There are few ways to authenticate your vpn clients, one is to create in the PIX/ASA local user database,
asa(config)#username password
have a look in this example
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008060f25c.shtml
another way is to use RADIUS. IAS for example that is free if you have Windows AD and have the RA VPN tunnel group authenticate through RADIUS your vpn clients and use your AD users database that are already configured in AD.
Have a look here for RADIUS authentication
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806de37e.shtml
Rgds
Jorge
Jorge Rodriguez