<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help with config. authentication probs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/help-with-config-authentication-probs/m-p/98372#M7239</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lee,&lt;/P&gt;&lt;P&gt;Try this&lt;/P&gt;&lt;P&gt;1. under crypto map vpn 10 ipsec-isakmp &lt;/P&gt;&lt;P&gt;match address 101 should refer to your LAN addresses  and not your Public IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. take off NAT if your not having web access as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Your inbound ACL on dialer0 should allow esp, ahp and isakmp from the far end address to the near-end dialer int address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue the commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto isakmp&lt;/P&gt;&lt;P&gt;debug crypto ipsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;give it a go and then issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh crypto engine connections active:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ali&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 May 2002 12:06:58 GMT</pubDate>
    <dc:creator>ali-franks</dc:creator>
    <dc:date>2002-05-23T12:06:58Z</dc:date>
    <item>
      <title>help with config. authentication probs</title>
      <link>https://community.cisco.com/t5/network-access-control/help-with-config-authentication-probs/m-p/98371#M7238</link>
      <description>&lt;P&gt;hi everyone. &lt;/P&gt;&lt;P&gt;im doing a cisco 1720  site to site vpn using 3 des&lt;/P&gt;&lt;P&gt;i am unable to get to pipex site and am being blocked for some reason.&lt;/P&gt;&lt;P&gt;within the config you will see three usernames&lt;/P&gt;&lt;P&gt;the pipex is the one id like to connect to. the other two are made up based upon the authentication problems im receiving. i tried to put a user in to try and get through.&lt;/P&gt;&lt;P&gt;in the interface dialer0 i put no ip access-group 150 in and then seemed to get challenge and response (part 3) but no success although this is not the id i wish to use. i run a dsl modem at home and have tried to connect from site using this and the pipex log in details and had no problems getting authenticated and int access.&lt;/P&gt;&lt;P&gt;please help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;00:51:33: Vi1 CHAP: Unable to authenticate for peer&lt;/P&gt;&lt;P&gt;00:51:37: Vi1 CHAP: O CHALLENGE id 3 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;00:51:37: Vi1 CHAP: I CHALLENGE id 119 len 39 from "sms1.dsl.pipex.net"&lt;/P&gt;&lt;P&gt;00:51:37: Vi1 CHAP: Username sms1.dsl.pipex.net not found&lt;/P&gt;&lt;P&gt;00:51:37: Vi1 CHAP: Unable to authenticate for peer&lt;/P&gt;&lt;P&gt;00:51:41: Vi1 CHAP: O CHALLENGE id 4 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;00:51:41: Vi1 CHAP: I CHALLENGE id 120 len 39 from "sms1.dsl.pipex.net"&lt;/P&gt;&lt;P&gt;00:51:41: Vi1 CHAP: Username sms1.dsl.pipex.net not found&lt;/P&gt;&lt;P&gt;00:51:41: Vi1 CHAP: Unable to authenticate for peer&lt;/P&gt;&lt;P&gt;00:51:45: Vi1 CHAP: O CHALLENGE id 5 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;00:51:45: Vi1 CHAP: I CHALLENGE id 121 len 39 from "sms1.dsl.pipex.net"&lt;/P&gt;&lt;P&gt;00:51:45: Vi1 CHAP: Username sms1.dsl.pipex.net not found&lt;/P&gt;&lt;P&gt;00:51:45: Vi1 CHAP: Unable to authenticate for peer&lt;/P&gt;&lt;P&gt;00:51:49: Vi1 CHAP: O CHALLENGE id 6 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;00:51:49: Vi1 CHAP: I CHALLENGE id 122 len 39 from "sms1.dsl.pipex.net"&lt;/P&gt;&lt;P&gt;00:51:49: Vi1 CHAP: Username sms1.dsl.pipex.net not found&lt;/P&gt;&lt;P&gt;00:51:49: Vi1 CHAP: Unable to authenticate for peer&lt;/P&gt;&lt;P&gt;00:51:53: Vi1 CHAP: O CHALLENGE id 7 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;00:51:53: Vi1 CHAP: I CHALLENGE id 123 len 39 from "sms1.dsl.pipex.net"&lt;/P&gt;&lt;P&gt;00:51:53: Vi1 CHAP: Username sms1.dsl.pipex.net not found&lt;/P&gt;&lt;P&gt;00:51:53: Vi1 CHAP: Unable to authenticate for peer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 2576 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.1&lt;/P&gt;&lt;P&gt;no service single-slot-reload-enable&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname hertford&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging rate-limit console 10 except errors&lt;/P&gt;&lt;P&gt;enable secret 5 $1$d6OJ$JU.yzY/g6lGebq0i.gD5H0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username ******@xtreme.pipex.net password 7 0200014F020F172456&lt;/P&gt;&lt;P&gt;username sms1.dsl.pipex.net password 7 0115031052021E0A3B&lt;/P&gt;&lt;P&gt;username RASB4NRP3.Ealing password 7 07092458470001000D&lt;/P&gt;&lt;P&gt;memory-size iomem 25&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip finger&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.2&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.1&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.254&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.3&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.4&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.5&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.6&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.7&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.8&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.9&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool hertford&lt;/P&gt;&lt;P&gt;   network 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;   dns-server 158.43.240.4 158.43.240.3&lt;/P&gt;&lt;P&gt;   default-router 192.168.1.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip dhcp-client network-discovery&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt;crypto isakmp key ********** address 52.168.35.118&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set strong esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map vpn 10 ipsec-isakmp&lt;/P&gt;&lt;P&gt; set peer 52.168.35.118&lt;/P&gt;&lt;P&gt; set transform-set strong&lt;/P&gt;&lt;P&gt; match address 101&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface ATM0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; atm vc-per-vp 256&lt;/P&gt;&lt;P&gt; no atm ilmi-keepalive&lt;/P&gt;&lt;P&gt; pvc 0/38&lt;/P&gt;&lt;P&gt;  encapsulation aal5mux ppp dialer&lt;/P&gt;&lt;P&gt;  dialer pool-member 1&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; dsl operating-mode auto&lt;/P&gt;&lt;P&gt; no fair-queue&lt;/P&gt;&lt;P&gt; crypto map vpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; ip address 192.168.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dialer0&lt;/P&gt;&lt;P&gt; ip address 52.168.35.126 255.255.255.248&lt;/P&gt;&lt;P&gt; ip access-group 150 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; dialer pool 1&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt; ppp authentication chap&lt;/P&gt;&lt;P&gt; crypto map vpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat pool vpn 52.168.35.121 52.168.35.121 prefix-length 29&lt;/P&gt;&lt;P&gt;ip nat inside source list 10 pool vpn overload&lt;/P&gt;&lt;P&gt;ip nat inside source static 192.168.1.2 52.168.35.122&lt;/P&gt;&lt;P&gt;ip nat outside source static 52.168.35.122 192.168.1.2&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer0&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 10 deny   192.168.1.2&lt;/P&gt;&lt;P&gt;access-list 10 permit 192.168.1.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host 52.168.35.122 host 52.168.35.113&lt;/P&gt;&lt;P&gt;access-list 150 permit ip 52.168.35.112 0.0.0.7 52.168.35.120 0.0.0.7&lt;/P&gt;&lt;P&gt;access-list 150 permit tcp any any established&lt;/P&gt;&lt;P&gt;no cdp run&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; password 7 045219561E34495A01&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt; transport input none&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt; password 7 020F160B1A130A3544&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Part: 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;05:53:40: Vi1 CHAP: O CHALLENGE id 45 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;05:53:40: Vi1 CHAP: I CHALLENGE id 150 len 37 from "RASB4NRP3.Ealing"&lt;/P&gt;&lt;P&gt;05:53:40: Vi1 CHAP: O RESPONSE id 150 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;05:53:42: Vi1 CHAP: O CHALLENGE id 46 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;05:53:42: Vi1 CHAP: I CHALLENGE id 151 len 37 from "RASB4NRP3.Ealing"&lt;/P&gt;&lt;P&gt;05:53:42: Vi1 CHAP: O RESPONSE id 151 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;05:53:44: Vi1 CHAP: O CHALLENGE id 47 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;05:53:44: Vi1 CHAP: I CHALLENGE id 152 len 37 from "RASB4NRP3.Ealing"&lt;/P&gt;&lt;P&gt;05:53:44: Vi1 CHAP: O RESPONSE id 152 len 29 from "hertford"no debug&lt;/P&gt;&lt;P&gt;05:53:46: Vi1 CHAP: O CHALLENGE id 48 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;05:53:46: Vi1 CHAP: I CHALLENGE id 153 len 37 from "RASB4NRP3.Ealing"&lt;/P&gt;&lt;P&gt;05:53:46: Vi1 CHAP: O RESPONSE id 153 len 29 from "hertford"all&lt;/P&gt;&lt;P&gt;All possible debugging has been turned off&lt;/P&gt;&lt;P&gt;hertford#&lt;/P&gt;&lt;P&gt;05:53:48: Vi1 CHAP: O CHALLENGE id 49 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;05:53:48: Vi1 CHAP: I CHALLENGE id 154 len 37 from "RASB4NRP3.Ealing"&lt;/P&gt;&lt;P&gt;05:53:48: Vi1 CHAP: O RESPONSE id 154 len 29 from "hertford"&lt;/P&gt;&lt;P&gt;hertford#ping 80.193.223.56&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 80.193.223.56, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;hertford#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:00:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-with-config-authentication-probs/m-p/98371#M7238</guid>
      <dc:creator>lee</dc:creator>
      <dc:date>2020-02-21T18:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: help with config. authentication probs</title>
      <link>https://community.cisco.com/t5/network-access-control/help-with-config-authentication-probs/m-p/98372#M7239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lee,&lt;/P&gt;&lt;P&gt;Try this&lt;/P&gt;&lt;P&gt;1. under crypto map vpn 10 ipsec-isakmp &lt;/P&gt;&lt;P&gt;match address 101 should refer to your LAN addresses  and not your Public IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. take off NAT if your not having web access as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Your inbound ACL on dialer0 should allow esp, ahp and isakmp from the far end address to the near-end dialer int address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue the commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto isakmp&lt;/P&gt;&lt;P&gt;debug crypto ipsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;give it a go and then issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh crypto engine connections active:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ali&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2002 12:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-with-config-authentication-probs/m-p/98372#M7239</guid>
      <dc:creator>ali-franks</dc:creator>
      <dc:date>2002-05-23T12:06:58Z</dc:date>
    </item>
  </channel>
</rss>

