Group.