cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1138
Views
0
Helpful
1
Replies

VPN Radius Authentication

Dan Loring
Level 1
Level 1

                   We are in the process of upgrading our AD to 2008.  So we are building a new Schema Master Grand Pooba  AD server with a new IP address, the old address will be demoted.  Unfortunately we have our AAA Server Group using radius to authenticate off this old server for our VPN users.  I went to Configuration > Remote Access VPN > AAA/Local Users > AAA Server Groups > AuthInBound on the ASA5510 ASDM ver(6.4(9)) and went to add our new AD Server as the AAA server for VPN and it is asking for a server secret key and Common password??   Anyone know where we go to generate this server secret key and a common password??

AAA server.JPG

Thanks,

Dan

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Dan,

You need to add the radius client to the IAS ( Internet Authentication Sevice)

Add a client to your radius – In the IAS MMC, right-click on the “Radius Clients” branch and choose “New Radius Client” Enter the Display anem and IP address of the device, click next. Change the Vendor to “Cisco” and enter your shared secret (keep a note of this for later)

This link might help you:

http://briandesmond.com/blog/how-to-authenticate-against-active-directory-from-cisco-ios/

Regards,

Remember to rate all the helpful posts, that is as important as a thanks

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: