11-25-2004 04:16 AM - edited 02-20-2020 11:46 PM
Hi,
Can I configure the PIX cut-through proxy feature to authenticate using a local user database and have different access-lists for each user - all defined on the PIX rather than in a RADIUS server? If so, what commands shoudl I use?
Thanks
Stuart
12-01-2004 01:41 PM
You should be able to do this with the PIX downloadable access-lists and xauth. Here is the configuration document that might help.
12-01-2004 05:50 PM
NO you cannot do this with local the local user DB, on
This is because this is an AUTHORIZATION command and local users are just an AUTHENTICATION.
The only way to do this is with a Radius Server.
sincerely
Patrick
12-02-2004 05:12 AM
I thought that might be the case. Thanks for the help.
Stuart
12-02-2004 06:37 AM
Stuart,
there are many open source and even a Windows Radius server available, you do not need to use the Cisco ACS even if it this is a good and flexible application.
Overview:
http://dmoz.org/Computers/Security/Authentication/RADIUS/Server/
Windows IAS Service:
http://www.microsoft.com/windows2000/techinfo/howitworks/communications/remoteaccess/ias.asp
http://www.microsoft.com/windows2000/techinfo/administration/radius.asp
Linux Radius OpenSource:
sincerely
Patrick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide