<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX VPN Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135303#M3286</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Introduced in 6.3, you would do:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;MAPNAME&gt; client authentication LOCAL&lt;/MAPNAME&gt;&lt;/P&gt;&lt;P&gt;username &lt;NAME&gt; password &lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have as many username/password entries as you like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Sep 2003 05:04:21 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2003-09-12T05:04:21Z</dc:date>
    <item>
      <title>PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135300#M3271</link>
      <description>&lt;P&gt;Can someone tell me all the options for authenticating VPN users on the PIX (515e v6.31)?  I dont see any way to do local user authentication based on the VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know of the following options:&lt;/P&gt;&lt;P&gt;AAA using Tacacs&lt;/P&gt;&lt;P&gt;AAA using Radius&lt;/P&gt;&lt;P&gt;VPN Group with local password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135300#M3271</guid>
      <dc:creator>gparrish</dc:creator>
      <dc:date>2020-02-21T18:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135301#M3278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by "local user authentication based on the vpn client"? If you mean each user has a unique username and password, that was introduced in pix os 6.2 (maybe 6.3).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2003 00:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135301#M3278</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2003-09-12T00:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135302#M3283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I mean that.  In the normal Cisco IOS context you normally have like tacacs and local authentication choices so thanks for that bit of information! I will look into how to configure that.  Just trying to figure out all the options so we can select one to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2003 01:06:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135302#M3283</guid>
      <dc:creator>gparrish</dc:creator>
      <dc:date>2003-09-12T01:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135303#M3286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Introduced in 6.3, you would do:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;MAPNAME&gt; client authentication LOCAL&lt;/MAPNAME&gt;&lt;/P&gt;&lt;P&gt;username &lt;NAME&gt; password &lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have as many username/password entries as you like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2003 05:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135303#M3286</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-09-12T05:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135304#M3295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any idea how to configure the VPN Client with the username and password for authentication since it only accepts the Group and CA Certificate options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2003 12:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135304#M3295</guid>
      <dc:creator>gparrish</dc:creator>
      <dc:date>2003-09-12T12:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135305#M3296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;You do not need to configure username and password within the client. Once the client tries to connect the user will be prompted to enter username and password. Only put in groupname and grouppassword and you'll be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2003 13:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135305#M3296</guid>
      <dc:creator>l.mourits</dc:creator>
      <dc:date>2003-09-12T13:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135306#M3297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay so this provides even more authentication?  You have to use the VPN Group and then you could also authenticate each user in addition to that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds like you have to use the VPN Group or a certificate at all times?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2003 21:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135306#M3297</guid>
      <dc:creator>gparrish</dc:creator>
      <dc:date>2003-09-12T21:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135307#M3298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, user authentication is a 2nd level of authentication.  You don't actually have to do it (just don't add in the two commands I mentioned previously), and then the client will get in simply with having the correct group name/password or certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would always use user authentication though, considering the group name/password or cert is stored on the PC all the time.  If that PC gets stolen and you have no user authentication set up, the thief has open access into your network.  The group name/password or cert authenticate the PC that is connecting, whereas the extra user authentication authenticates the person sitting at that PC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Sep 2003 00:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-vpn-authentication/m-p/135307#M3298</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-09-13T00:07:37Z</dc:date>
    </item>
  </channel>
</rss>

