
17-2
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 17 Applying AAA for Network Access
Configuring Authentication for Network Access
Authentication Overview
The FWSM lets you configure network access authentication using AAA servers. This section includes
the following topics:
•
One-Time Authentication, page 17-2
•
Applications Required to Receive an Authentication Challenge, page 17-2
•
Static PAT and HTTP, page 17-3
•
Authenticating Directly with the FWSM, page 17-3
One-Time Authentication
A user at a given IP address only needs to authenticate one time for all rules and types, until the
authentication session expires. (See the
timeout uauth
command in the
Catalyst 6500 Series Switch and
Cisco 7600 Series Router Firewall Services Module Command Reference
for timeout values.) For
example, if you configure the FWSM to authenticate Telnet and FTP, and a user first successfully
authenticates for Telnet, then as long as the authentication session exists, the user does not also have to
authenticate for FTP.
For HTTP or HTTPS authentication, once authenticated, a user never has to reauthenticate, no matter
how low the
timeout uauth
command is set, because the browser caches the string
“Basic=Uuhjksdkfhk==” in every subsequent connection to that particular site. This can be cleared only
when the user exits
all
instances of the web browser and restarts. Flushing the cache is of no use.
Applications Required to Receive an Authentication Challenge
Although you can configure the FWSM to require authentication for network access to any protocol or
service, users can authenticate directly with HTTP, HTTPS, Telnet, or FTP only. A user must first
authenticate with one of these services before the FWSM allows other traffic requiring authentication.
The authentication ports that the FWSM supports for AAA are fixed:
•
Port 21 for FTP
•
Port 23 for Telnet
•
Port 80 for HTTP
•
Port 443 for HTTPS
FWSM Authentication Prompts
For Telnet and FTP, the FWSM generates an authentication prompt. After you authenticate correctly, the
FWSM redirects you to your original destination. If the destination server also has its own
authentication, you enter another username and password.
For HTTP, you log in using basic HTTP authentication supplied by the browser. For HTTPS, the FWSM
generates custom login windows.
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......