<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5540 Not Authenticating in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149429#M959642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We can ping the AD server from ASA.  The client is using UDP, the AD Group is using RADIUS but when authenticating from within asa authentication server is unavailable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Jan 2009 20:37:46 GMT</pubDate>
    <dc:creator>wdhowellsr</dc:creator>
    <dc:date>2009-01-22T20:37:46Z</dc:date>
    <item>
      <title>ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149424#M959631</link>
      <description>&lt;P&gt;Our ASA 5540 has just started to deny all inbound connections for VPN with the following messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106023 Deny udp src dmz:...&lt;/P&gt;&lt;P&gt;713048 Error processing payload:&lt;/P&gt;&lt;P&gt;713048 Sending IKE Delete No Reason Prvd&lt;/P&gt;&lt;P&gt;713902 Removing peer from peer tabl fld&lt;/P&gt;&lt;P&gt;713903 Error. Unable to Remove Peer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upon connection regardless of user when username and password are entered the fields immediately clear and no login occurs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149424#M959631</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2020-02-21T11:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149425#M959633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post here the next debugs "debug crypto isakmp 50"? To check whether authentication is the issue, you can go ahead and issue a test command on the asa for your authentication "test aaa authentication &lt;AAA server=""&gt;" type in the username and password and see if it fails or passes.&lt;/AAA&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 18:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149425#M959633</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-22T18:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149426#M959636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will do.  Just a side point is that the asa time was actually two hours off of the accurate time.  It was reset to the current time but authentication still did not work.  I'm getting the debus now and will post them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 19:08:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149426#M959636</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2009-01-22T19:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149427#M959638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually the good news is that we can access the asa directly but apparently the connection between the asa and the active directory server is not working.  When we tested authentication it says the server is unavailable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 19:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149427#M959638</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2009-01-22T19:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149428#M959640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, what is the authentication protocol in use? Can he ASA reach it via ping?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 19:53:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149428#M959640</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-22T19:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149429#M959642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We can ping the AD server from ASA.  The client is using UDP, the AD Group is using RADIUS but when authenticating from within asa authentication server is unavailable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 20:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149429#M959642</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2009-01-22T20:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149430#M959644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the protocol that you are using to communicate the ASA to the AD is radius, assuming via AIS, what do you see on the Event Viewer of your server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 21:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149430#M959644</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-22T21:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149431#M959646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Typo, I meant IAS, do you see the authentication request on the server? run a debug radius all on the asa with the test, do you see any error there?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 21:40:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149431#M959646</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-22T21:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149432#M959649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your going to love this.  First I'm actually a contract programmer analyst developing a web reporting module for an insurance company.  Second the IT department is limited and they ask my help ocassionaly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now for the good part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem first started happening on Saturday afternoon.  Obviously something changed at that point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wait for it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Manager of IT decided to set the IAS server to dynamic IP and use the static IP on another server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That ones a keeper.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 23:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149432#M959649</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2009-01-22T23:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149433#M959650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Go figure.... it usually ends on a human mistake &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 23:42:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149433#M959650</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-22T23:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149434#M959653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your going to love this.  First I'm actually a contract programmer analyst developing a web reporting module for an insurance company.  Second the IT department is limited and they ask my help ocassionaly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now for the good part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem first started happening on Saturday afternoon.  Obviously something changed at that point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wait for it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Manager of IT decided to set the IAS server to dynamic IP and use the static IP on another server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That ones a keeper.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jan 2009 23:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149434#M959653</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2009-01-22T23:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149435#M959655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The pointy haired boss strikes again.  GRR!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;He changed the IAS server to a new static IP on a different subnet and updated DNS to point to the new IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even when the ASA is configured to point to the IP of the IAS server it fails authentication even though it can being pinged.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a gut feeling that there is DNS corruption somewhere and that while the ASA can ping the server IP it fails on authentication due to incorrect name resolution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My simple question is if there is a way to hardcode server name, ip and subnet mask in the ASA so that no matter what he screws up on the network as long as we keep the IAS and ASA configured properly it would work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is why I got out of network engineering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2009 17:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149435#M959655</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2009-01-27T17:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Not Authenticating</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149436#M959657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just a heads up.  If you mess around with the DNS and IP addressees to much just remember to clear out your DNS cache and tables on your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem Solved,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2009 22:49:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-not-authenticating/m-p/1149436#M959657</guid>
      <dc:creator>wdhowellsr</dc:creator>
      <dc:date>2009-01-27T22:49:09Z</dc:date>
    </item>
  </channel>
</rss>

