Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

VPN - RADIUS

I have a PIX setup as a VPN server for remote access users. I have it configured for the Cisco Client and for Microsoft using PPTP/MSCHAP. I have security set to authenticate via RADIUS. RADIUS works for the Microsoft client and authenticates fine. Using the cisco client, the client establishes the connection with the PIX, and then the pop up window asking for the credentials to pass to RADIUS is displayed. It fails authentication every time. Any ideas?

sysopt connection permit-ipsec

no sysopt route dnat

crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac

crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20

crypto dynamic-map outside_dyn_map 20 set transform-set ESP-DES-MD5

crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map

crypto map outside_map client authentication RADIUS

crypto map outside_map interface inside

isakmp enable outside

isakmp policy 20 authentication pre-share

isakmp policy 20 encryption des

isakmp policy 20 hash md5

isakmp policy 20 group 2

isakmp policy 20 lifetime 86400

vpngroup group1 address-pool sapool

vpngroup group1 dns-server 192.168.1.70

vpngroup group1 wins-server 192.168.1.5

vpngroup group1 idle-time 1800

vpngroup group1 password ********

aaa-server RADIUS protocol radius

aaa-server RADIUS (inside) host 192.168.1.7 123 timeout 10

2 REPLIES
New Member

Re: VPN - RADIUS

I have the same problem. I authenticate fine to the PIX, yet my authentication to IAS fails. configs are very similar.

New Member

Re: VPN - RADIUS

You have to enable "dial in" in your domain sever for the users you want to give access.

Active Directory -> USER -> Dial-in -> Allow Access

Hope it helps.

JM

107
Views
0
Helpful
2
Replies
CreatePlease login to create content