06-03-2009 04:42 PM - edited 03-11-2019 08:39 AM
Hi All,
I've setup ASA as easy VPN server. I don't want user authentication, which means when I run VPN client, I want to connect directly without to ask me username and password. I know we can do this in router, but I couldn't figure out in ASA.
any suggestion would be very appreciated.
thanks
Alex
06-03-2009 09:26 PM
Hello!
Try to add following command to tunnel-group ipsec-attributes:
isakmp ikev1-user-authentication none
But I should warn you - this practice is too insecure. Because in IKE's Aggressive mode group name and other attributes go in clear text.
With best regards.
06-05-2009 11:30 AM
also, when someone leaves the company who has either the pcf file or knows the groupname and password, everything is compromised. you should consider the security concerns inherent with not using xauth in this situation.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: