Im working on a http autentication from the outside network (Internet)on my PIX IOS 6.31.The extended autentication is with RSA RADIUS platform.
All works fine but when the token goes on the "next token code" after bad password,the RSA server pop-up
to wait for the token to change.We do this but the problem of the cached credencials of the Browser does not permit to acomplish the change.
For this cases,Cisco say to use the virtual http command.But I have some questions:
1.The IP use for this must be a routable IP of My CIDR or a internal NOT-CIDR IP?.Does it make diference?
2.I have a web server published on it?
3.If Not ,I will need translations slot end access-rules for this FAKE IP ?