We just setup a test environment with a PIX 515e and a windows 2000 server. IS ACS really needed or can I get away with tight security by just setting up my firewall/DMZ and controlled ports??
I've never used CSACS in production, but here is what I know/think.
The main features it gives you are access control per user.
So if you wish to define a company policy which gives several users only http access, and opens other ports for other users, it might be a good option.
You should note the CSACS does not do URL filtering nor content filtering.
So, if you do not need this kind of control and all internal users will have the same policy for outbound connections, then no need for it.
CSACS can also be used to authenticate inbound connections and to control access of incoming connections.
If you do need the options to control outbound access, you can either use CSACS or other products, including some proxy servers - some of them can give you more options like content filtering.
CSACS is not plug and play - you need to know what you want to do, then you need to configure both the pix and the CSACS server. It is not so dificult once you have the basic knowledge and there is GUI interface, but it is not something like just run SETUP.EXE and press enter.
In general (but depending on your needs), I think that purchasing a proxy server, content filters and/or dedicated VPN server can give you more options for your money.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.