cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1310
Views
0
Helpful
5
Replies

Cisco VPN client and kerberos

commarmi001
Level 1
Level 1

Someone know if the rfc4556 is implemented in cisco vpn client (http://www.faqs.org/rfcs/rfc4556.html)

5 Replies 5

auraza
Cisco Employee
Cisco Employee

The ASA supports kerberos authentication, which the VPN client authenticates against. VPN client does support Certificate authentication.

PS. If you found this response helpful, please rate it.

if my knowledge of Kerberos are correct,is the VPN client that has to do authenticacion against the KDC. Acording the documentation is posible with login/password but not indicate if is posible with Certificates. Kerberos certificate authentication uses "special" method that is explained in rfc4556.

The VPN client will get an Auth Request from the ASA, which is what will talk do Kerberos authentication on behalf of the client. The VPN client itself doesn't have the ability to do that as it does not communicate directly with the Kerberos server.

Sorry, but i don't understand. How do ASA to use private key (in the client) to negotiate with KDC ?

Please, can you explain me who adquire the TGT and how ?

You can't have the client do that. Only the ASA.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: