Solved

Cisco Pix VPN Windows 2003 domain integration

Posted on 2004-03-24
6
22,892 Views
Last Modified: 2013-11-16
Hi All,

We have a windows 2003 domain and are planning to install a Cisco Pix 515 firewall. I've already configured a few Pix firewalls for Pix to Pix tunnels, and basic client VPN sessions using pptp and a username and password contained in the pix's configuration. What we would like to do with the Cisco Pix 515 at this particulat site is allow users to connect to the network via a VPN connection, using their Active Directory username and password. How can we achieve this? Would we need to purchase any additional software or hardware.

Cheers.
0
Comment
Question by:jt003649
6 Comments
 
LVL 23

Accepted Solution

by:
Tim Holman earned 200 total points
ID: 10669192
Cisco PIX offers no native support for either NT domain or Active Directory authentication.
Ways round this are to use CiscoSecure ACS as a TACACS server.  This provides the NTLM or AD link, and allows you to authenitcate users pretty much anyway you please -

CSACS-3.2-WIN-K9      Cisco Secure ACS 3.2 for Windows      $5,995      £4,117 (list price - you should be able to get 40% off this from a good supplier !)

You would need a platform on which to run this.

Alternatively, the VPN 3000 series does offer integrated NTLM / AD authenticaion.  A basic model such as the VPN 3005 is far cheaper than ACS, and will probably serve your needs better:

CVPN3005-E/FE-BUN      VPN3005:Chassis, 2FE, 200 user, client, SW, US PWR      $2,995      £2,057


0
 

Author Comment

by:jt003649
ID: 10670031
Thanks for the answer Tim. Looks like the VPN 3005 is the way forward.

Would it also be possible to use an Microsoft IAS server, integrated into AD, as a Radius server to authenticate using AD accounts?
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10695412
You can use Microsoft RAS as a VPN Server, and use the MS VPN client (PPTP / IPSEC), but this is software based and you really need VPN accelerator hardware in order to use a reasonable amount of VPN clients.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 

Expert Comment

by:dpc453
ID: 10784138
You can also use the Cisco VPN client and the Radius server on Windows 2000/2003 Internet Authentication Services (IAS) to authenticate users using AD.  I just set this up the other day with a 515 (6.3) and a 2003 domain using the very detailed instructions from Cisco:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml
0
 
LVL 2

Expert Comment

by:jon47
ID: 10868800
tim holman is right, but missing a feature of the PIX.  Setup the "Internet Authentication Service" on windows, aka RADIUS, and configure the pix as per dpc453's note.

We've got a pix 515 authenticating against a windows active directory domain quite happily.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10869947
Good point !
PIX will happily do RADIUS / TACACS+ natively.... :)
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Access List 2 18
Viber-Only Restriction 6 24
Port Forwarding on Cisco 881 14 36
Using VMWare Snapshot as Cisco UCM backup method 3 14
When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now