10-18-2008 07:24 PM - edited 03-10-2019 04:08 PM
Hi all,
The other day I was configuring a test VPN 3000 with external groups that are configured on a RADIUS server, let's call one group SALES with group password 1234, which I have configured on the VPN 3000 as 'external' as well. I've assigned a few users to this group (call them Jack and Mary). So far no users can authenticate successfully (authentication fail).
After spending hours troubleshooting the problem, I configured a new user whose name is SALES and password is 1234 (same as the group) and assigned to group sales, got that config from a template. After doing so, Jack and Mary can authenticate and establish the tunnel.
The problem is fixed now but my question is why is this requirement? Does this mean that with every external group I create, I have to create a user with the same name as that group and assign it to the group so that the rest of the users in that group can authenticate normally?
I tried looking for answers on the web but so far I've found none.
Any explanation would be appreciated.
Thanks
Mo
10-18-2008 07:29 PM
When you configure group as external, Group authentication also takes place by the Authentication server. It is an expected behavior.
I am sure, if you look into the fail logs on your authentication server, you must have error log mentioning that authentication for user 'SALES' failed, when you did not have that user account created on the authentication server.
Regards,
Prem
Please rate if it helps!
10-18-2008 07:38 PM
Documentation,
http://www.cisco.com/en/US/docs/security/vpn3000/vpn3000_47/configuration/guide/Usermgt.html
"Configuring external groups means configuring them on an external authentication server such as RADIUS."
"If you are using an external authentication server, keep in mind that usernames and group names must be unique. When naming a group, do not pick a name that matches the name of any external user; and conversely, when assigning a name to an external user, do not choose the name of any existing group."
Regards,
Prem
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide