<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix TACACS+/Radius client authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127646#M6197</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oleg,&lt;/P&gt;&lt;P&gt;Thanks for the response.  We're using CS ACS 2.4 and I was trying it with TACACS.  I guess I'll have to wait until we upgrade our ACS to a new version before using any authentication beyond local!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim C&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 May 2003 14:22:27 GMT</pubDate>
    <dc:creator>OVHD IS Dept.</dc:creator>
    <dc:date>2003-05-13T14:22:27Z</dc:date>
    <item>
      <title>Pix TACACS+/Radius client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127643#M6194</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm in the process of setting up our Pix 515E (ver 6.1(4)) to act as a VPN endpoint for remote users (mainly Windows OS clients).  I wanted to eliminate the need to download the Cisco VPN client software (using Windows built-in VPN capabilities).  So far I've successfully setup the Pix to work with Win2k / XP (the client OSs we're dealing with) using local client authentication, but haven't been able to get the Pix to authenticate with our Cisco ACS server (NT, ver 2.4).  I know it's an old version, but I'd think it would be able to accomplish the simple task of verifying the entered username/password.  We're using the ACS for permissions and monitoring/logging on our routers, etc. for this purpose.  When I enter the client authentication mode for the vpdn group like so:&lt;/P&gt;&lt;P&gt;    vpdn group 1 client authentication aaa OVHDauth&lt;/P&gt;&lt;P&gt;I get the following error: "Error 781: The encryption attempt failed because no valid certificate was found."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I use radius (cisco or the ietf mode) I get "Error 742: The remote computer does not support the required data encryption type."  Doesn't the pix just pass the user's credentials to the radius server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127643#M6194</guid>
      <dc:creator>OVHD IS Dept.</dc:creator>
      <dc:date>2020-02-21T18:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Pix TACACS+/Radius client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127644#M6195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on tunnel type. For example, PPTP encryption (MPPE) works&lt;/P&gt;&lt;P&gt;with LOCAL or RADIUS only and MS-CHAP and CS ACS 3.0 or later&lt;/P&gt;&lt;P&gt;is required. If you use PPTP try to disable encryption on the client first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oleg Tipisov,&lt;/P&gt;&lt;P&gt;REDCENTER,&lt;/P&gt;&lt;P&gt;Moscow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2003 05:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127644#M6195</guid>
      <dc:creator>ovt</dc:creator>
      <dc:date>2003-05-06T05:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pix TACACS+/Radius client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127645#M6196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are trying to do IPSec over L2TP with the Microsoft client then you need a digital certificate for the client.  There is a reg hack you can use to disable IPSec encryption and get the MS client to work, but then you are only tunneling the packets so what's the point.  The Cisco VPN client will let you use a static  key (not the ideal solution).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to use the MS client and not do the dig cert thing then I'm pretty sure you'll have to go with PPTP.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2003 12:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127645#M6196</guid>
      <dc:creator>nick.garigliano</dc:creator>
      <dc:date>2003-05-06T12:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pix TACACS+/Radius client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127646#M6197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oleg,&lt;/P&gt;&lt;P&gt;Thanks for the response.  We're using CS ACS 2.4 and I was trying it with TACACS.  I guess I'll have to wait until we upgrade our ACS to a new version before using any authentication beyond local!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim C&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2003 14:22:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-tacacs-radius-client-authentication/m-p/127646#M6197</guid>
      <dc:creator>OVHD IS Dept.</dc:creator>
      <dc:date>2003-05-13T14:22:27Z</dc:date>
    </item>
  </channel>
</rss>

