cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
328
Views
0
Helpful
4
Replies

ASA 5510 Auth for site-to-site VPN users

dino55088
Level 1
Level 1

hi,

is there a way we can get the ASA to prompt site-to-site VPN users to authenticate to ASA/RADIUS before they can access head end resources behind ASA such as Sharepoint etc that are allowed in via respective VPN ACLs?

1 Accepted Solution

Accepted Solutions

Philip D'Ath
VIP Alumni
VIP Alumni

I've never done it, but you should be able to use "Cut Through" authentication.

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113363-asa-cut-through-config-00.html

Basically the user has little or no access, and the ASA intercepts a request, such as via HTTP, and then authenticates the session.  After that the user can access whatever you allow them to.

View solution in original post

4 Replies 4

Philip D'Ath
VIP Alumni
VIP Alumni

I've never done it, but you should be able to use "Cut Through" authentication.

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113363-asa-cut-through-config-00.html

Basically the user has little or no access, and the ASA intercepts a request, such as via HTTP, and then authenticates the session.  After that the user can access whatever you allow them to.

yes was looking at this thanks. I have not tried either but was wondering how it would handle multiple clients being NATed behind one source on the way in from remote site

I don't think it would work with NAT.  Can you remove the NAT over the VPN?

some B-to-B partnerswant single IP presented to s so not sure.

Thanks for the tip anyhow.