<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA authentication over L2L in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604445#M346168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ivan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tested aaa server with inside and outside interface. Management is set to inside interface. Same result - No responce.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will test tomorrow and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've just set up a new ASA5505 at home and tested radius up against our main office - No responce &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; aaa server is set to outside interface and im trying to connect to our main office WAN IP... 1645 and 1646 UDP ports are forwarded at main office... This should work to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help so far &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Jan 2011 22:28:06 GMT</pubDate>
    <dc:creator>csondergaard</dc:creator>
    <dc:date>2011-01-04T22:28:06Z</dc:date>
    <item>
      <title>AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604438#M346050</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ASA5505 with a L2L tunnel set up for our main office. L2L is working - no problems there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is we have some Remote VPN Clients that connects to this ASA 5505.. And i need it to authenticate to our radius (Windows 2003) in main office.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've set "Management interface inside" and i can manage the ASA5505 from my radius server (Both via SSH and ASDM).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also tried to forward port 1645,1646 from outside to my radius server in main office and set the ASA5505 to conect to its outside IP address - No luck there either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to enable something specific to allow radius traffic to an external host?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Carsten&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:41:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604438#M346050</guid>
      <dc:creator>csondergaard</dc:creator>
      <dc:date>2019-03-11T00:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604439#M346073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand the radius server is behind the main office and you wish to authenticate the RA VPN users across the L2L tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;topology is something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RA VPN users -- ASA -- Main office device -- Radius server (win 2k3).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please correct if above is wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please include the traffic from the pool to radius server and reverse as a part of interesting traffic(crypto acl) and nat exemption. That sholud resolve the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if this helps! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jan 2011 12:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604439#M346073</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-01-03T12:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604440#M346086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology is correct &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I authenticate a user with the LOCAL user database the user can access the ASA5505 network AND our main office. No problems there either.. Just the radius traffic i have problems with &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Carsten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jan 2011 13:12:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604440#M346086</guid>
      <dc:creator>csondergaard</dc:creator>
      <dc:date>2011-01-03T13:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604441#M346098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the test aaa authentication &lt;AAA-SERVER&gt; host x.x.x.x username &lt;USERNAME&gt; password &lt;PASSWORD&gt; working from the ASA??&lt;/PASSWORD&gt;&lt;/USERNAME&gt;&lt;/AAA-SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes, then you need to define the traffic in crypto ACL i.e.the pool ip address to the radius server and reverse on the other end of the tunnel.&lt;/P&gt;&lt;P&gt;please ensure you have a nat exemption for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jan 2011 13:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604441#M346098</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-01-03T13:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604442#M346122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When using this line:&lt;/P&gt;&lt;P&gt;test aaa authentication partnerauth host 172.20.12.9 usernamen Administrator password xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get this:&lt;/P&gt;&lt;P&gt;INFO: Attempting Authentication test to IP address &lt;DOMINO&gt; (timeout: 12 seconds)&lt;BR /&gt;ERROR: Authentication Server not responding: No error&lt;/DOMINO&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the host 172.20.12.9 (The radius server) i can ping the ASA's inside interface (172.16.7.1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Carsten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jan 2011 14:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604442#M346122</guid>
      <dc:creator>csondergaard</dc:creator>
      <dc:date>2011-01-03T14:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604443#M346130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please enable following debugs:&lt;/P&gt;&lt;P&gt;1. Debugs aaa authentication&lt;/P&gt;&lt;P&gt;2. debug radius all&lt;/P&gt;&lt;P&gt;3. term mon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try the test command and please paste the debug output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jan 2011 15:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604443#M346130</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-01-03T15:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604444#M346146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carsten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is your aaa server setup defined? is it showing something like aaa-server .... (inside) or outside? can you re enter the setup making sure the interface is defined as inside, management access allows the management traffic to go sourced from inside interface, however if your setup is not defined as inside it might not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jan 2011 19:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604444#M346146</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2011-01-04T19:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604445#M346168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ivan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tested aaa server with inside and outside interface. Management is set to inside interface. Same result - No responce.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will test tomorrow and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've just set up a new ASA5505 at home and tested radius up against our main office - No responce &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; aaa server is set to outside interface and im trying to connect to our main office WAN IP... 1645 and 1646 UDP ports are forwarded at main office... This should work to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help so far &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jan 2011 22:28:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604445#M346168</guid>
      <dc:creator>csondergaard</dc:creator>
      <dc:date>2011-01-04T22:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604446#M346196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your Radius server must have a client ip address definition, what is this ip address the public ip address of the remote ASA devices? As for your port forwarding well yeah you must allow 1645 for authentication and must have a static nat entry or static port forward entry along with the proper acls in place.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jan 2011 22:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604446#M346196</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2011-01-04T22:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication over L2L</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604447#M346261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have no idea why - But now its works...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Had just entered your debug commands and tested AAA authentiaction again... Then it just replied "Authentication succesfull"..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe the Windows server was rebooted or something..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ended up using "inside" interface and the L2L tunnel for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway - Thanks alot for all your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 10:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-over-l2l/m-p/1604447#M346261</guid>
      <dc:creator>csondergaard</dc:creator>
      <dc:date>2011-01-07T10:09:56Z</dc:date>
    </item>
  </channel>
</rss>

