cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2128
Views
0
Helpful
1
Replies

Problem to authenticate VPN clients if NT domain is set

rman
Level 1
Level 1

I'm using VPN 3030 Concentrator and Cisco ACS 2.6 NT as radius server.

I found that the CiscoSecure cannot authenticate Win98/ME VPN clients if the WindowsNT domain name is entered on the clients PC. The following error message was appeared on the client PC:

'Error 691. The computer U have dialed in to has denied access because the username and/or the password is invalid in the domain'

I checked the log on CiscoSecure and found that the login name is in the form "domain/username". The CiscoSecure reject the user with reason "CS unknow user".

What can I solve the problems ? Such as how to truncate the domain? or any VPN Concentrator software upgrade to do so ?

Thanks

Rayon

1 Reply 1

r-simpson
Level 3
Level 3

You should determine if DOMAIN\user works for non-aironet users & if offline testing works as described at http://www.cisco.com/warp/public/480/9.html.You can also force domain-stripping as described at http://www.cisco.com/warp/public/480/domain_stripping_hack.html. Or turn on an NT audit trail to check the event log to see why NT is denying them.