<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA: VPN client asking me to authenticate? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-client-asking-me-to-authenticate/m-p/1070256#M896462</link>
    <description>&lt;P&gt;Im probably being a total muppet but my vpn client is asking me to authenticate when I havent set authentication up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would be extremely greatful with any help as Im used to configuring PIX's which are far easier!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the client portion of my config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy EGRASUSER internal&lt;/P&gt;&lt;P&gt;group-policy EGRASUSER attributes&lt;/P&gt;&lt;P&gt; wins-server value xxxxxxxxxxx&lt;/P&gt;&lt;P&gt; dns-server value xxxxxxxxx&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value sptnl&lt;/P&gt;&lt;P&gt; default-domain value xxxxxxxx&lt;/P&gt;&lt;P&gt;tunnel-group EGRASUSER type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group EGRASUSER general-attributes&lt;/P&gt;&lt;P&gt; address-pool EGRASPOOL&lt;/P&gt;&lt;P&gt; default-group-policy EGRASUSER&lt;/P&gt;&lt;P&gt;tunnel-group EGRASUSER ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:43:37 GMT</pubDate>
    <dc:creator>danparsons</dc:creator>
    <dc:date>2019-03-11T13:43:37Z</dc:date>
    <item>
      <title>ASA: VPN client asking me to authenticate?</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-client-asking-me-to-authenticate/m-p/1070256#M896462</link>
      <description>&lt;P&gt;Im probably being a total muppet but my vpn client is asking me to authenticate when I havent set authentication up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would be extremely greatful with any help as Im used to configuring PIX's which are far easier!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the client portion of my config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy EGRASUSER internal&lt;/P&gt;&lt;P&gt;group-policy EGRASUSER attributes&lt;/P&gt;&lt;P&gt; wins-server value xxxxxxxxxxx&lt;/P&gt;&lt;P&gt; dns-server value xxxxxxxxx&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value sptnl&lt;/P&gt;&lt;P&gt; default-domain value xxxxxxxx&lt;/P&gt;&lt;P&gt;tunnel-group EGRASUSER type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group EGRASUSER general-attributes&lt;/P&gt;&lt;P&gt; address-pool EGRASPOOL&lt;/P&gt;&lt;P&gt; default-group-policy EGRASUSER&lt;/P&gt;&lt;P&gt;tunnel-group EGRASUSER ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-client-asking-me-to-authenticate/m-p/1070256#M896462</guid>
      <dc:creator>danparsons</dc:creator>
      <dc:date>2019-03-11T13:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: VPN client asking me to authenticate?</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-client-asking-me-to-authenticate/m-p/1070257#M896465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be default if you do not specific ANY config in the profile "EGRASUSER" then the device will apply any "default" configuration from the "DfltGrpPolicy" attirbutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you do not want any user auth the config the below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy EGRASUSER attributes&lt;/P&gt;&lt;P&gt;authentication-server-group  none &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above means you will only auth on IKE. My advise would be NOT to do this, as you only have 1 factor authentication - security best practise says you should have 2 or more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not want to authenticate to a back AD/RADIUS or LDAP - then authenticate locally:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username &amp;lt;&lt;USERNAME&gt;&amp;gt; password &amp;lt;&lt;PASSWORD&gt;&amp;gt; privilege 0&lt;/PASSWORD&gt;&lt;/USERNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group EGRASUSER general-attributes&lt;/P&gt;&lt;P&gt;authentication-server-group  LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2008 09:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-client-asking-me-to-authenticate/m-p/1070257#M896465</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-09-12T09:35:08Z</dc:date>
    </item>
  </channel>
</rss>

