<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN, PIX,TACACS and RSA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896958#M408687</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply, I have installed the patch but unfortunatly I still cannot get the vpn client to ask me to enter a pin &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Oct 2007 07:15:09 GMT</pubDate>
    <dc:creator>nickyh_is</dc:creator>
    <dc:date>2007-10-09T07:15:09Z</dc:date>
    <item>
      <title>VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896954#M408683</link>
      <description>&lt;P&gt;Hi, currently our cisco vpn connections to our pix are authenticated by our TACACS server. I am trying to implement RSA secure ID by using the ACS as an agent. This part works fine, when I did a test authencation with rsa it asked to me create a pin. I am now able to authenticate via vpn with my ACS username and pin/token in the password box. However I dont know how to roll this out to users as I was expecting the cisco vpn client to ask any new users to create a pin, or to have a pin box ? Any ideas will be very appreciated.&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;&lt;P&gt;nicky&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896954#M408683</guid>
      <dc:creator>nickyh_is</dc:creator>
      <dc:date>2019-03-10T22:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896955#M408684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, Im confused - you said in your test the vpn client asked you to enter a new pin via TACACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Isnt that what you want?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2007 10:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896955#M408684</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-10-08T10:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896956#M408685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry, the test was done with the 'authentication test' facility in the rsa authentication agent that I have installed on the TACACS server. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2007 11:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896956#M408685</guid>
      <dc:creator>nickyh_is</dc:creator>
      <dc:date>2007-10-08T11:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896957#M408686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that the new PIN mode is not working and users are not able to authenticate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found a bug relating to the issue. Bug ID  :CSCsd41866&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsd41866&amp;amp;Subm" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsd41866&amp;amp;Subm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;it=Search&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patch can be downloaded from, &lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-3des" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-3des&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;File name : ACS-4.0.1-RSA-SW-CSCsc12614-CSCsd41866.zip&lt;/P&gt;&lt;P&gt;ACS-4.0.1-RSA-SW-CSCsc12614-CSCsd41866.txt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2007 12:37:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896957#M408686</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-10-08T12:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896958#M408687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply, I have installed the patch but unfortunatly I still cannot get the vpn client to ask me to enter a pin &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2007 07:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896958#M408687</guid>
      <dc:creator>nickyh_is</dc:creator>
      <dc:date>2007-10-09T07:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896959#M408688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've done quite a bit of Cisco ACS 4.1 and &lt;/P&gt;&lt;P&gt;RSA Securid version 6.2.  I think I can help&lt;/P&gt;&lt;P&gt;you with this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) install Win2k3 Enterprise Edition with &lt;/P&gt;&lt;P&gt;service pack 2 on a dedicate machine or&lt;/P&gt;&lt;P&gt;vmware if you like,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) run dcpromo to promote the box to be Active&lt;/P&gt;&lt;P&gt;Directory server if you want integration with&lt;/P&gt;&lt;P&gt;LDAP,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) install RSA SecurID version 6.2 on the&lt;/P&gt;&lt;P&gt;same server in step 2,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) install Cisco ACS 4.1 on the same server&lt;/P&gt;&lt;P&gt;listed in step 3,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5) &lt;A class="jive-link-custom" href="http://127.0.0.1:2002" target="_blank"&gt;http://127.0.0.1:2002&lt;/A&gt; to log into the ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6) create an agent host for the Cisco ACS&lt;/P&gt;&lt;P&gt;and generate the sdconf.rec file.  Place&lt;/P&gt;&lt;P&gt;this file under \windows\system32 directory,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7) Under the External database, you should see&lt;/P&gt;&lt;P&gt;something like unknown policy. database&lt;/P&gt;&lt;P&gt;group mapping, you should be asked if the&lt;/P&gt;&lt;P&gt;user is not found, what you should do.  At&lt;/P&gt;&lt;P&gt;this point, configure it for RSA SecurID.&lt;/P&gt;&lt;P&gt;Keep clicking, you will see something about&lt;/P&gt;&lt;P&gt;dll file stuffs, it means your SecurID &lt;/P&gt;&lt;P&gt;is properly configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; under the user group, rename group1 to &lt;/P&gt;&lt;P&gt;RSA SecurID.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9) Go back to External database section,&lt;/P&gt;&lt;P&gt;in there you will be able to map SecurID group&lt;/P&gt;&lt;P&gt;in step 8 to RSA SecurID.  Remember that this&lt;/P&gt;&lt;P&gt;is dynamic mapping.  In other words, these&lt;/P&gt;&lt;P&gt;users are dynamic created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10) go through the process of creating network&lt;/P&gt;&lt;P&gt;devices, make sure you have the right ip &lt;/P&gt;&lt;P&gt;addresses of the network device, pre-share&lt;/P&gt;&lt;P&gt;key, etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;11) restart Cisco ACS services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@dca2-LinuxES root]# telnet 192.168.0.5&lt;/P&gt;&lt;P&gt;Trying 192.168.0.5...&lt;/P&gt;&lt;P&gt;Connected to 192.168.0.5 (192.168.0.5).&lt;/P&gt;&lt;P&gt;Escape character is '^]'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: test3&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to enter your own pin? (y or n) [n]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enter your new Numerical PIN, containing 4 to 8 digits&lt;/P&gt;&lt;P&gt;         or&lt;/P&gt;&lt;P&gt;"x" to cancel the new PIN procedure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reenter PIN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now go back to the ACS and click on the&lt;/P&gt;&lt;P&gt;users tab, you will see test3 as a &lt;/P&gt;&lt;P&gt;"dynamic" user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing to be aware of. I do not believe&lt;/P&gt;&lt;P&gt;Pix 6.x code is capable of changing&lt;/P&gt;&lt;P&gt;the RSA PIN from the vpn client.  Pix 7.x &lt;/P&gt;&lt;P&gt;code is definitely capable of doing that.&lt;/P&gt;&lt;P&gt;Same thing with the VPN concentrator.  &lt;/P&gt;&lt;P&gt;Version 4.7.x will let you do that from &lt;/P&gt;&lt;P&gt;the VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks to me that you've configured the RSA&lt;/P&gt;&lt;P&gt;and the ACS correctly.  it is a matter of&lt;/P&gt;&lt;P&gt;using the right software on the&lt;/P&gt;&lt;P&gt;Pix and VPN concentrator.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin- CIE Security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2007 17:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896959#M408688</guid>
      <dc:creator>kevin.jones1</dc:creator>
      <dc:date>2007-10-09T17:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896960#M408689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks very much for the reply. I will try following your steps. Howvever, I have now configuring my pix vpn to authenticate directly to the rsa server instead of tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server testrsa-native protocol sdi&lt;/P&gt;&lt;P&gt; reactivation-mode timed&lt;/P&gt;&lt;P&gt;aaa-server testrsa-native host 172.16.17.10&lt;/P&gt;&lt;P&gt; retry-interval 3&lt;/P&gt;&lt;P&gt; timeout 13  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the vpn client asks for username and passcode (with acs it asked for password) I enter my token code but I still dont get the box asking me to create the pin ? It just fials and the rsa log shows 2 messages, passcode accepted, new pin required. Then ACCSS denied, new pin deffered.  Am I missing something ? I have pix712 and vpn4.8 ?&lt;/P&gt;&lt;P&gt;thanks again for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2007 09:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896960#M408689</guid>
      <dc:creator>nickyh_is</dc:creator>
      <dc:date>2007-10-10T09:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896961#M408690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could it be the VPN client isnt capable of handling the challenge/response correctly? ie its a username+password fire once only client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A simple test, if you can get an ascii terminal login to the PIX (or any IOS device) authenticated by RSA via ACS that includes new pin mode - then everything on the ACS/RSA side must be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could even try the ACS "tactest" program to mimick the IOS device. This lives in the bin folder and you need to add a T+ nas to ACS with the local ip address. You then run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tactest -H 127.0.0.1 -k secret&lt;/P&gt;&lt;P&gt;TACACS&amp;gt;&lt;/P&gt;&lt;P&gt;Commands available:&lt;/P&gt;&lt;P&gt;        authen action type service port remote [user]&lt;/P&gt;&lt;P&gt;                action &lt;LOGIN&gt;&lt;/LOGIN&gt;&lt;/P&gt;&lt;P&gt;                type &lt;ASCII&gt; &lt;/ASCII&gt;&lt;/P&gt;&lt;P&gt;                service &lt;LOGIN&gt;&lt;/LOGIN&gt;&lt;/P&gt;&lt;P&gt;        author arg1=value1 arg2=value2 ...&lt;/P&gt;&lt;P&gt;        acct arg1=value1 arg2=value2 ...        &lt;/P&gt;&lt;P&gt;TACACS&amp;gt; authen login ascii login tty0 &lt;/P&gt;&lt;P&gt;Username: rsausername&lt;/P&gt;&lt;P&gt;Password: pin+token&lt;/P&gt;&lt;P&gt;Authentication succeeded :&lt;/P&gt;&lt;P&gt;TACACS&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In  your case there would also be the new pin exchange tagged on the end.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2007 10:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896961#M408690</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-10-10T10:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896962#M408691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;good news is, the tactest worked exactly as it should with the new pin prompt. Thanks for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;not sure what to do now, my telnet to my pix is also not displaying the correct prompt. Just username and password (the password works once I have created a passcode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2007 13:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896962#M408691</guid>
      <dc:creator>nickyh_is</dc:creator>
      <dc:date>2007-10-10T13:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN, PIX,TACACS and RSA</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896963#M408692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have just upgraded my testpix to 722 and looks like this has resolved the issue. I did a telnet and got the pin prompt, yehh!! cant test the vpn yet though as this is on a  live pix which i cant upgrade.&lt;/P&gt;&lt;P&gt;thanks for your help with this&lt;/P&gt;&lt;P&gt;nicky&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2007 15:29:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-pix-tacacs-and-rsa/m-p/896963#M408692</guid>
      <dc:creator>nickyh_is</dc:creator>
      <dc:date>2007-10-10T15:29:22Z</dc:date>
    </item>
  </channel>
</rss>

