Solved

Cisco ASA5510 solution remote Access on IAS using Windows 2003 with IPSEC

Posted on 2006-07-15
7
874 Views
Last Modified: 2009-02-22
Hi All,

I need your  expert assistance to get fix my problem :

LAN network [ Microsoft IAS-RADIUS configured and IPSEC policy in AD
server]---PIX ASA5510 --Internet ---- Remote VPN  client ( Connection
manager Automatic for IPSEC)

Can anybody assists me how to configure Remote Access  using IPSEC in IAS or
does IAS supports IPSEC protocol , if it is not what is the MS product
integrated in Windows 2003 OS  which supports IPSEC- Remote access AD
authentication not local PIX authentication.
May I know the steps and procedures and if possible any website with this
configuration and already working and tested.

Hoping your reply at the earliest and Please respond.

Thanks.
0
Comment
Question by:chaulq
  • 5
  • 2
7 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 17114221
1. Cisco VPN Client for clients
2. Configure VPN on ASA box
3. Configure the authentication through Radius, where Radius server being IAS.
4. IAS in turn will authenticate users using Active Directory.

If this is what you want, it is very simple; Just follow the Cisco link below for the full config including IAS.

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117091
I config step by step, but don't  run

event log view

User testvpn was denied access.
Fully-Qualified-User-Name = domain.com\testvpn
NAS-IP-Address = x.x.x.x
NAS-Identifier = <not present>
Called-Station-Identifier = x.x.x.x
Calling-Station-Identifier = x.x.x.x
Client-Friendly-Name = asa
Client-IP-Address = x.x.x.x
NAS-Port-Type = Virtual
NAS-Port = 1
Proxy-Policy-Name = vpn
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = <undetermined>
Authentication-Type = PAP
EAP-Type = <undetermined>
Reason-Code = 16
Reason = Authentication was not successful because an unknown user name or incorrect password was used

Help me, thanks

0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117150
Go to Active Directory, select the user 'testvpn' and open his properties. Check to see if he is allowed for 'dial-in' access. I am guessing it is not enabled, so enable it and then try.

Cheers,
Rajesh
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117156
?? Was that the problem?

Cheers,
Rajesh
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117159
May I know why grade C ?

Cheers,
Rajesh
0
 

Author Comment

by:chaulq
ID: 17117188

I have check enable "dial-in" for user testvpn, but don't run

cheers,
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17117194
Then why did you accept the answer ? The link I gave you is exclusively for Cisco VPN access to PIX with ActiveDirectory Radius Authentication using IAS, including IAS screenshot configurations. If you still have a problem, you should've followed up!

Cheers,
Rajesh
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SD - WAN 2 41
svg file 10 79
Recover password from HP 4300 SAN 2 40
logging buffered 8 37
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

948 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now