Solved

Cisco ASA5510 solution remote Access on IAS using Windows 2003 with IPSEC

Posted on 2006-07-15
7
878 Views
Last Modified: 2009-02-22
Hi All,

I need your  expert assistance to get fix my problem :

LAN network [ Microsoft IAS-RADIUS configured and IPSEC policy in AD
server]---PIX ASA5510 --Internet ---- Remote VPN  client ( Connection
manager Automatic for IPSEC)

Can anybody assists me how to configure Remote Access  using IPSEC in IAS or
does IAS supports IPSEC protocol , if it is not what is the MS product
integrated in Windows 2003 OS  which supports IPSEC- Remote access AD
authentication not local PIX authentication.
May I know the steps and procedures and if possible any website with this
configuration and already working and tested.

Hoping your reply at the earliest and Please respond.

Thanks.
0
Comment
Question by:chaulq
  • 5
  • 2
7 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 17114221
1. Cisco VPN Client for clients
2. Configure VPN on ASA box
3. Configure the authentication through Radius, where Radius server being IAS.
4. IAS in turn will authenticate users using Active Directory.

If this is what you want, it is very simple; Just follow the Cisco link below for the full config including IAS.

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117091
I config step by step, but don't  run

event log view

User testvpn was denied access.
Fully-Qualified-User-Name = domain.com\testvpn
NAS-IP-Address = x.x.x.x
NAS-Identifier = <not present>
Called-Station-Identifier = x.x.x.x
Calling-Station-Identifier = x.x.x.x
Client-Friendly-Name = asa
Client-IP-Address = x.x.x.x
NAS-Port-Type = Virtual
NAS-Port = 1
Proxy-Policy-Name = vpn
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = <undetermined>
Authentication-Type = PAP
EAP-Type = <undetermined>
Reason-Code = 16
Reason = Authentication was not successful because an unknown user name or incorrect password was used

Help me, thanks

0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117150
Go to Active Directory, select the user 'testvpn' and open his properties. Check to see if he is allowed for 'dial-in' access. I am guessing it is not enabled, so enable it and then try.

Cheers,
Rajesh
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117156
?? Was that the problem?

Cheers,
Rajesh
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117159
May I know why grade C ?

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117188

I have check enable "dial-in" for user testvpn, but don't run

cheers,
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117194
Then why did you accept the answer ? The link I gave you is exclusively for Cisco VPN access to PIX with ActiveDirectory Radius Authentication using IAS, including IAS screenshot configurations. If you still have a problem, you should've followed up!

Cheers,
Rajesh
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question