Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

ASA easy VPN server

Hi All,

I've setup ASA as easy VPN server. I don't want user authentication, which means when I run VPN client, I want to connect directly without to ask me username and password. I know we can do this in router, but I couldn't figure out in ASA.

any suggestion would be very appreciated.

thanks

Alex

2 REPLIES
New Member

Re: ASA easy VPN server

Hello!

Try to add following command to tunnel-group ipsec-attributes:

isakmp ikev1-user-authentication none

But I should warn you - this practice is too insecure. Because in IKE's Aggressive mode group name and other attributes go in clear text.

With best regards.

Gold

Re: ASA easy VPN server

also, when someone leaves the company who has either the pcf file or knows the groupname and password, everything is compromised. you should consider the security concerns inherent with not using xauth in this situation.

275
Views
0
Helpful
2
Replies
CreatePlease to create content