cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1039
Views
5
Helpful
7
Replies

Cisco IPsec IKEV2 AAA server

Kahlilevelyn
Level 1
Level 1

Good Day,

Is it possible to configure IKEv2 Ipsec VPN without a AAA server? Or at the very least use the ASA 5508x as a AAA server for VPN users?

1 Accepted Solution

Accepted Solutions

Hi,

I have attached the ASDM screenshot for doing both LOCAL authentication and DHCP address assignment for the VPN users.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

View solution in original post

7 Replies 7

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

Yes you can do that.

Under the tunnel group config you need to define authentication server as local.

tunnel-group TEST type remote-access
tunnel-group TEST general-attributes
no address-pool
no ipv6-address-pool
authentication-server-group LOCAL

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Is it possible to do this via ASDM?

As i have never used CLI to configure a IKEv2 VPN before.

Hi,

Apologies as I was not able to find it from the ASDM.

But the CLI commands shared would enable local authentication.

Let me know if you face any issues.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Thanks,

I have no idea what the CLI commands are

I want to create the IKEv2 Ipsec VPN on my outside interface with a dhcp pool of 192.168.250.1-253 and i want it to block access to my inside address of 10.0.0.0 and 192.168.10.0

Hi,

I have attached the ASDM screenshot for doing both LOCAL authentication and DHCP address assignment for the VPN users.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Is the attached correct?

i added the anyconnect client to the anyconnect client software tab also.

Yes that is correct.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Review Cisco Networking for a $25 gift card