<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Max number of local AAA users on PIX 7.2? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797256#M1008114</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sounds like the customer wants an administrative nightmare (:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set up AAA/radius authentication for vpn users using microsoft's free IAS (internet authentication server).  This way, remote users can use their domain login information to do xauth w/ the vpn client, and when they leave the  company, removing/disabling their AD account, disables their vpn access.  I've set this up successfully on both the vpn concentrator and PIX 6.3/7.x if you're interested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Apr 2007 16:40:52 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2007-04-05T16:40:52Z</dc:date>
    <item>
      <title>Max number of local AAA users on PIX 7.2?</title>
      <link>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797254#M1008111</link>
      <description>&lt;P&gt;I know that this is a bad idea, but I have a customer that wants upwards of 200+ users put in the config of his PIX for use with VPN.  What the customer wants, the customer gets... Unless, is that even possible?  I can't find anything to tell me the max number of local users you can have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know what the max number of local users is for a PIX 515e running 7.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797254#M1008111</guid>
      <dc:creator>NotMeHere</dc:creator>
      <dc:date>2019-03-11T09:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Max number of local AAA users on PIX 7.2?</title>
      <link>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797255#M1008113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no software imposed limit on the number of users in the local database.  So, in essence you are limited by the config size (and available space on flash to store the config).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, we have not tested performance with very large local user databases.  However, 200 users should be just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 14:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797255#M1008113</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-04-05T14:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Max number of local AAA users on PIX 7.2?</title>
      <link>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797256#M1008114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sounds like the customer wants an administrative nightmare (:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set up AAA/radius authentication for vpn users using microsoft's free IAS (internet authentication server).  This way, remote users can use their domain login information to do xauth w/ the vpn client, and when they leave the  company, removing/disabling their AD account, disables their vpn access.  I've set this up successfully on both the vpn concentrator and PIX 6.3/7.x if you're interested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 16:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797256#M1008114</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-04-05T16:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Max number of local AAA users on PIX 7.2?</title>
      <link>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797257#M1008116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure they want to tie it into AD is the problem.  However, I would like to see an example config if you wouldn't mind sharing it.  My email is phignutt @ hotmail dot com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 17:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797257#M1008116</guid>
      <dc:creator>NotMeHere</dc:creator>
      <dc:date>2007-04-05T17:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Max number of local AAA users on PIX 7.2?</title>
      <link>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797258#M1008117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the PIX 7.2 configuration (relevant portion only).  To configure IAS, google something like "IAS radius cisco".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the dollar sign ($) indicates variable names/fields (user defined names)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list $splittunnel_acl extended permit ip $local_network $vpn_dhcp_network&lt;/P&gt;&lt;P&gt;ip local pool vpn-pool $start_ip-$end_ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server RADIUSVPN protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUSVPN host $192.168.x.y&lt;/P&gt;&lt;P&gt; timeout 5    &lt;/P&gt;&lt;P&gt; key $shared_radius_key  &lt;/P&gt;&lt;P&gt;aaa-server RADIUSVPN host $192.168.x.z   (backup IAS server)&lt;/P&gt;&lt;P&gt; timeout 5    &lt;/P&gt;&lt;P&gt; key $shared_radius_key&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;group-policy $group_name internal&lt;/P&gt;&lt;P&gt;group-policy $group_name attributes&lt;/P&gt;&lt;P&gt; wins-server value $192.168.x.x&lt;/P&gt;&lt;P&gt; dns-server value $192.168.x.x $192.168.x.y&lt;/P&gt;&lt;P&gt; vpn-idle-timeout 1440&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value $splittunnel_acl&lt;/P&gt;&lt;P&gt; default-domain value $local_domain&lt;/P&gt;&lt;P&gt; backup-servers $backup_vpn_server&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set $transform_name esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map $DYN_MAPNAME 10 set transform-set $transform_name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map VPN 25 ipsec-isakmp dynamic $DYN_MAPNAME&lt;/P&gt;&lt;P&gt;crypto map VPN interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha     &lt;/P&gt;&lt;P&gt; group 2      &lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup general-attributes&lt;/P&gt;&lt;P&gt; authentication-server-group (outside) RADIUS&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;tunnel-group $group_name type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group $group_name general-attributes&lt;/P&gt;&lt;P&gt; address-pool vpn-pool&lt;/P&gt;&lt;P&gt; authentication-server-group RADIUSVPN&lt;/P&gt;&lt;P&gt; default-group-policy $group_name&lt;/P&gt;&lt;P&gt;tunnel-group $group_name ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key $psk&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;if you have regular crypto tunnels defined, place the dynamic map entry after those, otherwise strange things happen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Apr 2007 15:06:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/max-number-of-local-aaa-users-on-pix-7-2/m-p/797258#M1008117</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-04-07T15:06:37Z</dc:date>
    </item>
  </channel>
</rss>

