<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX VPN client user authentication in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281726#M838833</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 506E with 6.3(5) and wanted to know if I can configure VPN client with group and user authentications. I know I can configure just group authentication so users dont have to use the password everytime they try to connect. However I am also looking for second level of user authentication so I dont have to change the group password everytime a user leave the organization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured this on a PIX and ASA units with newer versions but I cannot find the commands for 6.3(5) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see commands below related to this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; vpngroup &amp;lt;group_name&amp;gt; secure-unit-authentication&lt;/P&gt;&lt;P&gt;        vpngroup &amp;lt;group_name&amp;gt; authentication-server &amp;lt;server_tag&amp;gt;&lt;/P&gt;&lt;P&gt;        vpngroup &amp;lt;group_name&amp;gt; user-authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I configure &lt;/P&gt;&lt;P&gt;vpngroup &amp;lt;group_name&amp;gt; user-authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the message&lt;/P&gt;&lt;P&gt;"Please configure an authentication server before enabling user authentication"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And when I add the below, I cannot configure for LOCAL authentication and accept only TACACS+ and RADIUS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        vpngroup &amp;lt;group_name&amp;gt; authentication-server &amp;lt;server_tag&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am not sure if I can configure second level user authentication on this version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:58:06 GMT</pubDate>
    <dc:creator>techtips03</dc:creator>
    <dc:date>2019-03-11T15:58:06Z</dc:date>
    <item>
      <title>PIX VPN client user authentication</title>
      <link>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281726#M838833</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 506E with 6.3(5) and wanted to know if I can configure VPN client with group and user authentications. I know I can configure just group authentication so users dont have to use the password everytime they try to connect. However I am also looking for second level of user authentication so I dont have to change the group password everytime a user leave the organization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured this on a PIX and ASA units with newer versions but I cannot find the commands for 6.3(5) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see commands below related to this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; vpngroup &amp;lt;group_name&amp;gt; secure-unit-authentication&lt;/P&gt;&lt;P&gt;        vpngroup &amp;lt;group_name&amp;gt; authentication-server &amp;lt;server_tag&amp;gt;&lt;/P&gt;&lt;P&gt;        vpngroup &amp;lt;group_name&amp;gt; user-authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I configure &lt;/P&gt;&lt;P&gt;vpngroup &amp;lt;group_name&amp;gt; user-authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the message&lt;/P&gt;&lt;P&gt;"Please configure an authentication server before enabling user authentication"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And when I add the below, I cannot configure for LOCAL authentication and accept only TACACS+ and RADIUS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        vpngroup &amp;lt;group_name&amp;gt; authentication-server &amp;lt;server_tag&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am not sure if I can configure second level user authentication on this version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281726#M838833</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2019-03-11T15:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN client user authentication</title>
      <link>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281727#M838834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you post the output of "show aaa"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jul 2009 17:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281727#M838834</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-07-22T17:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN client user authentication</title>
      <link>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281728#M838835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when I do sh aaa, I just see aaa proxy-limit 16. I have not configured anything with aaa specifically. But I see this below in the config as default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2009 01:22:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281728#M838835</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2009-07-23T01:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VPN client user authentication</title>
      <link>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281729#M838836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can someone advise on this please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2009 19:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vpn-client-user-authentication/m-p/1281729#M838836</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2009-07-23T19:11:35Z</dc:date>
    </item>
  </channel>
</rss>

