<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kerberos pre-authentication issues - why now? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/1321661#M348059</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;Pre-authentication on the Active Directory (AD) should be disabled or it can lead to user authentication failure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check the kerberos authentication example for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008060f261.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008060f261.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 Dec 2009 17:43:45 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2009-12-04T17:43:45Z</dc:date>
    <item>
      <title>Kerberos pre-authentication issues - why now?</title>
      <link>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/1321660#M347965</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently put up a new Windows 2003 Active Directory domain controller to replace a de-commissioned Windows 2000 DC.&amp;nbsp; When my VPN users try to authenticate to it using Kerberos, they are getting rejected with a pre-authentication failed error.&amp;nbsp; I know that this is a common issue with the ASA, and TAC has confirmed that there's no solution for it yet.&amp;nbsp; However, we have another W2K3 DC that has never had this issue.&amp;nbsp; So why now?&amp;nbsp; Why this new DC?&amp;nbsp; What's the difference between my DCs where one can authenticate a user with pre-authentication enabled and one can't?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or information that I can get would be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;- Steve&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/1321660#M347965</guid>
      <dc:creator>rstevek</dc:creator>
      <dc:date>2019-03-10T23:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos pre-authentication issues - why now?</title>
      <link>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/1321661#M348059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;Pre-authentication on the Active Directory (AD) should be disabled or it can lead to user authentication failure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check the kerberos authentication example for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008060f261.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008060f261.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Dec 2009 17:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/1321661#M348059</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-12-04T17:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos pre-authentication issues - why now?</title>
      <link>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/1321662#M348137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right, I understand that, and TAC directed me to the same document.&amp;nbsp; But we have an existing domain controller that we are currently using the authenicate against; pre-authentication is enabled, and it works fine.&amp;nbsp; It's only the NEW domain controller that has this problem.&amp;nbsp; So I'm trying to figure out what the difference is!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would rather NOT disable pre-authentication for all VPN users if possible - there are a lot of them and it lessens the security of Active Directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;- Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Dec 2009 18:12:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/1321662#M348137</guid>
      <dc:creator>rstevek</dc:creator>
      <dc:date>2009-12-04T18:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos pre-authentication issues - why now?</title>
      <link>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/5246435#M594170</link>
      <description>&lt;P&gt;Sorry to revive a really ancient post, but did you ever figure this out?&amp;nbsp; We're finding that Apple Mac users get their AD account locked after connecting to VPN and a Kerberos pre-auth event occurs.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 13:26:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/kerberos-pre-authentication-issues-why-now/m-p/5246435#M594170</guid>
      <dc:creator>Scott Wertz</dc:creator>
      <dc:date>2025-01-13T13:26:07Z</dc:date>
    </item>
  </channel>
</rss>

