06-20-2016 05:55 PM
hi,
is there a way we can get the ASA to prompt site-to-site VPN users to authenticate to ASA/RADIUS before they can access head end resources behind ASA such as Sharepoint etc that are allowed in via respective VPN ACLs?
Solved! Go to Solution.
06-20-2016 10:30 PM
I've never done it, but you should be able to use "Cut Through" authentication.
Basically the user has little or no access, and the ASA intercepts a request, such as via HTTP, and then authenticates the session. After that the user can access whatever you allow them to.
06-20-2016 10:30 PM
I've never done it, but you should be able to use "Cut Through" authentication.
Basically the user has little or no access, and the ASA intercepts a request, such as via HTTP, and then authenticates the session. After that the user can access whatever you allow them to.
06-21-2016 05:07 AM
yes was looking at this thanks. I have not tried either but was wondering how it would handle multiple clients being NATed behind one source on the way in from remote site
06-21-2016 12:56 PM
I don't think it would work with NAT. Can you remove the NAT over the VPN?
06-21-2016 03:40 PM
some B-to-B partnerswant single IP presented to s so not sure.
Thanks for the tip anyhow.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide