<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX not using Radius in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-not-using-radius/m-p/395274#M553697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you trying to authenticate PDM access and/or SSH access via RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your PDM config looks fine to me.   What ports does your RADIUS server listen on, if its not 1645 and 1646 then you need to tell the PIX to use different ports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. "aaa-server radius-authport 1812" and "aaa-server radius-acctport 1813".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i would check that you are using the correct key (7140) on both your PIX and RADIUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are trying to authenticate SSH via RADIUS then your configuration is set to authenticate SSH locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to change this to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console RADIUS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;PD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Dec 2004 20:11:10 GMT</pubDate>
    <dc:creator>paddyxdoyle</dc:creator>
    <dc:date>2004-12-17T20:11:10Z</dc:date>
    <item>
      <title>PIX not using Radius</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-using-radius/m-p/395273#M553695</link>
      <description>&lt;P&gt;I have configured my PIX to use our radius server for authentication, but it still only uses the local access  for authentication.  Can some one have a look at my config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pdm location 10.254.254.5 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;route inside 10.254.254.5 255.255.255.0 10.1.1.102 1&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3 &lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10 &lt;/P&gt;&lt;P&gt;aaa-server RADIUS (inside) host 10.254.254.5 7140 timeout 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;aaa authentication http console RADIUS&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:48:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-using-radius/m-p/395273#M553695</guid>
      <dc:creator>vanagon2tdi</dc:creator>
      <dc:date>2020-02-21T07:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not using Radius</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-using-radius/m-p/395274#M553697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you trying to authenticate PDM access and/or SSH access via RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your PDM config looks fine to me.   What ports does your RADIUS server listen on, if its not 1645 and 1646 then you need to tell the PIX to use different ports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. "aaa-server radius-authport 1812" and "aaa-server radius-acctport 1813".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i would check that you are using the correct key (7140) on both your PIX and RADIUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are trying to authenticate SSH via RADIUS then your configuration is set to authenticate SSH locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to change this to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console RADIUS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;PD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2004 20:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-using-radius/m-p/395274#M553697</guid>
      <dc:creator>paddyxdoyle</dc:creator>
      <dc:date>2004-12-17T20:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not using Radius</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-using-radius/m-p/395275#M553700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you also need a "aaa new-server" command at the top.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Dec 2004 04:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-using-radius/m-p/395275#M553700</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2004-12-18T04:13:13Z</dc:date>
    </item>
  </channel>
</rss>

