ASA: Authenticating Outbound Connections - Authentication-Gateway?

I use an ASA 5520 as I-Net Edge for 3 different groups of Users. Currently i control access in the internet segment for each groups by static dhcp leases based on MAC-Adresses.
As this is not the most secure approach i am looking for a different way to control access within my internet segment.
I am thinking of authenticating the users with username and password prior to establishing connections over the ASA. I think this can be done somehow with the cut-trough proxy feature. Unfortunately i have no ACS Server available so the cut-through approach is not possible.
Has anyone done a configuration setup where users get authenticated based on username/password prior to allowing a connection through the ASA so far?
A similar functionality is often seen on public hotspots in airports where you have to authenticate over a webpage before internet usage.
Is there an open source software capable of this authentication method and can you configure it in conjunction with an ASA? Maybe using the WCCP Feature?
This might be a little Offtopic but hopefully someone has already experience with this kind of setup.
Thanks for reading.
Roble

yeah i cant believe it either! http://www.cisco.com/en/US/docs/security/asa/asa90/configuration/guide/access_wccp.html#wp1105267
The following WCCPv2 features are not supported for the ASA:
•Multiple routers in a service group.
•Multicast WCCP.
•The Layer 2 redirect method.
•WCCP source address spoofing.
•WAAS devices.

Similar Messages

  • Unable to connect siebel gateway name server during configuration enterprise server

    Hi,
    when I try to configure Siebel enterpise after entering the port of the gateway server name I get the following error: "Unable to connect gateway server name".
    I perform the following steps:
    1) Configuration Gateway Server Name
         Entered port TCP/IP = 2320
         Enable automaticaly start server gateway name server
         Show pop up "Configuration siebel succesful"
    2) Configuration Enterprise Server
         Entered name account authentication gateway server name = SADMIN
         Entered passoword account authentication gateway server name = SADMIN
         Entered name host gateway server name = VDIMTNSIEBEL01 (name my machine)
         Entered port TCP/IP gateway server name = 2320
         show pop up error : "Unable to connect gatawey server name"
    I can not find the log file in order to understand the issue.
    When I try to connect to the gateway from the browser with the url
    vdimtnsiebel01:2320 I get this screen mode:
    ???@??????? ?????????? ????????QÈ  ??? ??????????? ??? ??? ? ?h????
    and writes this log in the file "C:\siebel\8.1.1.0.0\ses\gtwysrvr\log\NameSrvr.log
    SisnapiLayerLog Error 1 0000001151c810a0:0 2013-06-25 10:11:27   4980: [SISNAPI]: Rx msg len=0 peer=VDIMTNSIEBEL01.ISCVDI.LOCAL avail=325 Hello expected session=13
    474554202F66617669636F6E2E69636F
    20485454502F312E310D0A486F73743A
    207664696D746E73696562656C30313A
    323332300D0A557365722D4167656E74
    3A204D6F7A696C6C612F352E30202857
    696E646F7773204E5420362E313B2057
    4F5736343B2072763A32312E30292047
    65636B6F2F3230313030313031204669

    Hi,
    Please clarify me the following.
    You specified the login name as 'SADMIN'. Is this the login id, that you used for your Operating System? "Entered name account authentication gateway server name" expects you to enter the NT login, not the DB login.
    You may also expected to specify your network name, if your login id is specific to a network. e.g Oracle\Rajkumar assuming that Oracle is your network and Rajkumar is the user name.
    You may not expected to have the DSN created, as Gateway may not be interested in knowing which DB you are connected to. And you neither enter the 'DB name' anywhere in the 'Gateway Server Configuration', if my understanding is right.
    Please confirm.
    Below pages are for reference (not directly relevant to your question):
    http://docs.oracle.com/cd/B40099_02/books/SiebInstWIN/SiebInstCOM_Prep18.html
    Bookshelf v8.0: Requirements for Siebel Gateway Name Server Installation and Configuration
    Thanks.
    Regards,
    Rajkumar Raju

  • C7 Social: Unable to connect to Gateway!!!

    Hello All,
    When i'm trying to use Social client in C7 getting the message "Unable to connect to Gateway".  It was working fine for some days. Any idea why this issue is occurring?? How to overcome from this??
    Thanks,
    Abhilash.

    Hi,
    Please clarify me the following.
    You specified the login name as 'SADMIN'. Is this the login id, that you used for your Operating System? "Entered name account authentication gateway server name" expects you to enter the NT login, not the DB login.
    You may also expected to specify your network name, if your login id is specific to a network. e.g Oracle\Rajkumar assuming that Oracle is your network and Rajkumar is the user name.
    You may not expected to have the DSN created, as Gateway may not be interested in knowing which DB you are connected to. And you neither enter the 'DB name' anywhere in the 'Gateway Server Configuration', if my understanding is right.
    Please confirm.
    Below pages are for reference (not directly relevant to your question):
    http://docs.oracle.com/cd/B40099_02/books/SiebInstWIN/SiebInstCOM_Prep18.html
    Bookshelf v8.0: Requirements for Siebel Gateway Name Server Installation and Configuration
    Thanks.
    Regards,
    Rajkumar Raju

  • Netlet fails: "Unable to connect to Gateway: default:443"

    i have installed the portal 3.0 sp4, MAP and HP for sp4.
    when using netlet, it tells me: "Unable to connect to Gateway: default:443"
    the platform.conf file contains the right gateway name.
    why does the netlet uses default:443 instead of the right gateway name and port?
    thnx, thomas

    after reinstalling the server and the gateway, i face the same problem again, but i found out, that the error only occurs when the anonymous desktop is enabled.
    logging in using ldap authentication, everything works; but logging in, using the anonymous desktop, and then loging in at the login-chanel using ldap-authentication, the error occurs, when using Netlet.
    looking at the install logs, i found out that the sp4 wasn't able to update the "iwtGateway-netletproxy-port" and the "iwtNaming-sessionURL" attributes;
    could one of this be respobsible for the failure ?
    has anyone an idea, how to solve the problem ?
    thnx, thomas

  • Logging inbound and outbound connections through my Linksys router

    Hi There,
    I have a  Linksys wireless router (WRT54G series) that I use to connect to the internet with my cable modem. I would like to be able to configure my home network to log inbound and outbound connections through my router. 
    My router, which I bought brand new a couple of years ago, provides some very basic logging through its administration interface.  I can view a current log of very recent (within the past couple of minutes) inbound and outbound connections/traffic.  However, I would like to be able to configure my network to log all inbound and outbound traffic for at least 1 or 2 days and have this log saved somewhere so I can retrieve and review it at a more convenient time.  I haven't been able to figure out how to do this with my current Linksys router and would like some help in configuring my system.
    Is it possible for me to configure (perhaps with a firmware upgrade or even by replacing my older Linksys router with a newer one) my router to continuously log a day or more's worth of inbound and outbound connections?  If this is possible, what changes do I need to implement?  Does Linksys offer a wireless router that has more sophisticated logging capabilities?  What is the longest log period that I can create with a Linksys router?
    If it's not possible to create such a log with my router, then what other components would I need to log this information?  I've thought about setting up a Linux server with two network cards installed to act as a gateway between my router and cable modem which will log traffic.  Would this be a good strategy to implement logging?
    Thanks in advance.
    Tom
    Message Edited by   on 07-28-2007 07:44 AM
    Message Edited by   on 07-28-2007 07:50 AM

    well...the router's in-built log will only provide basic information about the incoming/outgoing log . So, it will be a good idea to install a separate log viewer .....

  • SAP R/3 outbound connection to CE 7.1 (Bean IDOC_INBOUND_ASYNCHRONOUS)

    Hi ...,
    I want to use RFC in the R/3 backend system to call a JCO-Server on SAP CE 7.1 (outbound connection).
    The JCO-Server starts successfully and everything works fine so far. That means, I can send an IDoc (material "MATMAS") via RFC to the SAP CE 7.1 and if I look through the transaction we02 the Idoc sent successfully to the the system. But if I look through the log-file of the CE 7.1 (.../nwa/logs) I realize the following error-message:
    java.lang.RuntimeException: Bean IDOC_INBOUND_ASYNCHRONOUS not found on host XXXX, ProgId =XXXX: Object not found in lookup of IDOC_INBOUND_ASYNCHRONOUS.
    at com.sap.engine.services.rfcengine.RFCDefaultRequestHandler.handleRequest(RFCDefaultRequestHandler.java:121)
    at com.sap.engine.services.rfcengine.RFCJCOServer$J2EEApplicationRunnable.run(RFCJCOServer.java:269)
    at com.sap.engine.core.thread.impl3.ActionObject.run(ActionObject.java:37)
    at java.security.AccessController.doPrivileged(Native Method)
    at com.sap.engine.core.thread.impl3.SingleThread.execute(SingleThread.java:152)
    at com.sap.engine.core.thread.impl3.SingleThread.run(SingleThread.java:247)
    Caused by: com.sap.engine.services.jndi.persistent.exceptions.NameNotFoundException: Object not found in lookup of IDOC_INBOUND_ASYNCHRONOUS.
    at com.sap.engine.services.jndi.implserver.ServerContextImpl.lookup(ServerContextImpl.java:584)
    at com.sap.engine.services.jndi.implclient.ClientContext.lookup(ClientContext.java:343)
    at com.sap.engine.services.jndi.implclient.OffsetClientContext.lookup(OffsetClientContext.java:266)
    at com.sap.engine.services.jndi.implclient.OffsetClientContext.lookup(OffsetClientContext.java:286)
    at javax.naming.InitialContext.lookup(InitialContext.java:351)
    at javax.naming.InitialContext.lookup(InitialContext.java:351)
    at com.sap.engine.services.rfcengine.RFCDefaultRequestHandler.handleRequest(RFCDefaultRequestHandler.java:104)
    ... 5 more
    It would be very grateful, if somebody of you could help me!
    Thanks a lot.
    Stefan

    Hi Stefan,
    I am not working in CE 7.1, but have come across this issue several times with various clients.  Did you ever get a solution to this issue?
    Thanks,
    Mike

  • Strage problem with outbound connections

    Hi all,
    I've been unable to connect to my Gmail IMAP since I restored from a time machine backup. I know my IP hasn't been blacklisted, because I can still connect via my iPhone when I'm home and connected to the LAN, and my wife's mail app still works. I've completely removed all mail caches data from ~/Library for the mail app.
    After doing some network diagnostics, I've noticed I can't telnet to imap.gmail.com on port 993 from my Macbook Pro (the computer with mail failing). My firewall is completely disabled, again this works on my wife's laptop. Is there some other plist that could be interfering. Also, is it possible to list the firewall rules from the command line similar to linux's iptables? Something is blocking my outbound connection on the laptop itself, but I'm at a loss to find out what it is.
    thanks,
    Todd

    Hi,
    This could be the problem of confilting namespace or combinations.
    in receive action just check that right message interface is configured at Inbound side.
    just check any place void ?
    1)just check the name as case sensitive.
    2)Just check is there interface belongs to right software component.
    3)Just check mapping assigned to the right combination or not.
    its better to cross check all the component are assigned to right place or not.
    ****if helpful then rewards points
    Regards,
    Sumit Gupta

  • Can't modify Outbound Connection Pools properties in WebLogic 10.3.6

    I'm trying to configure BAM adapter in WebLogic Administration Console. Navigate to deployments -> OracleBamAdapter -> Configuration -> Outbound Connection Pools -> eis/bam/rmi -> tried to enter property value of Hostname but I couldn't. It is not in edit mode - no check box in front of Hostname column. I tried to enter the value in the hostname property and save but nothing was saved.
    I've unlocked domain configuration lock and I see the <lock & edit> button is disabled and <release configuration> button is enabled in the change center. So why can I modify the property value?
    WebLogic 10.3.6
    SOA 11.1.1.6
    BAM
    All are installed in the same server and SOA is installed with development mode. I didn't bounce the admin server after unlocking the domain configuration, is this required?

    Thanks, Arik. I just figured it out and was banging my head against the wall when you posted the message. :-) Thanks for the reply!

  • Outbound Connection Pool Entry Missing for DBAdapter in Clustered Weblogic Congfiguration

    Hi ,
    When I created an outbound connection pool entry in DBAdapter through weblogic console in a clustered environment ( 1-Admin server and 2-managed servers) and updated DB adapter, I indentified that connection entry is updated in only in plan.xml of one managed server and for other managed server it is not updated. Due to this we are unable to access Datasources for some requests from application.
    As a work around if we update plan.xml file of other managed server manually with required connection entry and update DB Adapter we are able to find the connection entry for both the managed servers.
    Apart from work around is there any other solution for this issue so that I can add a DB adapter connection entry through console which will update both plan.xml files.
    Thanks & Regards,
    Venkat

    I can suggest you to keep the Plan.xml file in shared drive that is accessible from all the server nodes,this will reduce the manual work.
    Regards
    Albin I
    http://www.albinsblog.com/

  • HT204388 can you connect a GATEWAY TOWER to a MAC 23in CINEMA MONITOR?

    can you connect a GATEWAY TOWER to a MAC 23in CINEMA DISPLAY?

    Hi, likely you can, but which 23" is it, one requires an expensive DVI-> ADC connector, not the cheaper ADC->DVI connector, the later one has DVI already.
    Then it depends what output your Gateway has for Video.
    ADC...
    http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/TS2085/58846_1.gif
    VGA & DVI...
    http://cdn.overclock.net/2/21/215b66d1_all-DVI-types.jpeg
    http://www.mytechsecrets.com/wp-content/uploads/2011/01/dual-monitor-video-card. jpg

  • Social Cannot connect to gateway error

    I know that alot of people are having this issue as well as I. but i just have a bit of info that might help sovle it. 
    I noticed that this error only started occuring with the new version of social (1.2) because i have 2 N8's and one of them has V1.1 and it works flawlessly but my other N8 has V1.2 and it always tells me that it cannot connect to gateway.
    Hope this helps, and if anyone finds the answer plz let me know thanks!

    If you have done the following and still can't access Ovi Social, this might be the one for you:
    1. Created an Ovi Account
    2. Restore and Delete
    3. Re-flash your unit with Nokia Center Support
    ATTENTION: This issue is a Nokia problem.
    "Nokia is putting their free services and paid services on one server."
    Currently, https://sm.ovi.messaging.nokia.com/cds is being accessed by Ovi Social which is a free service. Now this URL is identified as 67.220.123.45 and is tagged as one of Nokia's paid services, Nokia Push Mail. One may experience this problem if a) the Telco offers Nokia Push Mail and b) if the subscriber is a prepaid account. In the Philippines, Nokia Push Mail is being offered by Smart and I have a prepaid account so i can't access Ovi Social. I tried using a postpaid SIM and it work perfectly fine. Now I tried it with Globe using a prepaid SIM and it works perfectly fine but i think they don't offer Nokia Push Mail (yet) so that figures. I don't know why Nokia is so quiet about this issue, they should address this problem. This is still a pending issue in Smart-side because Nokia is still not answering.
    Solution: Try changing Telco

  • Dozens of outbound connections to Russia and other...

    I was monitoring my network traffic today and saw that Skype has literally over 100 outbound connections from my computer. They range from the United States to Russia and more. I reached out to support chat today about this and was not given an answer about why this is happening. All they told me was "I guarantee your privacy is in tact". Attached is a screenshot of one of the outgoing connections.
    All I want is an answer. Is this due to some kind of peer-to-peer networking? If so, why does my computer need to contact Russia? What data is being sent?
    Thanks

    I have the same issue except that Skype is trying to connect to a trojan sight called "akamaitechnologies.com", whick is a known trojan site. I use TCPVCON.exe to monitor my IP connections. Im about ready to get rid of Skype, if I cant find a way to stop this.
    thanks ron

  • How to access a domain server which is targeted by Group Policy set to block Inbound and Outbound connections

    Hi,
    I have a practice lab with two physical servers 2012 R2, one of them is Hyper-V host and one of VMs is a domain controller. I was doeing some exercises with firewall rule deployment through Group Policy, so I created an outbound rule to block port 80 which
    was targeted to Domain Computers. Now my other physical server has inbound and outbound connections set to block and domain controller cannot be contacted to update policy ( with rule removed ). At least that is my understanding. Maybe I messed up something
    with the profiles too, because port 80 would not have block all outband traffic, or?
    I am new to IT so my understanding is still poor.
    Best
    Robert

    Hi Robert,
    If we block inbound connections, all connections that do not have firewall rules that explicitly allow the connection will be blocked.
    If we block outbound connections, all connections that do not have firewall rules that explicitly allow the connection will be blocked.
    If we block outbound TCP port 80, it will mean all websites will be unreachable, for TCP port 80 is for HTTP.
    Regarding Windows firewall security settings, the following article can be referred to for more information.
    Windows Firewall with Advanced Security Properties Page
    http://technet.microsoft.com/en-us/library/cc753002.aspx
    Best regards,
    Frank Shen

  • SOA 11g FTP Adapter creating outbound connections every minute

    FTP Adapter SOA 11.1.1.4 build.
    ####<Feb 17, 2011 1:30:49 PM EST> <Info> <Common> <usadanassoad1> <soa_server1> <weblogic.work.j2ee.J2EEWorkManager$WorkWithListener@374c159d> <Jing> <> <f1996a6c9a644552:-510fae37:12e30729d3f:-8000-0000000000008b36> <1297967449047> <BEA-000628> <Created "1" resources for pool "eis/Ftp/DynmManageFtp", out of which "1" are available and "0" are unavailable.>
    ####<Feb 17, 2011 1:31:48 PM EST> <Info> <Common> <usadanassoad1> <soa_server1> <weblogic.work.j2ee.J2EEWorkManager$WorkWithListener@374c159d> <Jing> <> <f1996a6c9a644552:-510fae37:12e30729d3f:-8000-0000000000008b36> <1297967508533> <BEA-000628> <Created "1" resources for pool "eis/Ftp/DynmManageFtp", out of which "1" are available and "0" are unavailable.>
    ####<Feb 17, 2011 1:32:49 PM EST> <Info> <Common> <usadanassoad1> <soa_server1> <weblogic.work.j2ee.J2EEWorkManager$WorkWithListener@374c159d> <Jing> <> <f1996a6c9a644552:-510fae37:12e30729d3f:-8000-0000000000008b36> <1297967569034> <BEA-000628> <Created "1" resources for pool "eis/Ftp/DynmManageFtp", out of which "1" are available and "0" are unavailable.>
    And the total connections are now over --1200-- currently.
    Outbound Connection Pool      Server           State      Current Connections      Created Connections
    eis/Ftp/DynmManageFtp          soa_server1     Running          1               1244
    Any ideas to why connections are being created would be helpful.
    Edited by: 827647 on Feb 25, 2011 12:41 PM

    This was due to polling attempts to "put" within the apps code

  • While Configuring Siebel Server we are getting "Unable to Connect to Gateway server" error in siebel 8.2.2.14

    Hi
    While Configuring Siebel Server we are getting "Unable to Connect to Gateway server" error in siebel 8.2.2.14
    Our OS is windows 2008 R2 64 bit,Orcale client is 11g 32 bit and Oracle DB is in 11g.We are also able to connect to DB using ODBCSQL.
    Please help.
    Regards
    Shuvendu

    Hello Shuvendu,
    Thanks for using Oracle Communities.
    About your error, there could be many reasons, To start with, please have following knowledge article to know possible reasons.
    C028: "Unable to Connect to the Siebel Gateway Name Server" Logged By Configuration Wizard (Doc ID 1391312.1)
    I hope it helps.
    Best Regards,
    Chetan
    P.S. If any one of the provided responses has been correct or helpful it would be great if you could mark them as appropriate.

  • Hi All , Getting connection to Gateway error when synchronizing in MI

    Hi All , Getting connection to Gateway error when synchronizing in MI using MAU application .
    Please provide the solution ASAP.
    Also provide the notes which can be avilable in SERVICE.SAP
    Thanks&Regards.
    Bharat

    Hi,
    well, the error - you should get this error as well if you sync with a new and empty client? It seems your Sync service is down. Check the sync service itself. Is the URL accessible from the device itself?
    It is usually not related to the App (MAU in your case) it is related to the ladscape itself.
    Can you add the correct error message and the part of the trace that shows the message? Including the lines before with the ping if the server is available?
    Regards,
    Oliver

Maybe you are looking for

  • My Apple ID is locked for 90 days and can't even purchase anything

    I had my personal Apple ID and I made an second Apple ID for my business. I logged into my iphone6 with that second business apple ID - this apple ID has no credit card information at all. then I tried to log into my personal previous apple ID - this

  • How do you add outer glow effect to text in Elements 12?

    I've created a layer in Elements 12 that contains some text.  I'd like to add an outer glow effect.  This is what I am doing: 1.  Select layer with text 2.  Click FX button at bottom of screen 3.  Click Styles tab 4.  Select Outer Glow from drop down

  • Premiere pro 2.0 のDVDマーカー

    DVDマーカーを一括で移動する方法はあるのでしょうか? 映像部分を変更.修正する際にマーカーがずれて困っています. どなたかご教授お願いします. 以上 よろしくお願いします.

  • LDAP + create homedir after changeip failure

    Hi all I have a vertically mounted Xserve running 10.4 and have some troubles. When I tried using changeip to change the server name of my xserve things started to become funky. This is what I did: * saw errors about DNS name in log * added the serve

  • ESA setup - best practices

    I have 2 ESA (c370) running active/active setup. Currently each ESA configured to use only a single port for both inbound and outbound email. The other 3 ports are not in use. What are the best practices of setting up the ESA ? Sent from Cisco Techni