Solved

Cisco Client - Logging into VPN

Posted on 2007-04-02
3
232 Views
Last Modified: 2013-11-16
I am now running a Cisco ASA 5510 and have the VPN Set up and working (thanks to lrmoore).  Within that VPN it is using the group name to authenticate and then after that it asks for another password for a username that I had to create within the ASA.  Is there a way around the second step?

I used to have a pix that only required me to enter the information into the Cisco Client and hit connect.  Then i was good to go.
0
Comment
Question by:rcooper83
  • 2
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 18836605
You can set the auth group to none

   tunnel-group GROUPNAME general-attributes
        authentication-server-group  none
0
 
LVL 1

Author Comment

by:rcooper83
ID: 18836635
How secure is that?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 18836706
It is as secure as with local authentication as long as there are prudent controls on how anyone logs onto the VPN client machine. If it is a laptop and gets stolen, the logon password to the desktop is trivial to override and if it is, then this unauthorized user has full access to your network just by launching the client.
Without the user authentication you have no traceability of who logged on when, just the IP address that the connection came from.
The user authentication is another layer in your defense.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Static route question 6 34
IT Contract Fee 17 128
Static Route 22 46
nexus filter logs 3 25
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now