cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
968
Views
0
Helpful
1
Replies

uauth for session base authentication

farancci
Level 1
Level 1

Hi,

Here is our current setup.

If users tries to access production network they are prompted by PIX for authentication, PIX pass there credentials to ACS server and if sucessfull the machine from whcih the user accessed network gets authenticated for 24 Hrs.

Here is what we are trying to achieve!

Rather then authenticated for 24 hrs we want to authenticate users on per session base ( each time they try to access production they should be prompted for authentication) this can be done by changing uauth absolute value to 0 however we want certain groups to be authenticated once in 24 hrs. we have created different groups in ACS server and tried that but everyone gets prompted for each session its look like ACS policies can not takeover the PIX uauth timer.

Any suggestion?

1 Reply 1

jsivulka
Level 5
Level 5

See if the documentation for configuring authentication on PIX is of any help. It's available at http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e71.shtml