<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No prompt for password change for VPN client authenticate us in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509715#M377512</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Password change/management through RADIUS is not supported for users in the local database. Password management to users in external stores is supported, and is documented in CSCsj50218 (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsj50218"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsj50218&lt;/A&gt;&lt;SPAN&gt;). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said, while not officially supported, password management to the ACS internal database for VPN users connecting to an ASA is known to work over TACACS on both ACS 4.x and 5.1+.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Dec 2010 23:34:52 GMT</pubDate>
    <dc:creator>slawford</dc:creator>
    <dc:date>2010-12-01T23:34:52Z</dc:date>
    <item>
      <title>No prompt for password change for VPN client authenticate using ACS local DB</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509709#M377506</link>
      <description>&lt;P&gt;I'm setting up VPN authentication using ACS 5.1 and ASA 8.0.5. User connects using Cisco VPN client, and is authenticated to Internal users db on ACS. Everything works, except that if "Change password on next login" is checked for a user, the login will fail. The Radius log on ACS says user need to change password. However it didn't prompt for the password change. I know there must be a simple option either in VPN client profile or ini file, or on ASA tunnel group definition. However I tried several options, still couldn't make it work. Does anyone know?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tao&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509709#M377506</guid>
      <dc:creator>jintao99</dc:creator>
      <dc:date>2019-03-11T00:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: No prompt for password change for VPN client authenticate us</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509710#M377507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe the change password a next logon will only work if user logs into a device using telnet. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 01:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509710#M377507</guid>
      <dc:creator>rodmunch999</dc:creator>
      <dc:date>2010-10-05T01:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: No prompt for password change for VPN client authenticate us</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509711#M377508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can someone from Cisco confirm if this is the case? Hard to believe that this won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tao&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 14:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509711#M377508</guid>
      <dc:creator>jintao99</dc:creator>
      <dc:date>2010-10-05T14:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: No prompt for password change for VPN client authenticate us</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509712#M377509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also stuck with the same issue and have no idea how to encourage user &lt;SPAN style="background-color: #f8fafd;"&gt;to change their password. Please share if you have any clue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;PK,&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Nov 2010 07:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509712#M377509</guid>
      <dc:creator>iam_pomme</dc:creator>
      <dc:date>2010-11-16T07:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: No prompt for password change for VPN client authenticate us</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509713#M377510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all, I'm having this same issue, is there any way to make users change their passwords via a prompt in the vpn client, Im using ASA 8.2 and ACS 4.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A response from Cisco would be appreciate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 16:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509713#M377510</guid>
      <dc:creator>hector.ricapa</dc:creator>
      <dc:date>2010-11-29T16:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: No prompt for password change for VPN client authenticate us</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509714#M377511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To make it work, MS-CHAPv2 must be selected in allowed protocol under ACS access policy. And under VPN tunnel group, enable password management. However this does't fix the issue in my case. Because all my other users should be using PAP/ASCII, when MS-CHAPv2 enabled, somehow all authentication would be using MS-CHAPv2 and fail. And I can't think of a way to define two different VPN policies to separate these two type of authenticaton requests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 16:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509714#M377511</guid>
      <dc:creator>jintao99</dc:creator>
      <dc:date>2010-11-29T16:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: No prompt for password change for VPN client authenticate us</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509715#M377512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Password change/management through RADIUS is not supported for users in the local database. Password management to users in external stores is supported, and is documented in CSCsj50218 (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsj50218"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsj50218&lt;/A&gt;&lt;SPAN&gt;). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said, while not officially supported, password management to the ACS internal database for VPN users connecting to an ASA is known to work over TACACS on both ACS 4.x and 5.1+.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 23:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509715#M377512</guid>
      <dc:creator>slawford</dc:creator>
      <dc:date>2010-12-01T23:34:52Z</dc:date>
    </item>
    <item>
      <title>tunnel-group RA general</title>
      <link>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509716#M377513</link>
      <description>&lt;PRE class="prettyprint"&gt;tunnel-group RA general-attributes&lt;BR /&gt;&amp;nbsp;authentication-server-group ACS&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;password-management&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;The &lt;STRONG&gt;password-management&lt;/STRONG&gt; command changes the behavior so that the ASA is forced to use MSCHAPv2, rather than PAP, in the Radius-Request.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 07:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-prompt-for-password-change-for-vpn-client-authenticate-using/m-p/1509716#M377513</guid>
      <dc:creator>Eternity</dc:creator>
      <dc:date>2016-09-22T07:44:50Z</dc:date>
    </item>
  </channel>
</rss>

