<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX IpSec Authentication Questions. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351766#M2947</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 3000 concentrators are a completely different product, they support tcp encapsulation of IPSec packets, ip compression, QOS, etc - all features that 6.3 pix os does not offer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Feb 2005 18:41:06 GMT</pubDate>
    <dc:creator>mostiguy</dc:creator>
    <dc:date>2005-02-24T18:41:06Z</dc:date>
    <item>
      <title>PIX IpSec Authentication Questions.</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351763#M2944</link>
      <description>&lt;P&gt;I am looking at using a pair of PIX 525 for firewalling and ipsec termination.  The firewall will have two physical and about 8 virtual interfaces.  I would like to have the pix be the termination point for ipsec traffic on two interfaces, outside and extranet.&lt;/P&gt;&lt;P&gt;-Is this a valid concept.&lt;/P&gt;&lt;P&gt;-Can I have it setup so user can authenticate from the internet, extranet, or both.&lt;/P&gt;&lt;P&gt;-Can the PIX support the Microsoft L2TP VPN solution.&lt;/P&gt;&lt;P&gt;-Can the PIX use RADIUS to authenticate remote users and remote management (telnet/ssh to the PIX)...can it be setup so the user ID can do one or the other or both. &lt;/P&gt;&lt;P&gt;-Can the PIX use one RADIUS server to authenticate remote users and another to authenticate remote management.&lt;/P&gt;&lt;P&gt;-What is the impact to the ipsec users when the PIX does a failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dan Laden&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351763#M2944</guid>
      <dc:creator>dladen</dc:creator>
      <dc:date>2020-02-21T18:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: PIX IpSec Authentication Questions.</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351764#M2945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;-Is this a valid concept. &lt;/P&gt;&lt;P&gt;A - Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Can I have it setup so user can authenticate from the internet, extranet, or both. &lt;/P&gt;&lt;P&gt;A - Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Can the PIX support the Microsoft L2TP VPN solution.&lt;/P&gt;&lt;P&gt;A - Yes, but support for PPTP and L2TP are being removed from all PIX releases beyond 6.3.  So, if you have any plans to upgrade in the future, I would suggest an IPSec solution.  The Cisco IPSec client is free of charge with the PIX.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;-Can the PIX use RADIUS to authenticate remote users and remote management (telnet/ssh to the PIX)...can it be setup so the user ID can do one or the other or both.&lt;/P&gt;&lt;P&gt;A - Yes, though configuring the authorization options could be a little tricky.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;-Can the PIX use one RADIUS server to authenticate remote users and another to authenticate remote management. &lt;/P&gt;&lt;P&gt;A - Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-What is the impact to the ipsec users when the PIX does a failover. &lt;/P&gt;&lt;P&gt;A - All tunnels will fail and need to re-established.  There is no concept of stateful failover for IPSec client connections on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2005 15:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351764#M2945</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2005-02-24T15:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX IpSec Authentication Questions.</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351765#M2946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, this is what I needed to know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Can the PIX use RADIUS to authenticate remote users and remote management (telnet/ssh to the PIX)...can it be setup so the user ID can do one or the other or both.&lt;/P&gt;&lt;P&gt;A - Yes, though configuring the authorization options could be a little tricky. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know of a document that details how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I am familiar with the VPN Concentrator 3030, are their any function in the 3030 that cannot be replicated in the PIX firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2005 16:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351765#M2946</guid>
      <dc:creator>dladen</dc:creator>
      <dc:date>2005-02-24T16:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX IpSec Authentication Questions.</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351766#M2947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 3000 concentrators are a completely different product, they support tcp encapsulation of IPSec packets, ip compression, QOS, etc - all features that 6.3 pix os does not offer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2005 18:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351766#M2947</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2005-02-24T18:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: PIX IpSec Authentication Questions.</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351767#M2948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The documentation details you are looking for would be related to the RADIUS server you are planning to use for this function.  All the PIX cares about getting is a YES or NO from the authentication server.  You would need to make sure your AAA server could make a distinction between a VPN client connection and an admin connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As has been pointed out, the VPN 3000 series is a full featured VPN platform.  The PIX, while very capable, does not offer near the number of "bells and whistles" as the 3000 does with respect to VPN functionality.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2005 19:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-ipsec-authentication-questions/m-p/351767#M2948</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2005-02-24T19:25:31Z</dc:date>
    </item>
  </channel>
</rss>

