<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN 3000 user authentication with Internal Database and Active Directory in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vpn-3000-user-authentication-with-internal-database-and-active/m-p/647739#M5663</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question about how to configure the VPN 3000 to work user authentication by using &lt;/P&gt;&lt;P&gt;Kerberos/Active Directory and Internal Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why I ask you that question is that I have a following problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured user authentication by using Internal Database for Group A for example.&lt;/P&gt;&lt;P&gt;Users of Group A have authenticated and communicated successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today I have configured user authentication by using Kerberos/Active Directory for Group B.&lt;/P&gt;&lt;P&gt;But at that time, Users of Group A could NOT authenticate and communicate.&lt;/P&gt;&lt;P&gt;(it seems VPN 3000 did not request user authentication to Internal Database)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To isolate the problem, I have deleted setting of Kerberos/Active Directory &lt;/P&gt;&lt;P&gt;"Configuration | System | Servers | Authentication and Delete" so that&lt;/P&gt;&lt;P&gt;Users of Group A can be authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have a question about how to configure to use both Internal Database and Kerberos/Active Directory &lt;/P&gt;&lt;P&gt;for user authentication for each Group, One Group uses Internal Database and another Group uses&lt;/P&gt;&lt;P&gt;Kerberos/Active Directory .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your information would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:17:22 GMT</pubDate>
    <dc:creator>snakayama</dc:creator>
    <dc:date>2020-02-21T18:17:22Z</dc:date>
    <item>
      <title>VPN 3000 user authentication with Internal Database and Active Directory</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-3000-user-authentication-with-internal-database-and-active/m-p/647739#M5663</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question about how to configure the VPN 3000 to work user authentication by using &lt;/P&gt;&lt;P&gt;Kerberos/Active Directory and Internal Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why I ask you that question is that I have a following problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured user authentication by using Internal Database for Group A for example.&lt;/P&gt;&lt;P&gt;Users of Group A have authenticated and communicated successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today I have configured user authentication by using Kerberos/Active Directory for Group B.&lt;/P&gt;&lt;P&gt;But at that time, Users of Group A could NOT authenticate and communicate.&lt;/P&gt;&lt;P&gt;(it seems VPN 3000 did not request user authentication to Internal Database)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To isolate the problem, I have deleted setting of Kerberos/Active Directory &lt;/P&gt;&lt;P&gt;"Configuration | System | Servers | Authentication and Delete" so that&lt;/P&gt;&lt;P&gt;Users of Group A can be authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have a question about how to configure to use both Internal Database and Kerberos/Active Directory &lt;/P&gt;&lt;P&gt;for user authentication for each Group, One Group uses Internal Database and another Group uses&lt;/P&gt;&lt;P&gt;Kerberos/Active Directory .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your information would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:17:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-3000-user-authentication-with-internal-database-and-active/m-p/647739#M5663</guid>
      <dc:creator>snakayama</dc:creator>
      <dc:date>2020-02-21T18:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN 3000 user authentication with Internal Database and Acti</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-3000-user-authentication-with-internal-database-and-active/m-p/647740#M5664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kerberos is a client-server based secret-key network authentication method that uses a trusted Kerberos server to verify secure access to both services and users. In Kerberos, this trusted server is called the key distribution center (KDC). The KDC issues tickets to validate users and services. A ticket is a temporary set of electronic credentials that verify the identity of a client for a particular service.&lt;/P&gt;&lt;P&gt;These tickets have a limited life span and can be used in place of the standard user password authentication mechanism if a service trusts the Kerberos server from which the ticket was issued. If the standard user password method is used, Kerberos encrypts user passwords into the tickets, ensuring that passwords are not sent on the network in clear text. When you use Kerberos, passwords are not stored on any machine, except for the Kerberos server, for more than a few seconds. Kerberos also guards against intruders who might pick up the encrypted tickets from the network.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps679/products_configuration_guide_chapter09186a008007ef3d.html#xtocid153536" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps679/products_configuration_guide_chapter09186a008007ef3d.html#xtocid153536&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jan 2007 16:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-3000-user-authentication-with-internal-database-and-active/m-p/647740#M5664</guid>
      <dc:creator>irisrios</dc:creator>
      <dc:date>2007-01-01T16:46:23Z</dc:date>
    </item>
  </channel>
</rss>

