?
Solved

PIX 6.3 VPN different AAA authentication

Posted on 2009-04-14
9
Medium Priority
?
616 Views
Last Modified: 2012-05-06
I would like to know if I can use differnt Radius servers to authenticate different vpngroups...
I'm trying eliminating the "crypto map outside_map client authentication VPN-DESA-PIX"
and using a

vpngroup vpn1 authentication-server VPN-PROD-PIX
vpngroup vpn2 authentication-server VPN-DESA-PIX

but it didn't work...

any idea???
0
Comment
Question by:mahe2000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24144179
Sure.

aaa-server VPN-PROD-PIX protocol radius
aaa-server VPN-PROD-PIX max-failed-attempts 3
aaa-server VPN-PROD-PIX deadtime 10
aaa-server VPN-PROD-PIX (inside) host 10.1.1.100 timeout 10
aaa-server VPN-DESA-PIX protocol radius
aaa-server VPN-DESA-PIX max-failed-attempts 3
aaa-server VPN-DESA-PIX deadtime 10
aaa-server VPN-DESA-PIX (inside) host 10.2.2.100 timeout 10

vpngroup vpn1 authentication-server VPN-PROD-PIX
vpngroup vpn2 authentication-server VPN-DESA-PIX
0
 
LVL 3

Author Comment

by:mahe2000
ID: 24144230
I have already tried this but it didn't work this way... it keeps using the "crypto map ... authentication client..."
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24144280
Have you tried removing the "crypto map ... authentication client..." command?
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 
LVL 3

Author Comment

by:mahe2000
ID: 24144330
yes, but it only allows one authentication server and I need two differnt user databases...
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24147090
Just so we are clear.

You removed the crypto map auth command and added the two servers and binded them to the VPN group?

no crypto map outside_map client authentication VPN-DESA-PIX

aaa-server VPN-PROD-PIX protocol radius
aaa-server VPN-PROD-PIX max-failed-attempts 3
aaa-server VPN-PROD-PIX deadtime 10
aaa-server VPN-PROD-PIX (inside) host 10.1.1.100 timeout 10
aaa-server VPN-DESA-PIX protocol radius
aaa-server VPN-DESA-PIX max-failed-attempts 3
aaa-server VPN-DESA-PIX deadtime 10
aaa-server VPN-DESA-PIX (inside) host 10.2.2.100 timeout 10

vpngroup vpn1 authentication-server VPN-PROD-PIX
vpngroup vpn2 authentication-server VPN-DESA-PIX
0
 
LVL 3

Author Comment

by:mahe2000
ID: 24147138
if I remove the line
no crypto map outside_map client authentication VPN-DESA-PIX

no authentication is made. i don´t need to put a user and password in that case...
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24147177
Really?  Nice functionality.  Let me take a look at some things...
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 1500 total points
ID: 24147545
Okay, so the "vpngroup vpn1 authentication-server <group>" command is not for xauth authentication so it won't work.

This is a limitation of the 6.3 code on the PIX.  You can only have one auth group for your VPN.

"crypto map outside_map client authentication VPN-DESA-PIX".

Is it a PIX 501 or 506? or a 515/525/535?  If a 501, you might want to look into replacing it with an ASA 5505 so you can run the latest and greatest software which provides the auth group per VPN group functionality.  If you have a 515/525/535, you can upgrade to 7.x/8.x to enable this functionality.
0
 
LVL 3

Author Closing Comment

by:mahe2000
ID: 31570203
I get to the same conclusion... thank you very much for the effort!!!
0

Featured Post

[Webinar] How Hackers Steal Your Credentials

Do You Know How Hackers Steal Your Credentials? Join us and Skyport Systems to learn how hackers steal your credentials and why Active Directory must be secure to stop them.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question