09-25-2003 12:42 PM - edited 02-20-2020 11:00 PM
I can give some feed back to one of our
customers, and they are implementing two Cisco Pix 515, to act as Firewall's and VPN servers. They asked the question if you could setup multiple VPN profiles on the Pix to point to different authentication servers, ie one profile to a SecurID server, another to a Radius server, lets say. I know you can do it on the Concentrator, but I'm not sure on the PIX. Can you check that for me. Also if you can find any documentation that would be great. Thanks
09-25-2003 02:28 PM
You can use the "vpngroup ... authentication-server ..." command to specify different AAA servers per vpn group, using either RADIUS or TACACS+. Is this what you need?
09-26-2003 05:14 AM
Can that point to a Radius server and point to ScureID server.
09-29-2003 02:11 PM
The PIX only supports RADIUS and TACACS+ as authentication protocols, so your SecurID server will need to use one of those to communicate with the PIX. The PIX does not support the SDI protocol that the VPN 3000 series does, so that's not an option.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide