Cisco PIX 525 Especificações Página 123

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 466
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 122
3-11
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 3 Controlling Network Access and Use
Using Authentication and Authorization
Figure 3-2 Secure Authentication Page
Note The Cisco Systems text field shown in this example was customized using the auth-prompt command.
For the detailed syntax of this command refer to the Cisco PIX Firewall Command Reference. If you do
not enter a string using the auth-prompt command, this field will be blank.
After the user enters a valid username and password, an “Authentication Successful” page appears and
closes automatically. If the user fails to enter a valid username and password, an “Authentication Failed”
page appears.
A maximum of 16 concurrent HTTPS authentications are allowed. If all 16 HTTPS authentication
processes are running, a new connection requiring authentication will not succeed. An authentication
process starts when the PIX
Firewall receives the user name and password from the browser and ends
when it receives the authentication result from the AAA server. The length of time required to complete
each authentication process depends on the response time from the authentication source. If the LOCAL
database is used, it is very fast, while if a RADIUS or TACACS+ server is used, it will depend on the
server response time.
Note Pre-PIX 6.3 configurations that include AAA authentication include tcp/0.. will inherit the HTTPS
Authentication Proxy feature enabled with a code upgrade to PIX 6.3 or later.
When using the uauth timeout 0 command, HTTPS authentication will not work if a browser initiates
multiple TCP connections to get a web page after HTTPS authentication. In this scenario, the first
connection is allowed, but the subsequent connections will trigger authentication because the uauth
timeout is set to 0. As a result, users will be presented authentication pages continuously even though
the correct username and password are entered each time. You can avoid this problem by setting the
uauth timeout to 1 second. However, this opens a 1-second window that could conceivably allow a
non-authenticated user to obtain access from the same source IP address.
If a web browser launches an HTTPS web page request while secure authentication is in process for a
previous HTTP request, the HTTPS request triggers a second secure authentication process, even if
secure authentication is not specifically enabled for HTTPS. Once the authentication process for either
web page is completed successful, the remaining request can be completed by reloading the page.
Vista de página 122
1 2 ... 118 119 120 121 122 123 124 125 126 127 128 ... 465 466

Comentários a estes Manuais

Sem comentários