<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132566#M590121</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;, have you tried downloading the image on your computer? It doesn't look blurry at all to me.&lt;/P&gt;&lt;P&gt;Let me know, otherwise I'll upload it somewhere else.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2024 12:33:18 GMT</pubDate>
    <dc:creator>MarcoLazzarotto</dc:creator>
    <dc:date>2024-06-17T12:33:18Z</dc:date>
    <item>
      <title>Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132467#M590118</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I urgently need help with an access problem on ACS with MSCHAP-V2 protocol. The client is connecting to our ASA in AnyConnect and RADIUS authentication is happening between our ACS and the client's Windows server. That client is pushing hard to switch from &lt;STRONG&gt;PAP_ASCII&lt;/STRONG&gt; to &lt;STRONG&gt;MSCHAP-V2&lt;/STRONG&gt; for security reasons.&lt;/P&gt;&lt;P&gt;The problem is that the authentication fails every time, and I've been banging my head about it for several weeks, to no avail.&lt;BR /&gt;Please check the authentication report from ACS:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="REDACTED_jsimpson_mschap_failed_auth.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221004iF7363773F3D9C9B2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="REDACTED_jsimpson_mschap_failed_auth.png" alt="REDACTED_jsimpson_mschap_failed_auth.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am going&amp;nbsp;to post my configuration below.&amp;nbsp;&lt;BR /&gt;ASA VPN config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;tunnel-group &amp;lt;Customer&amp;gt;RemoteSC type remote-access
tunnel-group &amp;lt;Customer&amp;gt;RemoteSC general-attributes
 authentication-server-group New-rad
 secondary-authentication-server-group DUO-ldaps use-primary-username
 default-group-policy &amp;lt;Customer&amp;gt;-Any
 password-management password-expire-in-days 0
tunnel-group &amp;lt;Customer&amp;gt;RemoteSC webvpn-attributes
 group-url https://bhmvpn.&amp;lt;redacted&amp;gt;.com/030 enable
 without-csd
tunnel-group &amp;lt;Customer&amp;gt;RemoteSC ppp-attributes
 authentication ms-chap-v2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;RADIUS Identity Store on ACS:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MarcoLazzarotto_0-1718616216504.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221005iE20E0FBF831F61AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MarcoLazzarotto_0-1718616216504.png" alt="MarcoLazzarotto_0-1718616216504.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;AAA Diagnostics Report in CSV attached.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 10:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132467#M590118</guid>
      <dc:creator>MarcoLazzarotto</dc:creator>
      <dc:date>2024-06-17T10:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132563#M590119</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Could you post a readable version of the authentication report &lt;U&gt;&lt;STRONG&gt;from ACS&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;(it is too blurred) ,&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 12:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132563#M590119</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-17T12:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132566#M590121</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;, have you tried downloading the image on your computer? It doesn't look blurry at all to me.&lt;/P&gt;&lt;P&gt;Let me know, otherwise I'll upload it somewhere else.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 12:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132566#M590121</guid>
      <dc:creator>MarcoLazzarotto</dc:creator>
      <dc:date>2024-06-17T12:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132568#M590122</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- For me , it's a no go ; even when saved on my computer first ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 12:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132568#M590122</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-17T12:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132569#M590123</link>
      <description>&lt;P&gt;Sorry, I'm reuploading it as file here.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 12:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132569#M590123</guid>
      <dc:creator>MarcoLazzarotto</dc:creator>
      <dc:date>2024-06-17T12:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132573#M590124</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Near the bottom it just says :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;...22063 &lt;U&gt;&lt;FONT color="#FF0000"&gt;Wrong password&lt;/FONT&gt;&lt;/U&gt; ,&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 12:55:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132573#M590124</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-17T12:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132574#M590125</link>
      <description>&lt;P&gt;I know, but the same password works very well when the user connects using PAP_ASCII. The issue here is just when using MSCHAP-V2. And this is not happening with 1 user, but with 2 users.&lt;/P&gt;&lt;P&gt;Strangely, I see packets from the ACS to the Domain controller (port 1812) with PAP_ASCII authentication, but I don't see any with MSCHAP-V2 authentication. It almost seems that it is the ACS itself that is breaking the connection, without first making sure whether the password is right or not.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 13:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132574#M590125</guid>
      <dc:creator>MarcoLazzarotto</dc:creator>
      <dc:date>2024-06-17T13:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132580#M590126</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - Have a look at this document&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/113485-acs5x-tshoot.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/113485-acs5x-tshoot.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; and or search for instanced of&amp;nbsp;&lt;STRONG&gt;MSCHAP&lt;/STRONG&gt; with &lt;STRONG&gt;find&lt;/STRONG&gt; in your browser , look for helpful hints&amp;nbsp; - if any.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Also note that ACS &lt;FONT color="#FF0000"&gt;&lt;EM&gt;is very &lt;STRONG&gt;old&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt; and no longer advisable for production environments ,&lt;FONT color="#008000"&gt;&lt;EM&gt;consider migrating to&lt;STRONG&gt; ISE&lt;/STRONG&gt; ,&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 13:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132580#M590126</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-17T13:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132658#M590130</link>
      <description>&lt;P&gt;I did look that document but I didn't find anything useful.&lt;/P&gt;&lt;P&gt;I can try to disable &lt;STRONG&gt;CHAP&lt;/STRONG&gt; and &lt;STRONG&gt;MS-CHAP-V1&lt;/STRONG&gt;, enabled by default.&lt;BR /&gt;I was comparing a successful (left) with a failed (right) authentication. I don't know if it's of any help.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MarcoLazzarotto_0-1718635548077.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221029i386053DCD8FF11CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MarcoLazzarotto_0-1718635548077.png" alt="MarcoLazzarotto_0-1718635548077.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The messages in the orange square are the same, then the differences begin (the left part didn't stop there, I just cropped it).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 14:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5132658#M590130</guid>
      <dc:creator>MarcoLazzarotto</dc:creator>
      <dc:date>2024-06-17T14:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5134049#M590193</link>
      <description>&lt;P&gt;I disabled MS-CHAP-V1 and CHAP on the tunnel-group but that didn't have any effect.&lt;/P&gt;&lt;P&gt;The weird part is that when using MS-CHAP-V2, the ACS is not communicating at all with the RADIUS server.&lt;/P&gt;&lt;P&gt;I also did a dump of packets when the ACS talks with the ASA, but there's nothing helpful as it appears that the decision to reject the user is done inside the ACS.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 12:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5134049#M590193</guid>
      <dc:creator>MarcoLazzarotto</dc:creator>
      <dc:date>2024-06-20T12:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.6 - RADIUS with MSCHAP-V2 not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5134234#M590201</link>
      <description>&lt;P&gt;Its been a while since I used ACS but I remember running into issues with some client's passwords that contained "special characters".&amp;nbsp; Has the user tried resetting their password to something alphanumeric to test?&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 17:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-6-radius-with-mschap-v2-not-working/m-p/5134234#M590201</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2024-06-20T17:38:05Z</dc:date>
    </item>
  </channel>
</rss>

