cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
392
Views
5
Helpful
2
Replies

local database of pix 525

abdul basit
Level 1
Level 1

hello friends..

i configured pix 525 for easy vpn. About 100 to 200 people will use this service. i dont have much knowledge about radius and tacacas servers. Is local data base enough for extended authentication or should i configure the server for it ?

regards.

1 Accepted Solution

Accepted Solutions

Jatin Katyal
Cisco Employee
Cisco Employee

Xauth is recommended and can be done with the local database or using  RADIUS.  All Win2k/2k3/2008 server include RADIUS as part of the OS like IAS or NPS server.

Just to add more security / Flexibility and to have centralize data/configuration for any large organisation, it is required. If you think the users strength will not grow in future, you can carry on with local database only.

Here is a document in case you need to study more about it.

How to Add AAA Authentication (Xauth) to PIX IPSec 5.2 and Later

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008010a206.shtml

Regards,

Jatin Katyal
- Do rate helpful posts -

~Jatin

View solution in original post

2 Replies 2

Jatin Katyal
Cisco Employee
Cisco Employee

Xauth is recommended and can be done with the local database or using  RADIUS.  All Win2k/2k3/2008 server include RADIUS as part of the OS like IAS or NPS server.

Just to add more security / Flexibility and to have centralize data/configuration for any large organisation, it is required. If you think the users strength will not grow in future, you can carry on with local database only.

Here is a document in case you need to study more about it.

How to Add AAA Authentication (Xauth) to PIX IPSec 5.2 and Later

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008010a206.shtml

Regards,

Jatin Katyal
- Do rate helpful posts -

~Jatin

thank you