cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1606
Views
10
Helpful
7
Replies

Disable the xauth in IOS router for EZVPN client

mkmzaman
Level 1
Level 1

I am trying to diable the xauth option and make the authentication by default not the interactive. I have tried using the username option, still its in the xauth interactive mode.Please can anyone help me out in this.

7 Replies 7

ajagadee
Cisco Employee
Cisco Employee

If possible, Can you post the current configuration from the router. If not, make sure that your configuration looks like the below:

crypto ipsec client ezvpn EZVPNCLIENT

connect auto

group TEST key TEST123

mode network-extension

peer 1.1.1.1

username cisco password cisco

xauth userid mode local

Let me know if it helps.

Regards,

Arul

thanks for your reply.

I am using the same configuration for my device. i have given the mode as local and defined the username and password.

regards,

muneer

If the ezvpn server doesn't allow password storage on client, you won't be able to set this to xauth userid mode local.

On a 3000 head end, this is set on the hardware client tab for the group. For IOS/PIX head end, I don't know how to set it.

As the previous poster suggested, check the below "password-storage enable" under the group policy.

http://www.cisco.com/en/US/docs/security/asa/asa70/command/reference/mr.html#wp1588027

Regards,

Arul

Thanks for your help.

I have enabled Password-storage command at Headend device, it started working.

Great! Thanks for the update!

Regards,

Arul

Hi, which IOS verion comes with this 'local' option, my router only has   http-intercept and  interactive. it's c2800nm-advipservicesk9-mz.124-15.T7.bin

Thanks, Leo

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: