<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP Authentication of VPN without IAS/NPS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784370#M292276</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I used everything behind the DC like this:&lt;/P&gt;&lt;P&gt;"CN=cisco Systems,OU=ServiceAccounts,OU=Accounts,DC=gulfbasco,DC=local"&lt;/P&gt;&lt;PRE&gt;So I used:&lt;BR /&gt;base-dn "DC=gulfbasco,DC=local"&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Aug 2011 18:24:23 GMT</pubDate>
    <dc:creator>dflick</dc:creator>
    <dc:date>2011-08-20T18:24:23Z</dc:date>
    <item>
      <title>LDAP Authentication of VPN without IAS/NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784368#M292244</link>
      <description>&lt;P&gt;Here is a snippet of my proposed config for LDAP&lt;/P&gt;&lt;P&gt;aaa group server ldap AD&lt;/P&gt;&lt;P&gt; server TESTSERVER&lt;/P&gt;&lt;P&gt;ldap attribute-map ADTEST&lt;/P&gt;&lt;P&gt;ldap server TESTSERVER&lt;/P&gt;&lt;P&gt; ipv4 192.168.0.20&lt;/P&gt;&lt;P&gt; bind authenticate root-dn testuser password testpw&lt;/P&gt;&lt;P&gt; base-dn DC=testdomain,DC=local&lt;/P&gt;&lt;P&gt;The username and password exist and can auth to AD directly.&amp;nbsp; I get the logs below when I try to hit from VPN.&amp;nbsp; Does anyone have this working that can give me some pointers? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;000293: Aug 20 10:37:42: AAA/BIND(00000E04): Bind i/f&lt;/P&gt;&lt;P&gt;000294: Aug 20 10:37:42: AAA/AUTHEN/LOGIN (00000E04): Pick method list 'AD'&lt;/P&gt;&lt;P&gt;000295: Aug 20 10:37:42: %AAA-3-BADSERVERTYPEERROR: Cannot process authenticatio&lt;/P&gt;&lt;P&gt;n server type *invalid_group_handle*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C1900 Software (C1900-UNIVERSALK9-M), Version 15.1(4)M1, REL&lt;/P&gt;&lt;P&gt;EASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System image file is "flash:c1900-universalk9-mz.SPA.151-4.M1.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gulf-Inet#&lt;/P&gt;&lt;P&gt;000296: Aug 20 10:48:00: LDAP: Received socket event&lt;/P&gt;&lt;P&gt;000297: Aug 20 10:48:00: LDAP: Checking the conn status&lt;/P&gt;&lt;P&gt;000298: Aug 20 10:48:00: LDAP: Socket read event socket=0&lt;/P&gt;&lt;P&gt;000299: Aug 20 10:48:00: LDAP: Found socket ctx&lt;/P&gt;&lt;P&gt;000300: Aug 20 10:48:00: LDAP: Receive event: read=0, errno=11 (Resource tempora&lt;/P&gt;&lt;P&gt;rily unavailable)&lt;/P&gt;&lt;P&gt;000301: Aug 20 10:48:00: LDAP: Connection closed remotely !!&lt;/P&gt;&lt;P&gt;000302: Aug 20 10:48:00: LDAP: ldap tcp transport closing on socket 0&lt;/P&gt;&lt;P&gt;000303: Aug 20 10:48:00: LDAP: Protocol received transport down notification&lt;/P&gt;&lt;P&gt;000304: Aug 20 10:48:00: LDAP: Server-GULFBASCO connection going down !!!&lt;/P&gt;&lt;P&gt;000305: Aug 20 10:48:00: LDAP: Clearing all ldap transactions&lt;/P&gt;&lt;P&gt;000306: Aug 20 10:48:00: LDAP: Connection state: UP =&amp;gt; DOWN&lt;/P&gt;&lt;P&gt;000307: Aug 20 10:48:00: LDAP: Connection state: DOWN =&amp;gt; DOWN&lt;/P&gt;&lt;P&gt;000308: Aug 20 10:48:00: LDAP: Connection timer started for 30 seconds for GULFB&lt;/P&gt;&lt;P&gt;ASCO&lt;/P&gt;&lt;P&gt;000309: Aug 20 10:48:00: LDAP: socket 0 - CONN_UP-&amp;gt;CONN_CLOSE&lt;/P&gt;&lt;P&gt;000310: Aug 20 10:48:00: LDAP: Received socket event&lt;/P&gt;&lt;P&gt;000311: Aug 20 10:48:30: LDAP: Received timer event&lt;/P&gt;&lt;P&gt;000312: Aug 20 10:48:30: LDAP: Connection timeout occured. Retrying&lt;/P&gt;&lt;P&gt;000313: Aug 20 10:48:30: LDAP: Opening ldap connection ( 192.168.254.23, 389 )&lt;/P&gt;&lt;P&gt;000314: Aug 20 10:48:30: LDAP: socket 0 - connecting to 192.168.254.23 (389)&lt;/P&gt;&lt;P&gt;000315: Aug 20 10:48:30: LDAP: socket 0 - connection in progress&lt;/P&gt;&lt;P&gt;000316: Aug 20 10:48:30: LDAP: socket 0 - local address 192.168.254.254 (63758)&lt;/P&gt;&lt;P&gt;000317: Aug 20 10:48:30: LDAP: Connection on socket 0&lt;/P&gt;&lt;P&gt;000318: Aug 20 10:48:30: LDAP: Connection to LDAP server (GULFBASCO, 192.168.254&lt;/P&gt;&lt;P&gt;.23) attempted&lt;/P&gt;&lt;P&gt;000319: Aug 20 10:48:30: LDAP: Connection state: DOWN =&amp;gt; CONNECTING&lt;/P&gt;&lt;P&gt;000320: Aug 20 10:48:30: LDAP: Received socket event&lt;/P&gt;&lt;P&gt;000321: Aug 20 10:48:30: LDAP: Checking the conn status&lt;/P&gt;&lt;P&gt;000322: Aug 20 10:48:30: LDAP: Socket read event socket=0&lt;/P&gt;&lt;P&gt;000323: Aug 20 10:48:30: LDAP: Found socket ctx&lt;/P&gt;&lt;P&gt;000324: Aug 20 10:48:30: LDAP: Making socket conn up&lt;/P&gt;&lt;P&gt;000325: Aug 20 10:48:30: LDAP: Notify the protocol code&lt;/P&gt;&lt;P&gt;000326: Aug 20 10:48:30: LDAP: Protocol received transport up notication&lt;/P&gt;&lt;P&gt;000327: Aug 20 10:48:30: LDAP: Connection state: CONNECTING =&amp;gt; UP&lt;/P&gt;&lt;P&gt;000328: Aug 20 10:48:30: LDAP: Set socket=0 to non blocking mode&lt;/P&gt;&lt;P&gt;000329: Aug 20 10:48:30: LDAP: Performing Root-Dn bind operation&lt;/P&gt;&lt;P&gt;000330: Aug 20 10:48:30: LDAP: Root Bind on ciscoauth initiated.&lt;/P&gt;&lt;P&gt;000331: Aug 20 10:48:30: LDAP: Received socket event&lt;/P&gt;&lt;P&gt;000332: Aug 20 10:48:31: LDAP: Received socket event&lt;/P&gt;&lt;P&gt;000333: Aug 20 10:48:31: LDAP: Checking the conn status&lt;/P&gt;&lt;P&gt;000334: Aug 20 10:48:31: LDAP: Socket read event socket=0&lt;/P&gt;&lt;P&gt;000335: Aug 20 10:48:31: LDAP: Found socket ctx&lt;/P&gt;&lt;P&gt;000336: Aug 20 10:48:31: LDAP: Receive event: read=1, errno=11 (Resource tempora&lt;/P&gt;&lt;P&gt;rily unavailable)&lt;/P&gt;&lt;P&gt;000337: Aug 20 10:48:31: LDAP: Passing the client ctx=317267D0&lt;/P&gt;&lt;P&gt;000338: Aug 20 10:48:31: LDAP: LDAP Messages to be processed: 1&lt;/P&gt;&lt;P&gt;000339: Aug 20 10:48:31: LDAP: LDAP Message type: 97&lt;/P&gt;&lt;P&gt;000340: Aug 20 10:48:31: LDAP: Got ldap transaction context from reqid 2&lt;/P&gt;&lt;P&gt;000341: Aug 20 10:48:31: LDAP: Received Bind Response&lt;/P&gt;&lt;P&gt;000342: Aug 20 10:48:31: LDAP: Received Root Bind Response&lt;/P&gt;&lt;P&gt;000343: Aug 20 10:48:31: LDAP: Failed to do Root Bind on ciscoauth. Bind anonymo&lt;/P&gt;&lt;P&gt;us&lt;/P&gt;&lt;P&gt;000344: Aug 20 10:48:31: LDAP: Transaction context removed from list [ldap reqid&lt;/P&gt;&lt;P&gt;=2]&lt;/P&gt;&lt;P&gt;000345: Aug 20 10:48:31: LDAP: Finished processing ldap msg, Result:Success&lt;/P&gt;&lt;P&gt;000346: Aug 20 10:48:31: LDAP: Received socket event&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connection to host lost.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:20:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784368#M292244</guid>
      <dc:creator>dflick</dc:creator>
      <dc:date>2019-03-11T01:20:18Z</dc:date>
    </item>
    <item>
      <title>LDAP Authentication of VPN without IAS/NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784369#M292257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The bind username has to be specified as the full LDAP object path per this &lt;A href="http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_cfg_ldap.html#wp1069114"&gt;http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_cfg_ldap.html#wp1069114&lt;/A&gt;. Use dsquery on the username that you want to use for the intial&amp;nbsp; lookup bind to get the full LDAP object description and set that&amp;nbsp; instead:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dsquery user -samid user_name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, remember to delegate permissions to this account to allow them to read AD.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Aug 2011 18:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784369#M292257</guid>
      <dc:creator>Minhua Zhu</dc:creator>
      <dc:date>2011-08-20T18:18:07Z</dc:date>
    </item>
    <item>
      <title>LDAP Authentication of VPN without IAS/NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784370#M292276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I used everything behind the DC like this:&lt;/P&gt;&lt;P&gt;"CN=cisco Systems,OU=ServiceAccounts,OU=Accounts,DC=gulfbasco,DC=local"&lt;/P&gt;&lt;PRE&gt;So I used:&lt;BR /&gt;base-dn "DC=gulfbasco,DC=local"&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Aug 2011 18:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784370#M292276</guid>
      <dc:creator>dflick</dc:creator>
      <dc:date>2011-08-20T18:24:23Z</dc:date>
    </item>
    <item>
      <title>LDAP Authentication of VPN without IAS/NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784371#M292302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm referring to this line:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bind authenticate root-dn testuser password testpw&lt;/P&gt;&lt;P&gt;it should be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bind authenticate root-dn "cn=testuser,ou=serviceaccounts,ou=accounts,dc=gulfbasco,dc=local" password blah&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the base-dn config line refers to the search base DN, not the bind base DN. Your debug output indicates that it is failing to bind to LDAP, i.e. authenticate with the testuser account specified in the bind configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Aug 2011 18:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784371#M292302</guid>
      <dc:creator>Minhua Zhu</dc:creator>
      <dc:date>2011-08-20T18:30:03Z</dc:date>
    </item>
    <item>
      <title>LDAP Authentication of VPN without IAS/NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784372#M292326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still erroring.&amp;nbsp; I tried with CN=full user name and CN=shortname.&amp;nbsp; Which should I be using and are there any other debugs that might help me figure out what is wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;000874: Aug 20 13:35:33: LDAP:&amp;nbsp; Filter: (objectclass=*)&lt;/P&gt;&lt;P&gt;000875: Aug 20 13:35:33: %SYS-5-CONFIG_I: Configured from console by admin on vt&lt;/P&gt;&lt;P&gt;y0 (192.168.254.23)&lt;/P&gt;&lt;P&gt;000876: Aug 20 13:35:33: LDAP: Received message event&lt;/P&gt;&lt;P&gt;000877: Aug 20 13:35:33: LDAP: Connection to LDAP server (GULFBASCO) already UP&lt;/P&gt;&lt;P&gt;000878: Aug 20 13:35:45: AAA/BIND(00000E08): Bind i/f&lt;/P&gt;&lt;P&gt;000879: Aug 20 13:35:45: AAA/AUTHEN/LOGIN (00000E08): Pick method list 'AD'&lt;/P&gt;&lt;P&gt;000880: Aug 20 13:36:07: AAA/BIND(00000E09): Bind i/f&lt;/P&gt;&lt;P&gt;000881: Aug 20 13:36:07: AAA/AUTHEN/LOGIN (00000E09): Pick method list 'AD'&lt;/P&gt;&lt;P&gt;000882: Aug 20 13:36:07: %AAA-3-BADSERVERTYPEERROR: Cannot process authenticatio&lt;/P&gt;&lt;P&gt;n server type *invalid_group_handle*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Aug 2011 18:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784372#M292326</guid>
      <dc:creator>dflick</dc:creator>
      <dc:date>2011-08-20T18:37:50Z</dc:date>
    </item>
    <item>
      <title>LDAP Authentication of VPN without IAS/NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784373#M292343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever find a resolution for this issue?&amp;nbsp; I'm having similar problems and getting the same error message.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 21:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-of-vpn-without-ias-nps/m-p/1784373#M292343</guid>
      <dc:creator>dp25269</dc:creator>
      <dc:date>2011-10-14T21:49:45Z</dc:date>
    </item>
  </channel>
</rss>

