RE: [fw-wiz] PIX Authentication Question

From: Melson, Paul (PMelson_at_sequoianet.com)
Date: 12/12/03

  • Next message: edp: "R: [fw-wiz] MTU issue routing traffic via Cisco GRE tunnel to Nokia/Check Point firewall"
    To: "Lee T. Christie" <Lee.Christie@mosaicinfo.org>, <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 12 Dec 2003 09:08:04 -0500
    
    

    In order to do this, you must use AAA authentication for enable mode:

    aaa authentication enable console admin-group
    timeout uauth 00:15:00 inactivity

    This would mean that users that can authenticate via the admin-group (see aaa-server) can access enabled mode on the PIX, and that after 15m of idle time, they must re-authenticate. However, the uauth timeout can only be set once, so if users authenticate to the PIX for other things (outbound access, for instance), this idle time affects them as well.

    PaulM

    -----Original Message-----
    I am looking for a way to have authentication timed-out on a direct console
    connection. e.g. If I authenticate with enable is there anyway to have it
    automatically log me off after a set time period? I am running a Cisco PIX
    520 ver 6.2(2). Any help would be appreciated.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: edp: "R: [fw-wiz] MTU issue routing traffic via Cisco GRE tunnel to Nokia/Check Point firewall"

    Relevant Pages

    • Re: SSO
      ... Unfortunately, integrated Windows authentication is not designed to work that way, so there isn't a really clean way to accomplish that. ... I am able to navigate to all 3 apps, back and forth without any issue. ... users session times out after 15 minutes of inactivity the authentication ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • How Long Until Cookie Timeout
      ... I am using standard forms authentication. ... default time of inactivity before a new browser request would force a page ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: OWA Timeout
      ... period of inactivity? ... I read the posting referring to Forms based ... authentication and expiring cookies but would prefer not to use forms based ...
      (microsoft.public.exchange.admin)