MS-CHAPv2 attribute error in ASA querying AD via ACS 5.2

Unanswered Question
Jun 29th, 2011

We have just set up a Secure ACS 5.2 VM to provide authentication for Anyconnect VPN clients.  The clients connect to an ASA 5520, which queries the ACS, which in turn queries Active Directory directly.  All seemed to work OK, but I noticed it was using PAP.  Following some docs, MS-CHAPv2 was enabled via the "Password-management" command.  This broke the configuration and the error on the ACS was:

11309 Incorrect RADIUS MS-CHAP v2 attribute

Some references suggest that the ASA and ACS should talk MSCHAPv2 without additional config, so I guess it must be the ASA config for the tunnel-group.  There are additional secondary authentication and authorisation pages on ASDM, that I suspect might be necessary to use mschap.

Please comment on this issue - all responses gratefully received!

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
micromedicreturns Wed, 06/29/2011 - 08:45

This was resolved by upgrading to the latest patch.

Actions

Login or Register to take actions

This Discussion

Posted June 29, 2011 at 3:18 AM
Stats:
Replies:1 Overall Rating:
Views:1102 Votes:0
Shares:0
 

Discussions Leaderboard

Rank Username Points
1
Tarik Admani
2,908
2
Neno Spasov
1,115
3
Premdeep Banga
1,083
4
darpotter
484
5
Amjad Abdullah
429
Rank Username Points
Neno Spasov
45
jan.nielsen
20
petenixon
5
ajay pandey
5
Michael Johnson
5