cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
587
Views
5
Helpful
2
Replies

Problem with Cisco 1721 + ACS 4.0 and VPND windows users auth

hyperglobus
Level 1
Level 1

Hello,

I used this example for making VPND server with radius auth for WinXP SP2 users - http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a008009436a.shtml

But users cant pass auth - in ACS logs i see what everything is ok - status in passed auths is - Authen OK.

Debug output and config file are in attach.

Thanks in advanced.

2 Replies 2

Premdeep Banga
Level 7
Level 7

debug indicate that radius is responding, and in debugs we can see,

"RADIUS: response-authenticator decrypt fail, pak len 126"

Device is somehow not able to decrypt the response. Generally its due to shared secret mismatch. But I don't think that's the case.

Please check if this applies,

CSCsh02500 : L2TPv2 calls fail when receiving hidden AVPs

Regards,

Prem

Hello,

1st - i checked key between cisco and ACS (because found a lot of examples of this error), after this i checked also users and passwords - because this group in ACS is maped to Windows AD.

L2TPv2 calls fail when receiving hidden AVPs ???