MS-CHAPv2 attribute error in ASA querying AD via ACS 5.2

Unanswered Question
Jun 29th, 2011

We have just set up a Secure ACS 5.2 VM to provide authentication for Anyconnect VPN clients.  The clients connect to an ASA 5520, which queries the ACS, which in turn queries Active Directory directly.  All seemed to work OK, but I noticed it was using PAP.  Following some docs, MS-CHAPv2 was enabled via the "Password-management" command.  This broke the configuration and the error on the ACS was:

11309 Incorrect RADIUS MS-CHAP v2 attribute

Some references suggest that the ASA and ACS should talk MSCHAPv2 without additional config, so I guess it must be the ASA config for the tunnel-group.  There are additional secondary authentication and authorisation pages on ASDM, that I suspect might be necessary to use mschap.

Please comment on this issue - all responses gratefully received!

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
micromedicreturns Wed, 06/29/2011 - 08:45

This was resolved by upgrading to the latest patch.

Actions

Login or Register to take actions

This Discussion

Posted June 29, 2011 at 3:18 AM
Stats:
Replies:1 Overall Rating:
Views:1095 Votes:0
Shares:0
 

Discussions Leaderboard

Rank Username Points
1
Tarik Admani
2,908
2
Premdeep Banga
1,083
3
Neno Spasov
1,072
4
darpotter
484
5
Amjad Abdullah
429
Rank Username Points
Neno Spasov
32
jan.nielsen
15
Martin Wisely
15
cehill
10
Patrick Meyer
10