cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1370
Views
8
Helpful
4
Replies

WebVPN on ASA 5505. How to use both Radius and local authentication

jbillochon
Level 1
Level 1

Hello,

WebVPN with radius (MS IAS) authentication works perfectly, alone. It's the same for local authentication.

But i can't use both authentication method.

Here is my authentication configuration:

tunnel-group DefaultWEBVPNGroup general-attributes

address-pool POOL_SSL

authentication-server-group AUTH-RADIUS LOCAL

accounting-server-group AUTH-RADIUS

But that doesn't seem to work.

In fact, i would like that my "own" users can log on Active Directory (with Radius authentication) and that my partners log on with the local database.

Somebody can help me ?

Thanks.

Julien

4 Replies 4

ggilbert
Cisco Employee
Cisco Employee

Julien,

This cant be done. User authentication to your local database will happen only if your RADIUS server not available.

What you are trying to do, will not work.

Sorry to give you the bad news.

Cheers

Gilbert

Hello,

Gilbert, Thanks for the reply.

I was afraid about this type of answer...But not very surprise.

So, Maybe it's possible to use 2 tunnelgroup policy ? One using Radius authentication and the other Local authentication ?

If it's not possible, i dont' t understand why it's possible to create many WebVPN tunnel group (at least 2 !) without being able to use it ?

Any idea ?

Thanks.

Julien

Hello again,

I've found a solution.

I create a second tunnelgroup call "partners", use local database authentication et create an alias like.

https://vpn.mycompany.com/partners

That works perfectly !!

Thanks for your help.

Julien

Hello,

Can you post the relevant ssl config parts including the second vpn tunnel. This may help me resolve an issue. Thanks.

jjcornelson@yahoo.com

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: