Advertisement

05.04.2008 at 08:42PM PDT, ID: 23375649
[x]
Attachment Details

Cisco ASA 5510 VPN not authenticating with Win 2k3 IAS.

Asked by mosaicatm in Virtual Private Networking (VPN), Windows 2003 Server, IPSec Security Protocol

Tags: Microsoft, Server 2003 Standard, Using IAS as Radius, Cisco, ASA, 5510 8.0(3), Trying to use IAS as RADIUS authenticator for VPN

I am not sure what is going wrong but I have setup IAS and configured the AAA settings on the ASA.  When I run the "test aaa-server..." from the CLI or from ASDM it passes and log entries are created in the System Event Log on the server running IAS.  When I use the LOCAL database for authentication it works fine but when I change the "authentication-server-group" from LOCAL to MyRADIUSGroup then it won't authenticate and nothing gets logged on the IAS server.  It seems that the request is not being sent from the ASA when I try to use it to authenticate my VPN sessions.

Here is the config on the ASA:

aaa-server MyRADIUSGroup protocol radius
aaa-server MyRADIUSGroup (inside) host 192.168.X.X
 key **************

group-policy RAVPN internal
group-policy RAVPN attributes
 dns-server value 192.168.X.X
 vpn-tunnel-protocol IPSec
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value RAVPNSplitTunnel
 default-domain value mydomain.local

tunnel-group RAVPN type remote-access
tunnel-group RAVPN general-attributes
 address-pool RAVPNPool
 default-group-policy RAVPN
 password-management
tunnel-group RAVPN ipsec-attributes
 pre-shared-key *

Start Free Trial
[+][-]05.05.2008 at 05:27AM PDT, ID: 21499464

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.05.2008 at 10:09AM PDT, ID: 21501380

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Virtual Private Networking (VPN), Windows 2003 Server, IPSec Security Protocol
Tags: Microsoft, Server 2003 Standard, Using IAS as Radius, Cisco, ASA, 5510 8.0(3), Trying to use IAS as RADIUS authenticator for VPN
Sign Up Now!
Solution Provided By: mosaicatm
Participating Experts: 0
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628