We have a POC using ASA5506-X running FTD image 6.2.3.5-52.
Included:
1. SSL Decryption -
Auto created when configuring Identity rule.
2. Identity -
Active Authentication with HTTP Basic and Guest fallback.
3. Access Control -
Rule #1 allows captive portal and DNS;
Rule #2 block user without successful authentication;
Rule #3 allow Internet for authenticated user;
Issues:
User without authentication is allowed to visit Facebook, YouTube and Google. All other HTTPS web sites will redirect to captive portal.
We notice special user 'Special Identities/Pending User' is allowing these traffic even without hitting any Access Control rule? Is this a bug?
We expect no traffic will pass through except the explicitly allowed captive portal and DNS.
Thanks.