Solved

PIX vs ASA CLI command differences

Posted on 2009-05-04
2
1,344 Views
Last Modified: 2012-08-14
For years, we have used the Cisco PIX FW, with extremely good results. Never had a problem with them.  Now that Cisco is discontinuing this product, we just purchased our first ASA. (5540).

There are many commands that have been drastically changed from the PIX IOS to the ASA IOS.  

One of them is the "sysopt connection permit-pptp" command which is no longer available on the ASA.  Instead the command SEEMS to be "sysopt connection permit-vpn".

If I enter the "sysopt connection permit-vpn" command in the ASA does it allow for Microsoft VPN clients, (including Vista ones), to come in via VPN for authentication?  

I will include the code I would have USUALLY put in to the PIX for supporting MS VPN clients.  If someone could translate that into code for the ASA I would greatly appreciate it.
(PIX code for supporting MS VPN clients)
 

ip local pool ippool 192.168.100.1-192.168.100.254
 

aaa-server RADIUS protocol radius

aaa-server RADIUS max-failed-attempts 3

aaa-server RADIUS deadtime 10

aaa-server RADIUS (inside) host <local radius server ip> <pwd> timeout 10
 
 

sysopt connection permit-pptp
 

vpdn group PPTP-GROUP accept dialin pptp

vpdn group PPTP-GROUP ppp authentication pap

vpdn group PPTP-GROUP ppp authentication chap

vpdn group PPTP-GROUP ppp authentication mschap

vpdn group PPTP-GROUP client configuration address local ippool

vpdn group PPTP-GROUP client configuration dns <local DNS server IP>

vpdn group PPTP-GROUP client authentication aaa RADIUS

vpdn group PPTP-GROUP pptp echo 60

vpdn enable outside

Open in new window

0
Comment
Question by:jgrammer42
2 Comments
 
LVL 8

Accepted Solution

by:
akalbfell earned 500 total points
Comment Utility
Cisco actually makes a PIX to ASA config tool, i have used it once with surprisingly good results. I only had to make a few minor changes on the ASA afterwards...

http://www.cisco.com/cgi-bin/Software/Tablebuild/doftp.pl?ftpfile=/cisco/ciscosecure/pix/PIXtoASAsetup_1_0.exe

you need a CCO account which i am assuming you have :-)
0
 

Author Comment

by:jgrammer42
Comment Utility
Thanks, akalbfell, I will give that a shot.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Join & Write a Comment

Suggested Solutions

Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now