<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD 2008 and VPN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ad-2008-and-vpn/m-p/1937153#M221924</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update 1: The login dn notation in the linked article is wrong. Format should be domain\username or username@domain. Once I corrected this issue, the test began working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have now created the IPSec Connecktion Profile, Group Policy, and Dynamic Access Policy. I have setup my PCF file on my client to connect to the new group I created, however I seem to be getting the following errors:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Cisco Systems VPN Client Version 5.0.07.0440&lt;/P&gt;&lt;P&gt;Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.&lt;/P&gt;&lt;P&gt;Client Type(s): Windows, WinNT&lt;/P&gt;&lt;P&gt;Running on: 6.1.7601 Service Pack 1&lt;/P&gt;&lt;P&gt;Config file directory: &lt;FILE directory="" withheld=""&gt;&lt;/FILE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.855&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE3000057&lt;/P&gt;&lt;P&gt;The received HASH payload cannot be verified&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.856&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE300007E&lt;/P&gt;&lt;P&gt;Hash verification failed... may be configured with invalid group password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.856&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE300009B&lt;/P&gt;&lt;P&gt;Failed to authenticate peer (Navigator:915)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.856&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE30000A7&lt;/P&gt;&lt;P&gt;Unexpected SW error occurred while processing Aggressive Mode negotiator:(Navigator:2263)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Mar 2012 14:35:30 GMT</pubDate>
    <dc:creator>DemPackets</dc:creator>
    <dc:date>2012-03-20T14:35:30Z</dc:date>
    <item>
      <title>AD 2008 and VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-2008-and-vpn/m-p/1937152#M221898</link>
      <description>&lt;P&gt;I am rather new to administrating the ASA. I am currently on 8.2.5 but I will be moving to 8.4.3 within the next week or so. In the meantime I would like to get my vpn system up and going. Currently I am able to vpn in to my system using a local server group, but I would like to simplify things by getting my ASA to accept AD credentials. I found a bunch of articles referencing how to do this. I first attempted to use this &lt;A href="http://www.block.net.au/blogs/james/pages/active-directory-vpn-authentication-with-a-cisco-asa-5510-series-appliance.aspx" target="_blank"&gt;article&lt;/A&gt; but the test option yeilds a failure stating "The authentication Server not responding: AAA Server has been removed." I then began to do more research finding things like having to add the Network Policy and Access Services to my domain controllers which I vaguely remember using at my last job prior to getting our Tacacs+ server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are my questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is LDAP able to be used for this process with AD 2008 Domain Controllers? I have a feeling the linked article I referenced used old AD 2003 servers because I am fairly sure I followed it to a T.&lt;/LI&gt;&lt;LI&gt;Is LDAP the preferred method to connect the ASA to the directory server? Is NPAS a better option? I would like to use a Tacacs+ server but I don't have that option right now and probably won't for another year. &lt;/LI&gt;&lt;LI&gt;Does anyone have a good link to some documentation that shows this method (preferred/best practice method)? &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance. I did some searching on the forums and there were some mildly related items to what I am asking but I couldn't find anything very recent. If someone's search-fu is better then mine, linking me to a relevant already asked question would be helpful as well.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-2008-and-vpn/m-p/1937152#M221898</guid>
      <dc:creator>DemPackets</dc:creator>
      <dc:date>2019-03-11T01:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: AD 2008 and VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-2008-and-vpn/m-p/1937153#M221924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update 1: The login dn notation in the linked article is wrong. Format should be domain\username or username@domain. Once I corrected this issue, the test began working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have now created the IPSec Connecktion Profile, Group Policy, and Dynamic Access Policy. I have setup my PCF file on my client to connect to the new group I created, however I seem to be getting the following errors:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Cisco Systems VPN Client Version 5.0.07.0440&lt;/P&gt;&lt;P&gt;Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.&lt;/P&gt;&lt;P&gt;Client Type(s): Windows, WinNT&lt;/P&gt;&lt;P&gt;Running on: 6.1.7601 Service Pack 1&lt;/P&gt;&lt;P&gt;Config file directory: &lt;FILE directory="" withheld=""&gt;&lt;/FILE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.855&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE3000057&lt;/P&gt;&lt;P&gt;The received HASH payload cannot be verified&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.856&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE300007E&lt;/P&gt;&lt;P&gt;Hash verification failed... may be configured with invalid group password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.856&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE300009B&lt;/P&gt;&lt;P&gt;Failed to authenticate peer (Navigator:915)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:06:52.856&amp;nbsp; 03/20/12&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IKE/0xE30000A7&lt;/P&gt;&lt;P&gt;Unexpected SW error occurred while processing Aggressive Mode negotiator:(Navigator:2263)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 14:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-2008-and-vpn/m-p/1937153#M221924</guid>
      <dc:creator>DemPackets</dc:creator>
      <dc:date>2012-03-20T14:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: AD 2008 and VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-2008-and-vpn/m-p/1937154#M221970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fixed this issue. My Group Profile was spelled incorrectly. I renamed it in the ASA with the correct spelling and everything is now fine. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 18:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-2008-and-vpn/m-p/1937154#M221970</guid>
      <dc:creator>DemPackets</dc:creator>
      <dc:date>2012-03-20T18:45:59Z</dc:date>
    </item>
  </channel>
</rss>

