cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
260
Views
0
Helpful
1
Replies

PIX: Inbound http, secure-http-client, virtual http; combination??

nkleyn
Level 1
Level 1

Hi,

I hope someone can help me out.

I've a pix 515E 6.3(2), ACS for Unix 2.3(6), and a very simple webserver on the inside.

Outside users need to access the simple web-server on port 80. However they need to be authenticated/authorized with the aaa server (tacacs+)

The Userid and password challenge must be encrypted (https)

There are examples for aaa secure-http-client and also examples on virtual http.

I have big problems getting the combination working.

from the debug on AAA i see that the user is authenticated and authorization is allowed, but no redirection to the simple web-server happens, i keep getting the 'secure authentication screen' with a url http://virtual-ip,webserver-global-ip,webserver-global-ip/

when the 'stop' button is hit and then the url is typed in (webserver-global-ip) i get the right page?

b.t.w. i use IE 6.0

Any help or working examples or people who got this working???

Thanks in advance....

;-{

1 Reply 1

mhoda
Level 5
Level 5

Hi,

Pl. provide the snippet of the aaa config (chaning the actual ip) and the syslog messages if possible after logging level set to debugging.

Thanks,

Mynul

Review Cisco Networking for a $25 gift card