Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA Identity-Based Internet Access

Hi,

A client of mine is looking at controlling user access to the Internet based on identity. I know Microsoft ISA and other proxy solutions would do.

However, I am looking at leveraging their present installation of ASA and Microsoft AD to provide them with this function.

I know for sure that the ASA can be used to authenticate users on a web page against the AD and apply access rules accordingly (Identity-Based Access).

Unfortunately, I dont seem to be getting much info on the setup and configuration of this requirement.

If anyone knows of any source, please let me have the links. (I am not referring to authenticating telnet/ssh sessions on the ASA against AD tho).

Regards,

Felix

1 REPLY
Silver

Re: ASA Identity-Based Internet Access

You can use HTTP cut through proxy feature for this. Cut through proxy would give users a log-in prompt when they try to access the web through the ASA. You can configure that login prompt to point to an authentication server. If they have a valid user name and password, it will let them through. If they don't, it will block access from their IP. There are basically two parts of configuration that you will need to do.

1) HTTP Proxy

2) LDAP setup on the ASA

The document link below shows how to configure an ASA to use LDAP as an authentication server

http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/extsvr.html

133
Views
0
Helpful
1
Replies
CreatePlease login to create content