<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Authentication problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536823#M5690</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this help....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Aug 2006 15:43:09 GMT</pubDate>
    <dc:creator>jmia</dc:creator>
    <dc:date>2006-08-01T15:43:09Z</dc:date>
    <item>
      <title>VPN Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536820#M5681</link>
      <description>&lt;P&gt;I have recently upgraded our PIX OS 7.0(5). We are experiencing issues with remote access VPN clients. Phase 1 authentication occurs OK but the user authentication is failing on some accounts. The PIX authenticates against Active Directory.&lt;/P&gt;&lt;P&gt;The strange thing is that some accounts authenticate ok yet other do not. Looking at the accounts there are no obvious differences, all standard user accounts. If I set up a new account it will also work? From the debug kerberos output the only difference between a successful authentication and one that isn't is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'Kerberos library reports: "unknown"'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody any ideas?&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536820#M5681</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2020-02-21T18:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536821#M5683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One frequent cause of authentication failure is clock skew. Be sure that the clocks on the PIX or ASA and your authentication server are synchronized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also take a look here, using ASDM...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008060f261.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008060f261.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and if it does please rate post!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2006 14:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536821#M5683</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2006-08-01T14:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536822#M5687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, the whole clock skew problem I found during development so its not that I'm afraid. The strange thing is that this was tested against a test domain and worked fine. The other weird thing is that from the same remote client machine we can authenticate using one account but not the others.&lt;/P&gt;&lt;P&gt;I followed the document you listed during development.&lt;/P&gt;&lt;P&gt;Do you know if the PIX can actually authenticate directly against AD? I know I've done this in development but have the feeling I may have fluked something.&lt;/P&gt;&lt;P&gt;I'm a big PIX champion and have been trying to get this in instead of ISA Server. I finally proved that it can work against the domain (something that was required) and now it appears it doesn't work. I'm pretty gutted actually, though it could be a Windows issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2006 15:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536822#M5687</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2006-08-01T15:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536823#M5690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this help....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_example09186a00806de37e.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2006 15:43:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536823#M5690</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2006-08-01T15:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536824#M5693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jay&lt;/P&gt;&lt;P&gt;Had a look at that too. The whole reason for upgrading to PIX 7.0 was to get rid of intermediary authentication servers as the sales blurb states.&lt;/P&gt;&lt;P&gt;I'm sure its a Kerberos authentication problem looking at the debug because successful attempts to authenticate then through up LDAP debug as they go on to be authorised.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 12:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-authentication-problems/m-p/536824#M5693</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2006-08-02T12:41:55Z</dc:date>
    </item>
  </channel>
</rss>

