<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: X-Auth on Per-Group Basis in PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133403#M638427</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Naman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me see we can answer you second issue, that will take care of the first one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create separate method for the console port so that you are not asked for the username/password in it, it will ask you only the vty /telnet password .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authen login conmethod line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;login authentication conmethod&lt;/P&gt;&lt;P&gt;password  &lt;PASSWROD&gt;&lt;/PASSWROD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sujit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jun 2003 03:56:39 GMT</pubDate>
    <dc:creator>sghosh</dc:creator>
    <dc:date>2003-06-06T03:56:39Z</dc:date>
    <item>
      <title>X-Auth on Per-Group Basis in PIX</title>
      <link>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133402#M638426</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is it possible disable X-Auth for a particular Group, when it has been enabled globaly using the command "crypto map vpnmap client authentication internal-radius" for all Other groups ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to have an IOS Router connected to the PIX using EzVPN Client, however with X-Auth enabled (which is enabled to take care of other groups with Software VPN Clients), the user will have to enter the username\password at the Router Console, which is not desired.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards \\ Naman&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:47:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133402#M638426</guid>
      <dc:creator>mnlatif</dc:creator>
      <dc:date>2020-02-21T06:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: X-Auth on Per-Group Basis in PIX</title>
      <link>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133403#M638427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Naman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me see we can answer you second issue, that will take care of the first one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create separate method for the console port so that you are not asked for the username/password in it, it will ask you only the vty /telnet password .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authen login conmethod line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;login authentication conmethod&lt;/P&gt;&lt;P&gt;password  &lt;PASSWROD&gt;&lt;/PASSWROD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sujit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2003 03:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133403#M638427</guid>
      <dc:creator>sghosh</dc:creator>
      <dc:date>2003-06-06T03:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: X-Auth on Per-Group Basis in PIX</title>
      <link>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133404#M638428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to configure exception for this.  Here is the link that will help in configurin g this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800eb72d.html#29251" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800eb72d.html#29251&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2003 05:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133404#M638428</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-06T05:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: X-Auth on Per-Group Basis in PIX</title>
      <link>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133405#M638429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mynul,&lt;/P&gt;&lt;P&gt;Well. This applies to the Site-Site VPN, which we have already configured this way. My question was for VPN Groups.&lt;/P&gt;&lt;P&gt;E.g. Lets say there are two VPN Groups with "Clients" and "EzVPN", X-Auth is enabled globally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now PC Clients using (Cisco VPN Software) connect to Group "Clients" and are propmpted for their Username\Password, which is fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However the Cisco IOS Routers connects to Group EzVPN, and has to go through X-Auth, which means that at the Cisco Router Console "a User" will have to type "crypto ipsec client ezvpn xauth" and then Enter Username\Passwd.  This is What i Want to Avoid ?&lt;/P&gt;&lt;P&gt;If i can make an exception that though X-Auth is enabled globaly but Shouldn't be required for "EzVPN" group, Is it possible ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards \\ Naman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2003 16:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/x-auth-on-per-group-basis-in-pix/m-p/133405#M638429</guid>
      <dc:creator>mnlatif</dc:creator>
      <dc:date>2003-06-06T16:24:20Z</dc:date>
    </item>
  </channel>
</rss>

