<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN3005 and ACS Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vpn3005-and-acs-problem/m-p/419992#M428750</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When using Cisco ACS as the RADIUS server, the authentication is being failed by the VPN Concentrator with the following message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Authentication Rejected: Group password is not configured"&lt;/P&gt;&lt;P&gt;Even though the the ACS server send an Access-Accept back to the VPN concentrator but VPN concetrator still rejects the connect attempt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I replace the ACS server with a Windows IAS RADIUS server then Authentication is OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is ACS server sending some kind of VSA to the VPN box, which causes the rejection ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;\\ Naman&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:14:50 GMT</pubDate>
    <dc:creator>mnlatif</dc:creator>
    <dc:date>2019-03-10T21:14:50Z</dc:date>
    <item>
      <title>VPN3005 and ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn3005-and-acs-problem/m-p/419992#M428750</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When using Cisco ACS as the RADIUS server, the authentication is being failed by the VPN Concentrator with the following message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Authentication Rejected: Group password is not configured"&lt;/P&gt;&lt;P&gt;Even though the the ACS server send an Access-Accept back to the VPN concentrator but VPN concetrator still rejects the connect attempt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I replace the ACS server with a Windows IAS RADIUS server then Authentication is OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is ACS server sending some kind of VSA to the VPN box, which causes the rejection ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;\\ Naman&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn3005-and-acs-problem/m-p/419992#M428750</guid>
      <dc:creator>mnlatif</dc:creator>
      <dc:date>2019-03-10T21:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN3005 and ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn3005-and-acs-problem/m-p/419993#M428757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The message " Authentication Rejected: Group password is not configured" is often seen when you're passing back a group name from the Radius server, and that Radius group doesn't exist on the VPN. Check the Radius attributes on the Radius server for the user you are testing with (and the ACS group that user is in), do you have attribute 25 (Class) checked, and is there a value for it similar to "OU=groupname;"? Also, on ACS make sure the concentrator is being defined as Radius (Cisco VPN 3000).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2005 19:55:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn3005-and-acs-problem/m-p/419993#M428757</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2005-08-01T19:55:27Z</dc:date>
    </item>
  </channel>
</rss>

