White Paper Abstract:
This sample configuration initially blocks traffic from a host device (at 10.31.1.47) on the internal network to all devices on the Internet until you perform browser authentication with the use of authentication proxy. The access list passed down from the server (permit tcp|ip|icmp any any) adds dynamic entries post-authorization to access list 116 that temporarily allow access from that device to the Internet.