cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
470
Views
0
Helpful
7
Replies

3000Concentrator - How to tell which auth server being used

tylerlucas
Level 1
Level 1

We own several 3000-series concentrators. Today we had a major issue where users could not connect via Remote Access. Because we didn't have DHCP scopes specified in the concentrator, it (apparently) was pulling DHCP from the auth server being used.

Because we had 8 authentication servers in our server list, I couldn't tell which server was causing the issue.

Is there ANY way to find this information in the concentrator? I ended up having to connect to every single one...

1 Accepted Solution

Accepted Solutions

When you go to Configuration | User Management, you will see the defined groups in there, if you highlight the group you desire and then on the right click on the button "authentication server" you can add the authentication server that this particular group will use.

View solution in original post

7 Replies 7

Ivan Martinon
Level 7
Level 7

Other than setting Authentication logs and go through the logs, there is no way to tell what Authentication server your CVPN is using at that time. But it really depends on whether you have it assigned to the group, if it is globally defined, if they are the same type of servers.

Thank you for the reply! That clears things up a lot for me.

One other quick scenario:

Suppose there are three authentication servers, and suppose that each auth server belongs to a different domain. If three users log in and all attempt to use NT credentials, one from each domain, will it automatically use the "correct" respective auth servers?

They will use the authentication server that:

1) is assigned to the group (if any)

or

2) the first authentication server on the list.

The CVPN does not differentiate the authentication server based on domains, tipically the user would enter DOMAIN\USER to authenticate but the CVPN cannot be a member of any domain to strip this and send it to the correct domain, instead it will just forward DOMAIN\USER to the authentication server that first match the request.

Thanks again for the response :)

Last question:

How do I assign which auth server is associated with a specific group? I see where to assign what 'type' of auth (NTBackup, etc), but not an area to assign a specific server to a specific group (I'm looking in group config).

When you go to Configuration | User Management, you will see the defined groups in there, if you highlight the group you desire and then on the right click on the button "authentication server" you can add the authentication server that this particular group will use.

Ah, I had NO idea.

Thank you so much, you've been a huge help.

Take care!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: