ASA easy VPN server

Unanswered Question
Jun 3rd, 2009
User Badges:

Hi All,

I've setup ASA as easy VPN server. I don't want user authentication, which means when I run VPN client, I want to connect directly without to ask me username and password. I know we can do this in router, but I couldn't figure out in ASA.

any suggestion would be very appreciated.

thanks

Alex


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Maxim Zimovets Wed, 06/03/2009 - 21:26
User Badges:

Hello!


Try to add following command to tunnel-group ipsec-attributes:

isakmp ikev1-user-authentication none


But I should warn you - this practice is too insecure. Because in IKE's Aggressive mode group name and other attributes go in clear text.


With best regards.


srue Fri, 06/05/2009 - 11:30
User Badges:
  • Blue, 1500 points or more

also, when someone leaves the company who has either the pcf file or knows the groupname and password, everything is compromised. you should consider the security concerns inherent with not using xauth in this situation.

Actions

This Discussion