<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA with RADIUS via AZURE VPN in VPN</title>
    <link>https://community.cisco.com/t5/vpn/asa-with-radius-via-azure-vpn/m-p/4276946#M276765</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm trying to configure ASA 5515-X as authenticator for VPN RA connections. ASA device + switches are on-prem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;DC and RADIUS are on Windows Server 2016 installled as VM in Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have working 'Route based' site-to-site VPN tunnel with Azure (VTI interface). I can reach this VM on Azure (ping, rdp, etc..).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is that i can't set up AAA Server on ASA. In Radius configuration window, there is no option to choose VTI interface.&lt;/P&gt;&lt;P&gt;I found similar topic here: &lt;A href="https://community.cisco.com/t5/vpn/radius-via-azure-vpn/m-p/3803634" target="_blank"&gt;https://community.cisco.com/t5/vpn/radius-via-azure-vpn/m-p/3803634&lt;/A&gt;&lt;/P&gt;&lt;P&gt;,but in my scenario i don't have public IP assigned to Radius server. I'm trying to set Radius with 'Outside' interface and local IP of Radius on Azure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have static route to network with WinServer VM.&lt;/P&gt;&lt;P&gt;I’ve added command: &lt;EM&gt;&lt;STRONG&gt;management-access outside ,&lt;/STRONG&gt; &lt;/EM&gt;but this won't help - in ASDM, ASA says that management interface can't be with lowest security level. In config i have line with &lt;EM&gt;&lt;STRONG&gt;management-access outside,&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;so ASA accept it.&lt;/P&gt;&lt;P&gt;Radius has configured 'ASA client' with my public (IP of 'Outside' interface).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know from other topic, that this connection is possible but i'm running out of ideas.&lt;/P&gt;&lt;P&gt;Can anybody help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Damian&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jan 2021 18:02:29 GMT</pubDate>
    <dc:creator>DamianKolodziej03650</dc:creator>
    <dc:date>2021-01-21T18:02:29Z</dc:date>
    <item>
      <title>ASA with RADIUS via AZURE VPN</title>
      <link>https://community.cisco.com/t5/vpn/asa-with-radius-via-azure-vpn/m-p/4276946#M276765</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm trying to configure ASA 5515-X as authenticator for VPN RA connections. ASA device + switches are on-prem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;DC and RADIUS are on Windows Server 2016 installled as VM in Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have working 'Route based' site-to-site VPN tunnel with Azure (VTI interface). I can reach this VM on Azure (ping, rdp, etc..).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is that i can't set up AAA Server on ASA. In Radius configuration window, there is no option to choose VTI interface.&lt;/P&gt;&lt;P&gt;I found similar topic here: &lt;A href="https://community.cisco.com/t5/vpn/radius-via-azure-vpn/m-p/3803634" target="_blank"&gt;https://community.cisco.com/t5/vpn/radius-via-azure-vpn/m-p/3803634&lt;/A&gt;&lt;/P&gt;&lt;P&gt;,but in my scenario i don't have public IP assigned to Radius server. I'm trying to set Radius with 'Outside' interface and local IP of Radius on Azure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have static route to network with WinServer VM.&lt;/P&gt;&lt;P&gt;I’ve added command: &lt;EM&gt;&lt;STRONG&gt;management-access outside ,&lt;/STRONG&gt; &lt;/EM&gt;but this won't help - in ASDM, ASA says that management interface can't be with lowest security level. In config i have line with &lt;EM&gt;&lt;STRONG&gt;management-access outside,&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;so ASA accept it.&lt;/P&gt;&lt;P&gt;Radius has configured 'ASA client' with my public (IP of 'Outside' interface).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know from other topic, that this connection is possible but i'm running out of ideas.&lt;/P&gt;&lt;P&gt;Can anybody help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Damian&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 18:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-with-radius-via-azure-vpn/m-p/4276946#M276765</guid>
      <dc:creator>DamianKolodziej03650</dc:creator>
      <dc:date>2021-01-21T18:02:29Z</dc:date>
    </item>
  </channel>
</rss>

