Cisco Cisco Web Security Appliance S360 User Guide

Page of 455
 
5-30
AsyncOS 8.7 for Cisco Web Security Appliances User Guide
 
Chapter 5      Acquire End-User Credentials
  Failed Authentication
Note
If this option is not available it means the profile you chose is not configured to support guest 
access. Return to step 
 and choose another, or see 
 to define a new one.
Step 6
Submit and commit your changes.
Configure How Guest User Details are Logged
Step 1
Choose Network > Authentication. 
Step 2
Click Edit Global Settings.
Step 3
Click a Log Guest User By radio button, described below, in the Failed Authentication Handling field.
Step 4
Submit and commit your changes.
Failed Authorization: Allowing Re-Authentication with Different Credentials
About Allowing Re-Authentication with Different Credentials
Use re-authentication to allow users the opportunity to authenticate again, using different credentials, if 
the credentials they previously used have failed authorization. A user may authenticate successfully but 
still be prevented from accessing a web resource if not authorized to do so. This is because authentication 
merely identifies users for the purpose of passing their verified credentials on to policies, but it is the 
policies that authorize those users (or not) to access resources. 
A user must have authenticated successfully to be allowed to re-authenticate. 
To use the re-authentication feature with user defined end-user notification pages, the CGI script that 
parses the redirect URL must parse and use the Reauth_URL parameter. 
Allowing Re-Authentication with Different Credentials
Step 1
Choose Network > Authentication.
Step 2
Click Edit Global Settings.
Radio button
Description 
IP Address
The IP address of the guest user’s client will be logged in the access logs.
User Name As Entered 
By End-User
The user name that originally failed authentication will be logged in the 
access logs.