cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
704
Views
0
Helpful
5
Replies

PIX IPsec Xauth to W2K IAS Radius Server

darren.foo
Level 1
Level 1

Has anyone had any luck getting this working? I followed the guidelines at http://www.cisco.com/warp/public/110/pixcryaaa52.html

but when I am prompted for the radius user/pass it fails. I checked the event logs and there's 2 entries... one that says successfully granted access, and then another at the same time saying that the username or password is wrong. I tried just using Radius authentication without IPSec, and it works. Anyone know what may be the problem?

5 Replies 5

s-doyle
Level 3
Level 3

It’s possible the PIX already cached the unsuccessful attempt. Try clearing the uauth table in the PIX and trying again.

We have cleared the uauth table. We are trying to use the vpn 3000 2.5 client. Has anyone used this client with extended authorization to a 2000/radius server?

The only issue I ran into was that you need to set IAS to allow unencrypted passwords.

gattanasio
Level 1
Level 1

How do you give user and password. The only way it works is giving the domain/user and the password. Withouth the domain the authentication fails

You shouldn't have to use the DOMAIN\user syntax using xauth to IAS. Just create a rule like users with remote dial-in enabled are allowed.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: