WebVPN problems

Sep 27, 2005 5 Replies

Hi,


At my work we have an intranet site in the DMZ. It has an eDirectory server on it (wich is a slave and gets it's data from the master) to let users login on the site. This login is used for both intranetsite and to login on a computer in the company. (Same password username combination.) We have a cisco firewall that supports WebVPN. Now our 'problem' is that a user has to login into WebVPN and then he/she has to login again with the same username and password on the intranet site.



Has anyone an idee how to solve this?



Greetings,


WyriHaximus



Hey,

I forgot something to put in the message.

We like to have it that users login 1 time total for both WebVPN and intranet.

Grtz,

WyriHaximus

+0100"

I think you will need to use something like Novell's NMAS product to do RADIUS authentication via Edirectory. I'm looking at setting it up but no-one in Novell in UK seems to know what this product does or if it's included in Netware/Edirectory.... ;)

peter.

Hey,

I forgot something to put in the message.

We like to have it that users login 1 time total for both WebVPN and intranet.

Grtz,

WyriHaximus

We are using RADIUS for connecting the eDirectory server and the firewall. So that aint the problem. Our problem is that users have to auth with the firewall and then again on the intranet site. We want to merge that in 1 login. My first idee was that the firewall would ouput a form with the username and password and let it submit it in POST method so users get logged in automaticly :).

In article , WyriHaximus wrote: :We are using RADIUS for connecting the eDirectory server and the :firewall. So that aint the problem. Our problem is that users have to :auth with the firewall and then again on the intranet site. We want to :merge that in 1 login. My first idee was that the firewall would ouput :a form with the username and password and let it submit it in POST :method so users get logged in automaticly :).

PIX 6.x definitely can't handle that kind of automatic form submission.

But you aren't using PIX 6.x, as 6.x does not handle WebVPN. So you must be using PIX 7.0, or an ASA 5400 series with 7.0 software, or you must be using a 6500-based FWSM (firewall services module.) Then again, you might have been speaking loosely when you said "Cisco firewall", and including the Firewall Feature Set on one of the IOS routers...

We are indeed using a PIX 7.0 powerd firewall (ASA 5400).

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required