Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Cisco ASA5510 solution remote Access on IAS using Windows 2003 with IPSEC

Posted on 2006-07-15
7
Medium Priority
?
887 Views
Last Modified: 2009-02-22
Hi All,

I need your  expert assistance to get fix my problem :

LAN network [ Microsoft IAS-RADIUS configured and IPSEC policy in AD
server]---PIX ASA5510 --Internet ---- Remote VPN  client ( Connection
manager Automatic for IPSEC)

Can anybody assists me how to configure Remote Access  using IPSEC in IAS or
does IAS supports IPSEC protocol , if it is not what is the MS product
integrated in Windows 2003 OS  which supports IPSEC- Remote access AD
authentication not local PIX authentication.
May I know the steps and procedures and if possible any website with this
configuration and already working and tested.

Hoping your reply at the earliest and Please respond.

Thanks.
0
Comment
Question by:chaulq
  • 5
  • 2
7 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 1000 total points
ID: 17114221
1. Cisco VPN Client for clients
2. Configure VPN on ASA box
3. Configure the authentication through Radius, where Radius server being IAS.
4. IAS in turn will authenticate users using Active Directory.

If this is what you want, it is very simple; Just follow the Cisco link below for the full config including IAS.

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117091
I config step by step, but don't  run

event log view

User testvpn was denied access.
Fully-Qualified-User-Name = domain.com\testvpn
NAS-IP-Address = x.x.x.x
NAS-Identifier = <not present>
Called-Station-Identifier = x.x.x.x
Calling-Station-Identifier = x.x.x.x
Client-Friendly-Name = asa
Client-IP-Address = x.x.x.x
NAS-Port-Type = Virtual
NAS-Port = 1
Proxy-Policy-Name = vpn
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = <undetermined>
Authentication-Type = PAP
EAP-Type = <undetermined>
Reason-Code = 16
Reason = Authentication was not successful because an unknown user name or incorrect password was used

Help me, thanks

0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117150
Go to Active Directory, select the user 'testvpn' and open his properties. Check to see if he is allowed for 'dial-in' access. I am guessing it is not enabled, so enable it and then try.

Cheers,
Rajesh
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117156
?? Was that the problem?

Cheers,
Rajesh
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117159
May I know why grade C ?

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117188

I have check enable "dial-in" for user testvpn, but don't run

cheers,
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117194
Then why did you accept the answer ? The link I gave you is exclusively for Cisco VPN access to PIX with ActiveDirectory Radius Authentication using IAS, including IAS screenshot configurations. If you still have a problem, you should've followed up!

Cheers,
Rajesh
0

Featured Post

WatchGuard Case Study: NCR

With business operations for thousands of customers largely depending on the internal systems they support, NCR can’t afford to waste time or money on security products that are anything less than exceptional. That’s why they chose WatchGuard.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
Tech spooks aren't just for those who are tech savvy, it also happens to those of us running a business. Check out the top tech spooks for business owners.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question