Cisco Cisco Web Security Appliance S170 ユーザーガイド

ページ / 455
 
5-28
AsyncOS 8.7 for Cisco Web Security Appliances User Guide
 
Chapter 5      Acquire End-User Credentials
  Failed Authentication
About Failed Authentication
Users may be blocked from the web due to authentication failure for the following reason:
Client limitations. Some client applications may not properly support authentication. You can 
bypass authentication for these clients by configuring Identities that do not require authorization and 
basing their criteria on the clients (and, optionally, on the URLs they need to access). 
Authentication service is unavailable. An authentication service might be unavailable due to 
network or server issues. You can choose to allow unauthenticated traffic in this circumstance. 
Invalid credentials. Some users may be unable to supply valid credentials for proper authentication 
(for example, visitors or users awaiting credentials). You can choose to grant these users limited 
access to the web. 
Related Topics
Bypassing Authentication
Related Topics
Bypassing the Web Proxy
Permitting Unauthenticated Traffic While Authentication Service is Unavailable
Note
This configuration applies only when an authentication service is unavailable. It will not bypass 
authentication permanently. For alternative options, see 
Step
More Information
1.
Create a custom URL category that contains 
the affected websites by configuring the 
Advanced properties.
2.
Create an Identification Profile with 
these characteristics:
Placed above all identities that 
require authentication.
Includes the custom URL category.
Includes affected client applications.
Does not require authentication
Classifying Users and Client Software, page 6-3
3.
Create a policy for the Identification Profile.