Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

VPN Client 3.5 config with IOS Router-- little confusion.


I have a little problem in understanding few lines of the configuration when I have configured the Cisco VPN Client ver3.5 on a Win2k PC with a Cisco IOS Router. The confusion is with the following two lines,


crypto map cskclientmap client authentication list vpnusers

crypto map cskclientmap isakmp authorization list vpngroup


The function of these two lines is clear to me when I have configured the VPN Client on Router with aaa-new model. When I remove the aaa-new model authentication than still VPN Client is able to connect but when I remove these two lines or even one of these two lines than VPN Client is not able to connect.

My question is why we need these two lines when we are not using any aaa-model for authentication? What is the function of these two lines? I have tried to understand this but found no clue.

Can somebody give some comments on this?




Re: VPN Client 3.5 config with IOS Router-- little confusion.

Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center ( or speak with a TAC engineer. You can open a TAC case online at

If anyone else in the forum has some advice, please reply to this thread.

Thank you for posting.

CreatePlease login to create content