Authenticating Directly with the Security Appliance

If you do not want to allow HTTP, HTTPS, Telnet, or FTP through the security appliance but want to authenticate other types of traffic, you can authenticate with the security appliance directly using HTTP, HTTPS, or Telnet.

This section includes the following topics:

• Enabling Direct Authentication Using HTTP and HTTPS, page 19-6

• Enabling Direct Authentication Using Telnet, page 19-6

Enabling Direct Authentication Using HTTP and HTTPS

If you enabled the redirect method of HTTP and HTTPS authentication in the "Enabling Network Access Authentication" section on page 19-3, then you also automatically enabled direct authentication. If you want to continue to use basic HTTP authentication, but want to enable direct authentication for HTTP and HTTPS, then enter the following command:

hostname(config)# aaa authentication listener http[s] interface_name [port portnum]

where the interface_name argument is the interface on which you want to enable direct authentication.

The port portnum argument specifies the port number that the security appliance listens on; the defaults are 80 (HTTP) and 443 (HTTPS).

Enter this command separately for HTTP and for HTTPS.

You can authenticate directly with the security appliance at the following URLs when you enable AAA for the interface:

http://interface_ip[sport]/netaccess/connstatus.html https://interface_ip[sport]/netaccess/connstatus.html

Enabling Direct Authentication Using Telnet

To enable direct authentication with Telnet, configure a virtual Telnet server. With virtual Telnet, the user Telnets to a given IP address configured on the security appliance, and the security appliance provides a Telnet prompt. To configure a virtual Telnet server, enter the following command:

hostname(config)# virtual telnet ip_address where the ip_address argument sets the IP address for the virtual Telnet server. Make sure this address is an unused address that is routed to the security appliance. For example, if you perform NAT for inside addresses when they access the outside, and you want to provide outside access to the virtual Telnet server, you can use one of the global NAT addresses for the virtual Telnet server address.

Continue reading here: Configuring Tacacs Authorization

Was this article helpful?

0 0