Users not prompted for username or PASSCODE through Cisco PIX firewall
2 years ago
Originally Published: 2002-11-12
Article Number
000056023
Applies To
Cisco PIX
RSA ACE/Server
Issue
Users not prompted for username or PASSCODE through Cisco PIX firewall
Users prompted once and successfully authenticate, but not prompted for subsequent attempts
Cause
The IOS line "timeout uauth 0:05:00 absolute" is responsible to the time a users session is valid. This line essentially means the authentication is good for 5 minutes, and the user will not be challenged for that time.
Resolution
To correct this issue, change the value to be 0:00:30 (30 seconds) or less - the user will be challenged again when the timeout expires.