Authentication Overview; One-Time Authentication; Applications Required To Receive An Authentication Challenge; Fwsm Authentication Prompts - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Configuring Authentication for Network Access

Authentication Overview

The FWSM lets you configure network access authentication using AAA servers. This section includes
the following topics:

One-Time Authentication

A user at a given IP address only needs to authenticate one time for all rules and types, until the
authentication session expires. (See the timeout uauth command in the Catalyst 6500 Series Switch and
Cisco 7600 Series Router Firewall Services Module Command Reference for timeout values.) For
example, if you configure the FWSM to authenticate Telnet and FTP, and a user first successfully
authenticates for Telnet, then as long as the authentication session exists, the user does not also have to
authenticate for FTP.
For HTTP or HTTPS authentication, once authenticated, a user never has to reauthenticate, no matter
how low the timeout uauth command is set, because the browser caches the string
"Basic=Uuhjksdkfhk==" in every subsequent connection to that particular site. This can be cleared only
when the user exits all instances of the web browser and restarts. Flushing the cache is of no use.

Applications Required to Receive an Authentication Challenge

Although you can configure the FWSM to require authentication for network access to any protocol or
service, users can authenticate directly with HTTP, HTTPS, Telnet, or FTP only. A user must first
authenticate with one of these services before the FWSM allows other traffic requiring authentication.
The authentication ports that the FWSM supports for AAA are fixed:

FWSM Authentication Prompts

For Telnet and FTP, the FWSM generates an authentication prompt. After you authenticate correctly, the
FWSM redirects you to your original destination. If the destination server also has its own
authentication, you enter another username and password.
For HTTP, you log in using basic HTTP authentication supplied by the browser. For HTTPS, the FWSM
generates custom login windows.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
17-2
One-Time Authentication, page 17-2
Applications Required to Receive an Authentication Challenge, page 17-2
Static PAT and HTTP, page 17-3
Authenticating Directly with the FWSM, page 17-3
Port 21 for FTP
Port 23 for Telnet
Port 80 for HTTP
Port 443 for HTTPS
Chapter 17
Applying AAA for Network Access
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents