<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote client AUTH to ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/remote-client-auth-to-acs/m-p/1586716#M258463</link>
    <description>&lt;P&gt;I have been trying to get remote ipsec client get authenticated via ACS, cannot figure out what is causing the issue. Below is the configuration and debugs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything specific that needs to be configured on the ACS?? BTW ACS version is 3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any input is appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config on router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login 3Gusers group tacacs+&lt;BR /&gt;aaa authorization network 3Gusers group tacacs+&lt;/P&gt;&lt;P&gt;crypto isakmp policy 100&lt;BR /&gt; encr 3des&lt;BR /&gt; authentication pre-share&lt;BR /&gt; group 2&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp client configuration group 3Gvpn&lt;BR /&gt; key trewq&lt;BR /&gt; dns 10.142.171.22 10.142.171.21&lt;BR /&gt; pool 3Gpool&lt;BR /&gt; netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp profile 3Gclient&lt;BR /&gt;&amp;nbsp;&amp;nbsp; match identity group 3Gvpn&lt;BR /&gt;&amp;nbsp;&amp;nbsp; client authentication list 3Gusers&lt;BR /&gt;&amp;nbsp;&amp;nbsp; isakmp authorization list 3Gusers&lt;BR /&gt;&amp;nbsp;&amp;nbsp; client configuration address respond&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec transform-set 3G esp-3des esp-md5-hmac &lt;BR /&gt;!&lt;BR /&gt;crypto dynamic-map 3Gmap 10&lt;BR /&gt; set security-association idle-time 86400&lt;BR /&gt; set transform-set 3G &lt;BR /&gt; set isakmp-profile 3Gclient&lt;BR /&gt; reverse-route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug----&lt;/P&gt;&lt;P&gt;Dec 15 16:21:19.566 EDST: ISAKMP (0): received packet from 10.200.0.106 dport 50&lt;BR /&gt;0 sport 3553 Global (N) NEW SA&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: Created a peer struct for 10.200.0.106, peer p&lt;BR /&gt;ort 3553&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: New peer created peer = 0x3AE6B3EC peer_handle&lt;BR /&gt; = 0x8000001F&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: Locking peer struct 0x3AE6B3EC, refcount 1 for&lt;BR /&gt; crypto_isakmp_process_block&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP[R]: sa-&amp;gt;swdb: GigabitEthernet1/2/1&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: local port 500, remote port 3553&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: Find a dup sa in the avl tree during calling i&lt;BR /&gt;sadb_insert sa = 3AFB77A8&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0): processing SA payload. message ID = 0&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0): processing ID payload. message ID = 0&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP (0): ID payload &lt;BR /&gt;next-payload : 13&lt;BR /&gt;type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 11 &lt;BR /&gt;group id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3Gvpn &lt;BR /&gt;protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 17 &lt;BR /&gt;port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 500 &lt;BR /&gt;length&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 13&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0):: peer matches 3Gclient profile&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0):Setting client config settings 3A7D8D0C&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0):(Re)Setting client xauth list&amp;nbsp; and state&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP/xauth: initializing AAA request&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID seems Unity/DPD but major 215 mi&lt;BR /&gt;smatch&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is XAUTH&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is DPD&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID seems Unity/DPD but major 194 mi&lt;BR /&gt;smatch&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID seems Unity/DPD but major 123 mi&lt;BR /&gt;smatch&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is NAT-T v2&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is Unity&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): Authentication by xauth preshared&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0):Checking ISAKMP transform 1 against priorit&lt;BR /&gt;y 100 policy&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; encryption AES-CBC&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hash SHA&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default group 2&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; auth XAUTHInitPreShared&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; life type in seconds&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; life duration (VPI) of&amp;nbsp; 0x0 0x20 0xC4 0x9&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:39:26 GMT</pubDate>
    <dc:creator>amar_5664</dc:creator>
    <dc:date>2019-03-11T00:39:26Z</dc:date>
    <item>
      <title>Remote client AUTH to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/remote-client-auth-to-acs/m-p/1586716#M258463</link>
      <description>&lt;P&gt;I have been trying to get remote ipsec client get authenticated via ACS, cannot figure out what is causing the issue. Below is the configuration and debugs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything specific that needs to be configured on the ACS?? BTW ACS version is 3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any input is appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config on router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login 3Gusers group tacacs+&lt;BR /&gt;aaa authorization network 3Gusers group tacacs+&lt;/P&gt;&lt;P&gt;crypto isakmp policy 100&lt;BR /&gt; encr 3des&lt;BR /&gt; authentication pre-share&lt;BR /&gt; group 2&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp client configuration group 3Gvpn&lt;BR /&gt; key trewq&lt;BR /&gt; dns 10.142.171.22 10.142.171.21&lt;BR /&gt; pool 3Gpool&lt;BR /&gt; netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp profile 3Gclient&lt;BR /&gt;&amp;nbsp;&amp;nbsp; match identity group 3Gvpn&lt;BR /&gt;&amp;nbsp;&amp;nbsp; client authentication list 3Gusers&lt;BR /&gt;&amp;nbsp;&amp;nbsp; isakmp authorization list 3Gusers&lt;BR /&gt;&amp;nbsp;&amp;nbsp; client configuration address respond&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec transform-set 3G esp-3des esp-md5-hmac &lt;BR /&gt;!&lt;BR /&gt;crypto dynamic-map 3Gmap 10&lt;BR /&gt; set security-association idle-time 86400&lt;BR /&gt; set transform-set 3G &lt;BR /&gt; set isakmp-profile 3Gclient&lt;BR /&gt; reverse-route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug----&lt;/P&gt;&lt;P&gt;Dec 15 16:21:19.566 EDST: ISAKMP (0): received packet from 10.200.0.106 dport 50&lt;BR /&gt;0 sport 3553 Global (N) NEW SA&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: Created a peer struct for 10.200.0.106, peer p&lt;BR /&gt;ort 3553&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: New peer created peer = 0x3AE6B3EC peer_handle&lt;BR /&gt; = 0x8000001F&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: Locking peer struct 0x3AE6B3EC, refcount 1 for&lt;BR /&gt; crypto_isakmp_process_block&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP[R]: sa-&amp;gt;swdb: GigabitEthernet1/2/1&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: local port 500, remote port 3553&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP: Find a dup sa in the avl tree during calling i&lt;BR /&gt;sadb_insert sa = 3AFB77A8&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0): processing SA payload. message ID = 0&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0): processing ID payload. message ID = 0&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP (0): ID payload &lt;BR /&gt;next-payload : 13&lt;BR /&gt;type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 11 &lt;BR /&gt;group id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3Gvpn &lt;BR /&gt;protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 17 &lt;BR /&gt;port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 500 &lt;BR /&gt;length&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 13&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0):: peer matches 3Gclient profile&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0):Setting client config settings 3A7D8D0C&lt;BR /&gt;Dec 15 16:21:19.566 EDST: ISAKMP:(0):(Re)Setting client xauth list&amp;nbsp; and state&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP/xauth: initializing AAA request&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID seems Unity/DPD but major 215 mi&lt;BR /&gt;smatch&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is XAUTH&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is DPD&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID seems Unity/DPD but major 194 mi&lt;BR /&gt;smatch&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID seems Unity/DPD but major 123 mi&lt;BR /&gt;smatch&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is NAT-T v2&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): processing vendor id payload&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): vendor ID is Unity&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0): Authentication by xauth preshared&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:(0):Checking ISAKMP transform 1 against priorit&lt;BR /&gt;y 100 policy&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; encryption AES-CBC&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hash SHA&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default group 2&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; auth XAUTHInitPreShared&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; life type in seconds&lt;BR /&gt;Dec 15 16:21:19.567 EDST: ISAKMP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; life duration (VPI) of&amp;nbsp; 0x0 0x20 0xC4 0x9&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:39:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remote-client-auth-to-acs/m-p/1586716#M258463</guid>
      <dc:creator>amar_5664</dc:creator>
      <dc:date>2019-03-11T00:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Remote client AUTH to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/remote-client-auth-to-acs/m-p/1586717#M258487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; On the ACS, you need to check if the Radius Access-request packet are making into the ACS. Please check ACS report and Acitvity to see if there is failed attempts . Check to see what error is displayed, that should help you with initial troubleshooting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Note: Please rate the answer if it was helpful&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 18:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remote-client-auth-to-acs/m-p/1586717#M258487</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2010-12-16T18:14:54Z</dc:date>
    </item>
  </channel>
</rss>

