02-21-2022 01:32 PM
I was wondering if I can connect two options for remote user VPN. As of now I have remote VPN configured for certificate based authentication only. I was wondering if I can add another using Radius so in effect when a user connects they have an option of choosing certificated based VPN or entering in their Active Directory credentials through windows radius?
Solved! Go to Solution.
02-21-2022 01:39 PM
If I get you request,
config two tunnel group and enable group-alias, then the user can select group with prefer auth method.
02-21-2022 01:39 PM
If I get you request,
config two tunnel group and enable group-alias, then the user can select group with prefer auth method.
02-21-2022 03:38 PM
Hi thanks. When I connect the VPN i see what is in the attached screenshot. I cannot find where this group is located anywhere within my VPN settings. If I go in and add an additional connection profile (Tunnel Group) within FMC and I reconnect I still only see the group called Tunnelusers.
02-21-2022 06:12 PM - edited 02-21-2022 06:14 PM
Thank you I got two methods to authenticate using the Tunnel Groups one being smart card only users and the other for Radius. Super cool. It took me awhile to figure out how to troubleshoot my radius setup and if you are ever interested from the FTD you can run the following command to check your radius setting and communication to. In this case I using WINDOWS RADIUS NAP
Looks like they kept these from the ASA for the FTD. WIndowsRadius is name of radius object I created within FMC
1) Show run aaa-server
2) test aaa-server authentication WIndowsRadius host 192.168.30.10
Username: vpntest
Password: ***************
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide