Solved

Can Cisco ASA 5510 perform user authentication for internet access

Posted on 2008-06-23
4
2,020 Views
Last Modified: 2010-04-21
We are currently using Checkpoint at our head office and one of our remote sites. There is a site to site VPN and users at teh remote site use Checkpoint user accounts and Radius authentication for Internet access. Not all site personnel are allowed internet access.
We will be changing shortly to a full ASA, TACACS setup at head office with an MPLS connection to the remote site. Of course the timing of the MPLS installation is horrible. The Checkoint SPLAT box at the remote site is failing.
We would like to install an ASA5510 at the remote site. The VPN setup can be done, but I don't yet know how I can control Internet access at the site. Can this be done with an ASA or do I need some type of proxy server.
0
Comment
Question by:Potashcorp2
  • 2
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
AugustTen earned 500 total points
ID: 21847055
Hi, the ASA can be configured with "cut-through proxy" to challenge a user at the application layer and then authenticate against standard AAA servers or the local database.

This can be used together with filtering databases like Websense, integrated with LDAP, AD etc etc
0
 

Author Comment

by:Potashcorp2
ID: 21847135
This is probably what I want. Can you point me to any documentation on this?
We have not yet ordered the 5510 so I don't have manuals yet.
0
 
LVL 3

Expert Comment

by:AugustTen
ID: 21847188
Try this link:

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/fwaaa.html

This is very useful together with per-user downloadable ACL's for example.
0
 

Author Closing Comment

by:Potashcorp2
ID: 31469780
Thanks. That is exactly what I need.
Saved me doing hours of web searching.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will step through configuring a SonicWALL appliance to utilize an internal DHCP server for Global VPN Client (GVC) hosts.  There are times when using an external (external to the SonicWALL) DHCP server, such as Windows Servers, isn’t pr…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now