Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other troubleshooting best practices.

Labels

Forum Posts

Hello group,We currently have a PIX 501 to PIX 501 vpn between two offices. Wehave an AS400 at the main site. At both locations we would like theusers to authenticate to the PIX locally for internet access. Iunderstand that the PIX allows for telnet,...

joe.sallmann by Community Member
  • 1440 Views
  • 1 replies
  • 0 Helpful votes

Hello,Does anyone know whether you can configure a PIX to use an alternate RADIUS server if the primary one is not responding? For example, one of our customers authenticates their VPN clients using a RADIUS server with the PIX command:aaa-server ISA...

Hi, I am using ACS for Authentication for Access-server. I am using RADIUS for authentication. Now If the user is connected and it has a 1 hours time remaining in his account. Now if this user is authenticate and use the services, and between this if...

Hello..I am using the ACS v2.6 in Windows2000.I want to limit the user session in ACS..All user can login to Router in one session at a time.I tried to set it in user setup, but it didn't work.I really want to know how to setting it...

dullyo by Community Member
  • 1538 Views
  • 2 replies
  • 0 Helpful votes

There are two RADIUS servers - Cisco ACS and some freeradius. Both servers are proxy servers for each other - we have on our distribution table their RADIUS as proxy, and they have ours. Problem - we can authenticate to their RADIUS with their userna...

jlipacis by Frequent Visitor
  • 1503 Views
  • 1 replies
  • 0 Helpful votes

Hi gurus,Please help:acs (net172.16.1.12)---PIX(10.0.20.1/28)-----(10.0.20.32/28)PIX----NASRouter (Fa0/0 192.168.0.1)--Dial-in User. NOTE: --Between PIX there has 2 network coz go throughservice provider --The Fa0/0 has being NAT-ed to 10.0.20.46. --...

j.hato by Level 3
  • 1664 Views
  • 2 replies
  • 0 Helpful votes

I'm trying to use ACS 2.6 and ACS 3.2 as a radius server to for my Msft win-xp client to do authentication before it brings up its pptp client.To that end, on ACS, I enable the attributes:MS-CHAP-MPPE-Keys (N/A)MS-CHAP-MPPE-Types (128 bit)MS-MPPE-Rec...

admin_2 by Level 7
  • 1815 Views
  • 1 replies
  • 0 Helpful votes

Hello,I have a LNS configured to send start and stop accounting messages to the Radius server.It seems some stop messages aren't received by the server.Is there a retransmission timer for the accounting stop messages ?Thanks

guyber by Community Member
  • 1503 Views
  • 1 replies
  • 0 Helpful votes

Which is the behaviour of a LNS in such a situation :A Radius server sends an access-accept with an IP address which is already linked to a PPP session.Does the LNS maintain the PPP session and refuse the creation of a new one, or does it react by de...

guyber by Community Member
  • 1500 Views
  • 1 replies
  • 0 Helpful votes

Anyone have an ini file which adds the packeteer attributes to an acs 3.2 server. I'm having problems with the "=" in the VSA. I'll keep trying but if someone has already done this please send it over.Does Cisco have a site that might already have de...

wes by Community Member
  • 1389 Views
  • 1 replies
  • 0 Helpful votes

Our VPN 3030 Concentrator is sitting in the DMZ zone of our firewall. The ACS is sitting behind the firewall inside our LAN. Our mobile users are authenticated through the ACS server when they wants to establish a VPN connection to our network. Curre...

jliew by Community Member
  • 1443 Views
  • 1 replies
  • 0 Helpful votes