cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
673
Views
0
Helpful
1
Replies

Microsoft 2003 IAS immediately logs off credentials.

mathews20
Level 1
Level 1

I'm trying to connect Cisco VPN 4.6.02.0011 clients to a Cisco PIX 501 v6.3(4), using RADIUS to an internal Microsoft 2003 IAS, configured according to http://www.cisco.com/warp/public/110/cvpn3k_pix_ias.html

Whenever a VPN client tries to authenticate, the client software seems to keep retrying, eventually it just times out. Microsoft security event viewer log shows that the user is authenticated and "logged on", but the immediate following message says the user has been "logged off". I should mention that the Microsoft server is the active directory domain controller. I get the same result if I provide the username in the form of "domain\username".

Using the LOCAL database for authentication works fine.

I'm happy to provide the PIX's configuration or debug messages I've gotten from it during log on attempts if you email me directly for it. sschaef2 at csc com

Any help, or suggestions would be greatly appreciated.

1 Reply 1

didyap
Level 6
Level 6

The document has more information on Cisco Secure PIX Firewall 6.x and Cisco VPN Client 3.5 for Windows with Microsoft Windows 2000 and 2003 IAS RADIUS Authentication.

http://www.cisco.com/en/US/customer/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml