Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA Identity-Based Internet Access


A client of mine is looking at controlling user access to the Internet based on identity. I know Microsoft ISA and other proxy solutions would do.

However, I am looking at leveraging their present installation of ASA and Microsoft AD to provide them with this function.

I know for sure that the ASA can be used to authenticate users on a web page against the AD and apply access rules accordingly (Identity-Based Access).

Unfortunately, I dont seem to be getting much info on the setup and configuration of this requirement.

If anyone knows of any source, please let me have the links. (I am not referring to authenticating telnet/ssh sessions on the ASA against AD tho).




Re: ASA Identity-Based Internet Access

You can use HTTP cut through proxy feature for this. Cut through proxy would give users a log-in prompt when they try to access the web through the ASA. You can configure that login prompt to point to an authentication server. If they have a valid user name and password, it will let them through. If they don't, it will block access from their IP. There are basically two parts of configuration that you will need to do.

1) HTTP Proxy

2) LDAP setup on the ASA

The document link below shows how to configure an ASA to use LDAP as an authentication server

CreatePlease login to create content