<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect syslog AAA user authentication rejected in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5107216#M1112719</link>
    <description>&lt;P&gt;For this point&amp;nbsp; did you check it?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2024 09:17:29 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-05-17T09:17:29Z</dc:date>
    <item>
      <title>AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093062#M1112185</link>
      <description>&lt;P&gt;I have some locally managed FTDs. I'm parsing syslog data for VPN auth failures. The FDM FlexConfig won't allow some of the simplest changes like "no logging hide username" (bug). Anyway, most the AAA user authentication errors indicate reason = Unspecified and the username is "*****".&amp;nbsp; But there are some log entries that report the actual username and reason = Invalid password. I checked AD, it appears that the usernames displayed are actual accts in AD. I can't tell about the others as I am unable to display the actual username that was attempted. I'm wondering why the difference in the syslog messages. I'm unable to find what "Unspecified error" means. Was that caused by AnyConnect or someone failing auth through the web client? Or maybe those accts don't actually exist in AD so it lists "*****' and generates the Unspecified error?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;David&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 19:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093062#M1112185</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-05-07T19:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093690#M1112199</link>
      <description>&lt;P&gt;This is by design. From the feature description:&lt;/P&gt;&lt;P class=""&gt;&lt;EM&gt;You can now show invalid usernames in syslog messages for unsuccessful login attempts. The default setting is to hide usernames &lt;STRONG&gt;when the username is invalid&lt;/STRONG&gt; or if the validity is unknown. If a user accidentally types a password instead of a username, for example, then it is more secure to hide the “username” in the resultant syslog message. You might want to show invalid usernames to help with troubleshooting login issues.&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;EM&gt;We introduced the following command: &lt;SPAN class=""&gt;no logging hide username&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;So, if you see ****, the user doesn't exist, and if you see the username and the reason is "Invalid password", the user exists, but password is incorrect. The reason is shown as "Unspecified error" just to hide further details.&lt;/P&gt;&lt;P class=""&gt;Also described here:&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslog-messages-101001-to-199021.html#con_8293726" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslog-messages-101001-to-199021.html#con_8293726&lt;/A&gt;&lt;/P&gt;&lt;H3&gt;113005&lt;/H3&gt;&lt;P class=""&gt;&lt;STRONG&gt;Error Message&lt;/STRONG&gt; %&lt;SPAN class=""&gt;ASA&lt;/SPAN&gt;-6-113005: AAA user authentication Rejected: reason = AAA failure: server = &lt;EM&gt;ip_addr&lt;/EM&gt; : user = *****: user IP = &lt;EM&gt;ip_addr&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Explanation&lt;/STRONG&gt; The AAA authentication on a connection has failed. The username is hidden when invalid or unknown, but appears when valid or the &lt;SPAN class=""&gt;no logging hide username&lt;/SPAN&gt; command has been configured.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 07:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093690#M1112199</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-08T07:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093703#M1112200</link>
      <description>&lt;P&gt;Check above&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093703#M1112200</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T13:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093713#M1112201</link>
      <description>&lt;P&gt;Believe you or not, this is how it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 07:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5093713#M1112201</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-08T07:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094177#M1112227</link>
      <description>&lt;P&gt;You can't configure "no logging hide username" using flexconfig on a locally managed FTD device. It incorrectly throws a syntax error upon validation. At most it should throw a warning and let you proceed. I also am standing up FMC managed firewalls at another location and this was not an issue. Flexconfig seems mostly broken in FDM. This makes handling security incidents much more problematic. We are working on bringing all of our firewalls into FMC but that will take time. Meanwhile I'm left partially blinded on these FDM managed devices.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:00:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094177#M1112227</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-05-08T13:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094202#M1112228</link>
      <description>&lt;P&gt;I remember somebody reported that he managed to get FlexConfig working by configuring &lt;SPAN class=""&gt;"no loggin hide username" (logging without the last G)&lt;/SPAN&gt;. Don't believe this is true, although there is bug which tells the same:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;CSCvj02826&lt;/SPAN&gt; &lt;SPAN class=""&gt;Need a way to negate "logging hide username" in FTD&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:17:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094202#M1112228</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-08T13:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094208#M1112230</link>
      <description>&lt;P&gt;Ahh, I just realized you confirmed my suspicions.If the username is invalid, it is all *.&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094208#M1112230</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-05-08T13:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094220#M1112232</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/error-authentication-rejected-unspecified/td-p/3887948" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/error-authentication-rejected-unspecified/td-p/3887948&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check this post&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5094220#M1112232</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T13:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5105146#M1112461</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt;This actually worked. I ran this up in CDO with our test FTD VPN and flex config took the command &lt;SPAN class=""&gt;"no loggin hide username"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 16:52:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5105146#M1112461</guid>
      <dc:creator>othydojo</dc:creator>
      <dc:date>2024-05-15T16:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5106427#M1112664</link>
      <description>&lt;P&gt;I started seeing entries in our syslog like the following:&lt;/P&gt;&lt;P&gt;AAA user authentication Rejected : reason = User was not found : local database&lt;/P&gt;&lt;P&gt;What sort of VPN auth attempt tries against the local database? We don't have fallback to local database enabled.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 19:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5106427#M1112664</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-05-16T19:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5107051#M1112708</link>
      <description>&lt;P&gt;There are two possibilities.&lt;/P&gt;&lt;P&gt;1. You have not patched FTD and it is vulnerable to &lt;A href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC" target="_blank" rel="noopener"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;CSCwh23100 Cisco ASA and FTD Software Remote Access VPN Unauthorized Access Vulnerability&lt;BR /&gt;CSCwh45108 Cisco ASA and FTD Software Remote Access VPN Unauthorized Access Vulnerability&lt;/P&gt;&lt;P&gt;In this case you need to update it.&lt;/P&gt;&lt;P&gt;2. You're running fixed version, but didn't implement hardening measures. In this case connection attempts may hit DefaultWEBVPNGroup connection profile, that is why you see such messages. Refer to the following doc:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-client/221880-implement-hardening-measures-for-secure.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-client/221880-implement-hardening-measures-for-secure.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Read the following discussion too:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-security/cisco-asa-anyconnect-ddos-protection/m-p/5050819/highlight/true#M1110394" target="_blank"&gt;https://community.cisco.com/t5/network-security/cisco-asa-anyconnect-ddos-protection/m-p/5050819/highlight/true#M1110394&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 08:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5107051#M1112708</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-17T08:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5107213#M1112718</link>
      <description>&lt;P&gt;Some User that is try to access using any password username direct to use defualt Group policy' since realm is not match.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need no-access policy for these user&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/216313-configure-ra-vpn-using-ldap-authenticati.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/216313-configure-ra-vpn-using-ldap-authenticati.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 09:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5107213#M1112718</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-17T09:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect syslog AAA user authentication rejected</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5107216#M1112719</link>
      <description>&lt;P&gt;For this point&amp;nbsp; did you check it?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 09:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-syslog-aaa-user-authentication-rejected/m-p/5107216#M1112719</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-17T09:17:29Z</dc:date>
    </item>
  </channel>
</rss>

