<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN3000 Authentication: Group Delimiter function ?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vpn3000-authentication-group-delimiter-function/m-p/104399#M6423</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;Here is my test result regarding group delimiter:&lt;/P&gt;&lt;P&gt;Settings as follow:&lt;/P&gt;&lt;P&gt;1. Checked "enable group lookup" at System-&amp;gt;General-&amp;gt;Authentication&lt;/P&gt;&lt;P&gt;    Group delimiter "@" selected.&lt;/P&gt;&lt;P&gt;2. Checked "Strip Realm" at Groups-&amp;gt; General setting (group name is testgroup)&lt;/P&gt;&lt;P&gt;3. Set Group-&amp;gt; Ipsec-Authentication to "SDI" so that the user authentication will be done by an external ACE/Server&lt;/P&gt;&lt;P&gt;4. create a user named "testuser" at the ACE/Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At VPN Remote Client, I entered the following at each tests:&lt;/P&gt;&lt;P&gt;Test 1 : &lt;/P&gt;&lt;P&gt;Group : "testgroup" ,  User: "testuser"&lt;/P&gt;&lt;P&gt;Result: No problem on authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 2:&lt;/P&gt;&lt;P&gt;Group: "testgroup" , User: "testuser@testgroup"&lt;/P&gt;&lt;P&gt;Result: No problem on authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 3:&lt;/P&gt;&lt;P&gt;Group: "testgroup" , User: "testuser@whatevergroup"&lt;/P&gt;&lt;P&gt;Result: User can not authenticate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;From Test 1 and Test 2 `s result ,  a user that is not using an "@"  and, a user that is using an "@" delimiter will authenticat just fine. How to force a user to use an "@" delimiter , so that a user that is not using "@" delimiter will be rejected  ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate for any help&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:03:27 GMT</pubDate>
    <dc:creator>engel</dc:creator>
    <dc:date>2020-02-21T18:03:27Z</dc:date>
    <item>
      <title>VPN3000 Authentication: Group Delimiter function ??</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn3000-authentication-group-delimiter-function/m-p/104399#M6423</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;Here is my test result regarding group delimiter:&lt;/P&gt;&lt;P&gt;Settings as follow:&lt;/P&gt;&lt;P&gt;1. Checked "enable group lookup" at System-&amp;gt;General-&amp;gt;Authentication&lt;/P&gt;&lt;P&gt;    Group delimiter "@" selected.&lt;/P&gt;&lt;P&gt;2. Checked "Strip Realm" at Groups-&amp;gt; General setting (group name is testgroup)&lt;/P&gt;&lt;P&gt;3. Set Group-&amp;gt; Ipsec-Authentication to "SDI" so that the user authentication will be done by an external ACE/Server&lt;/P&gt;&lt;P&gt;4. create a user named "testuser" at the ACE/Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At VPN Remote Client, I entered the following at each tests:&lt;/P&gt;&lt;P&gt;Test 1 : &lt;/P&gt;&lt;P&gt;Group : "testgroup" ,  User: "testuser"&lt;/P&gt;&lt;P&gt;Result: No problem on authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 2:&lt;/P&gt;&lt;P&gt;Group: "testgroup" , User: "testuser@testgroup"&lt;/P&gt;&lt;P&gt;Result: No problem on authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 3:&lt;/P&gt;&lt;P&gt;Group: "testgroup" , User: "testuser@whatevergroup"&lt;/P&gt;&lt;P&gt;Result: User can not authenticate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;From Test 1 and Test 2 `s result ,  a user that is not using an "@"  and, a user that is using an "@" delimiter will authenticat just fine. How to force a user to use an "@" delimiter , so that a user that is not using "@" delimiter will be rejected  ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate for any help&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn3000-authentication-group-delimiter-function/m-p/104399#M6423</guid>
      <dc:creator>engel</dc:creator>
      <dc:date>2020-02-21T18:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: VPN3000 Authentication: Group Delimiter function ??</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn3000-authentication-group-delimiter-function/m-p/104400#M6424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the following link &lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/3_5/config/usermgt.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/3_5/config/usermgt.htm&lt;/A&gt; it shows the "Strip Realm" as being needed if the server is unable to parse delimeters. So you might want to try it without the Strip Realm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2002 13:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn3000-authentication-group-delimiter-function/m-p/104400#M6424</guid>
      <dc:creator>r-simpson</dc:creator>
      <dc:date>2002-09-17T13:11:29Z</dc:date>
    </item>
  </channel>
</rss>

