WEBVPN Authentication

Answered Question
Aug 20th, 2008
User Badges:

Hi,

We have setup SSLVPN on a Cisco 3800 to host VPN for IP Communicator (VOIP). IOS = IOS AdvanceSecurity 12.4-15(T) and Cisco Secure ACS v3.0

We have trialed an authentication method by using our existing TACACS+ server to host the AAA for the SSLVPN but the problem is the same user account can login to our routers using the same TACACS+.

Is there a way to permit SSLVPN auth for VOIP use and deny access to our routers using the same AAA server?

Correct Answer by Premdeep Banga about 8 years 7 months ago

As your Tacacs+ is ACS, then you can make use of NAR (Network Access Restriction).


Users will be prompted for username/password if device is configured for the same, but they wont be able to telnet/ssh into the Network Device. But should be able to do VPN.


Please go through what attributes are evaluated for a NAR to be applied,

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml


Regards,

Prem


Please rate if it helps!

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Marwan ALshawi Thu, 08/21/2008 - 03:34
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

if u are giveing users a pool of IPs through the ssl vpn u can u se an ACL on the outside interface that allow only access to the voip network and deny anything els!

Peter Valdes Thu, 08/21/2008 - 15:14
User Badges:

Hi, Thanks for the reply.

The part has been secured. The problem is when they are not using the VPN. Normal ADSL connection and if they know the public IP Address of one router, they can VTY/SSH to it using their TACACS+ account.


VTY has ACL already to only allow our internal network in. SSH is for outside use.


I should have included this on the first message to be more clearer.

Is there a setup on the TACACS+ to deny VTY/SSH use of the accounts?


Thanks

Marwan ALshawi Thu, 08/21/2008 - 20:27
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

in this case you need to use AUth proxy if ur router include IOS firewall feature

this way u can spisify whay ports are allowed and use source and distination IPs.

Correct Answer
Premdeep Banga Fri, 08/22/2008 - 04:40
User Badges:
  • Gold, 750 points or more

As your Tacacs+ is ACS, then you can make use of NAR (Network Access Restriction).


Users will be prompted for username/password if device is configured for the same, but they wont be able to telnet/ssh into the Network Device. But should be able to do VPN.


Please go through what attributes are evaluated for a NAR to be applied,

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml


Regards,

Prem


Please rate if it helps!

Peter Valdes Fri, 08/22/2008 - 06:02
User Badges:

Thanks. I will try this and let you know on the result.


Thanks again for your replies.


Peter

Marwan ALshawi Sun, 08/24/2008 - 19:47
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

Prem this is 5+ from me :)

Actions

This Discussion