1-27
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 1 Overview of Cisco Secure ACS
Cisco Secure ACS HTML Interface
From the server on which Cisco Secure ACS is installed, you can also use the
following URLs:
•
http://127.0.0.1:2002
•
http://hostname:2002
where hostname is the hostname of the computer running Cisco Secure ACS.
Network Environments and Remote Administrative Sessions
We recommend that remote administrative sessions take place without the use of
an HTTP proxy server, without a firewall between the remote browser and
Cisco Secure ACS, and without a NAT gateway between the remote browser and
Cisco Secure ACS. Because these limitations are not always practical, we
included the following topics regarding these remote administration scenarios:
•
Remote Administrative Sessions and HTTP Proxy, page 1-27
•
Remote Administrative Sessions through Firewalls, page 1-28
•
Remote Administrative Sessions through a NAT Gateway, page 1-28
Remote Administrative Sessions and HTTP Proxy
Cisco Secure ACS does not support HTTP proxy for remote administrative
sessions. If the browser used for a remote administrative session is configured to
use a proxy server, Cisco Secure ACS sees the administrative session originating
from the IP address of the proxy server rather than from the actual address of the
remote workstation. Remote administrative session tracking assumes each
browser resides on a workstation with a unique IP.
Also, IP filtering of proxied administrative sessions has to be based on the IP
address of the proxy server rather than the IP address of the workstation. This
conflicts with administrative session communication that does use the actual IP
address of the workstation. For more information about IP filtering of remote
administrative sessions, see
Access Policy, page 10-11
.
For these reasons, we do not recommend performing administrative sessions
using a web browser that is configured to use a proxy server. Administrative
sessions using a proxy-enabled web browser is not tested. If your web browser is
configured to use a proxy server, disable HTTP proxying when attempting remote
Cisco Secure ACS administrative sessions.