Solved

Can Cisco ASA 5510 perform user authentication for internet access

Posted on 2008-06-23
4
2,022 Views
Last Modified: 2010-04-21
We are currently using Checkpoint at our head office and one of our remote sites. There is a site to site VPN and users at teh remote site use Checkpoint user accounts and Radius authentication for Internet access. Not all site personnel are allowed internet access.
We will be changing shortly to a full ASA, TACACS setup at head office with an MPLS connection to the remote site. Of course the timing of the MPLS installation is horrible. The Checkoint SPLAT box at the remote site is failing.
We would like to install an ASA5510 at the remote site. The VPN setup can be done, but I don't yet know how I can control Internet access at the site. Can this be done with an ASA or do I need some type of proxy server.
0
Comment
Question by:Potashcorp2
  • 2
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
AugustTen earned 500 total points
ID: 21847055
Hi, the ASA can be configured with "cut-through proxy" to challenge a user at the application layer and then authenticate against standard AAA servers or the local database.

This can be used together with filtering databases like Websense, integrated with LDAP, AD etc etc
0
 

Author Comment

by:Potashcorp2
ID: 21847135
This is probably what I want. Can you point me to any documentation on this?
We have not yet ordered the 5510 so I don't have manuals yet.
0
 
LVL 3

Expert Comment

by:AugustTen
ID: 21847188
Try this link:

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/fwaaa.html

This is very useful together with per-user downloadable ACL's for example.
0
 

Author Closing Comment

by:Potashcorp2
ID: 31469780
Thanks. That is exactly what I need.
Saved me doing hours of web searching.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a computer or other electronic gear that is attached to a rat nest of cables, or alternatively have your cables all bundled nice at neat?  If so then read this post to sidstep common pitfalls. When I was a student at DeVry University,…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question