cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
908
Views
0
Helpful
10
Replies

cisco web security appliance local authentication

ezzaariyouness
Level 1
Level 1

Hello Everyone,

I Cisco Web Security Appliance S395 Version 14.5.1 , I'm trying to set up local authentication for users Proxy, Can You please help about configuration steps because I didn't find any doc about that.

Best regards

Younes

2 Accepted Solutions

Accepted Solutions

Short answer NO - the document i have provided only offer certain source be used to authentication purpose ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

Correct, it's not possible on WSA.
Your options are
AD via NTLM or Kerberos
Or
LDAP

View solution in original post

10 Replies 10

balaji.bandi
Hall of Fame
Hall of Fame

user authentication against local users created in WSA (there are some limitations)

check the authentication how it works :

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_01001.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I didn'  see in the document how Can I create local users on the WSA, then performs authentication again those users.

Short answer NO - the document i have provided only offer certain source be used to authentication purpose ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank You for your Answer . 

Local authentication as in the WSA maintains users and passwords?

The WSA has no facilities for that, it wants AD or LDAP.

Yes, Local authentication as in the WSA maintains users and passwords 

is that not possible with WSA ?

Correct, it's not possible on WSA.
Your options are
AD via NTLM or Kerberos
Or
LDAP

Thank You, @Ken Stieers  for your Answer. 

amojarra
Cisco Employee
Cisco Employee

Hello @ezzaariyouness 

in case, you need to have couple of custom policies, you can create some Id profile with IP address, and configure those rules for those clients, if they are having fixed IP address, on separate Network address.

Else as mentioned above, you need to define your users in Directory service.

 

Regards,

Amirhossein Mojarrad

+++++++++++++++++++++++++++++++++++++++++++++++++++

++++        If you find this answer helpful, please rate it as such      ++++

+++++++++++++++++++++++++++++++++++++++++++++++++++

 

 

ezzaariyouness
Level 1
Level 1

Hi @amojarra ,

Yeah, I see that, I issue That I'm migrating Policy form other Proxy that have Local Authentication.