Solved

CIsco PIX and ACS - VPN client won't prompt to change password

Posted on 2008-10-23
2
1,754 Views
Last Modified: 2008-11-06
I currently have a PIX (IOS 6.3), and an ACS (v4.1) server. VPN clients connect to the PIX and are authenticated by the ACS through the external Windows database for Active Directory. The problem is when a user in AD has the option checked for "User must change password at next login", the VPN client fails immediately with Reason 413: User authentication failed.

One thing I found from here:
http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps6659/prod_white_paper0900aecd80478ad7.html
... but not sure if it applies because I am using an ACS. Would this be the correct usage line for the PIX

aaa authentication login USERAUTH passwd-expiry group radius

Is that needed even if using an ACS? Is there anything else I'm missing? Please let me know what other information you need to help me out.

Thanks!
0
Comment
Question by:djspin007
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 2

Accepted Solution

by:
vivek283 earned 125 total points
ID: 22891785
Hi,

PIX 6.x does not support password change on expiry for VPN clients. For password change ms-chap-v2 must be used. IPSEC uses PAP.

This feature was introduced on PIX on 7.0. On 7.x the tunnel group can be configured for radius-with-expiry or password-management. This will work with AD as external DB to ACS.
0
 

Author Comment

by:djspin007
ID: 22895417
Thanks for the info! I guess that's why so many people had VPN Concentrators prior to upgrading to PIX 7.x or replacing it with an ASA. Glad to hear though I didn't miss something in the configuration.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Suggested Courses
Course of the Month5 days, 21 hours left to enroll

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question