<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 3015 needs to authenticate PCs before permiiting access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93146#M4699</link>
    <description>&lt;P&gt;Can I use a MS certificate server to authenticate PCs going through a 3015 VPN concentrator?  The need is to ensure that we only allow approved PCs through the link.  Using a shared secret is not enough because an end user that knows the shared secret can load the vpn client on another box and configure to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:04:24 GMT</pubDate>
    <dc:creator>rob.wright</dc:creator>
    <dc:date>2020-02-21T18:04:24Z</dc:date>
    <item>
      <title>3015 needs to authenticate PCs before permiiting access</title>
      <link>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93146#M4699</link>
      <description>&lt;P&gt;Can I use a MS certificate server to authenticate PCs going through a 3015 VPN concentrator?  The need is to ensure that we only allow approved PCs through the link.  Using a shared secret is not enough because an end user that knows the shared secret can load the vpn client on another box and configure to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93146#M4699</guid>
      <dc:creator>rob.wright</dc:creator>
      <dc:date>2020-02-21T18:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: 3015 needs to authenticate PCs before permiiting access</title>
      <link>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93147#M4700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use certificates for authenticaqtion instead of pre-shared keys, if that is what you meant :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/471/installboth.html" target="_blank"&gt;http://www.cisco.com/warp/public/471/installboth.html&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Oct 2002 02:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93147#M4700</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2002-10-12T02:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: 3015 needs to authenticate PCs before permiiting access</title>
      <link>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93148#M4701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can, but the CA must be a Certificate server in an AD domain.  The concentrator does an LDAP lookup to AD.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2002 11:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93148#M4701</guid>
      <dc:creator>nick.garigliano</dc:creator>
      <dc:date>2002-10-14T11:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: 3015 needs to authenticate PCs before permiiting access</title>
      <link>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93149#M4702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.  So a standalone Win2000 server running as a CA will not work?  This is pretty helpful as we are also ramping up to AD right now, I will have to make sure this is available prior to my implementation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any documentation on this specific subject? Any links?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2002 19:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93149#M4702</guid>
      <dc:creator>rob.wright</dc:creator>
      <dc:date>2002-10-17T19:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: 3015 needs to authenticate PCs before permiiting access</title>
      <link>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93150#M4703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I remember correctly, it was about a year ago, the concentrator uses LDAP to check the CRL and the only way to get a MS CA to respond to an LDAP lookup is to have the CA on an AD Domain Controller.  You also need to enable LDAP  on your interface filters.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2002 19:24:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3015-needs-to-authenticate-pcs-before-permiiting-access/m-p/93150#M4703</guid>
      <dc:creator>nick.garigliano</dc:creator>
      <dc:date>2002-10-17T19:24:49Z</dc:date>
    </item>
  </channel>
</rss>

