Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Cisco ASA5510 solution remote Access on IAS using Windows 2003 with IPSEC

Posted on 2006-07-15
7
Medium Priority
?
892 Views
Last Modified: 2009-02-22
Hi All,

I need your  expert assistance to get fix my problem :

LAN network [ Microsoft IAS-RADIUS configured and IPSEC policy in AD
server]---PIX ASA5510 --Internet ---- Remote VPN  client ( Connection
manager Automatic for IPSEC)

Can anybody assists me how to configure Remote Access  using IPSEC in IAS or
does IAS supports IPSEC protocol , if it is not what is the MS product
integrated in Windows 2003 OS  which supports IPSEC- Remote access AD
authentication not local PIX authentication.
May I know the steps and procedures and if possible any website with this
configuration and already working and tested.

Hoping your reply at the earliest and Please respond.

Thanks.
0
Comment
Question by:chaulq
  • 5
  • 2
7 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 1000 total points
ID: 17114221
1. Cisco VPN Client for clients
2. Configure VPN on ASA box
3. Configure the authentication through Radius, where Radius server being IAS.
4. IAS in turn will authenticate users using Active Directory.

If this is what you want, it is very simple; Just follow the Cisco link below for the full config including IAS.

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117091
I config step by step, but don't  run

event log view

User testvpn was denied access.
Fully-Qualified-User-Name = domain.com\testvpn
NAS-IP-Address = x.x.x.x
NAS-Identifier = <not present>
Called-Station-Identifier = x.x.x.x
Calling-Station-Identifier = x.x.x.x
Client-Friendly-Name = asa
Client-IP-Address = x.x.x.x
NAS-Port-Type = Virtual
NAS-Port = 1
Proxy-Policy-Name = vpn
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = <undetermined>
Authentication-Type = PAP
EAP-Type = <undetermined>
Reason-Code = 16
Reason = Authentication was not successful because an unknown user name or incorrect password was used

Help me, thanks

0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117150
Go to Active Directory, select the user 'testvpn' and open his properties. Check to see if he is allowed for 'dial-in' access. I am guessing it is not enabled, so enable it and then try.

Cheers,
Rajesh
0
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117156
?? Was that the problem?

Cheers,
Rajesh
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117159
May I know why grade C ?

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117188

I have check enable "dial-in" for user testvpn, but don't run

cheers,
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117194
Then why did you accept the answer ? The link I gave you is exclusively for Cisco VPN access to PIX with ActiveDirectory Radius Authentication using IAS, including IAS screenshot configurations. If you still have a problem, you should've followed up!

Cheers,
Rajesh
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question