I am wanting to use ACS 3.2 to authenticate users who use the Cisco VPN client software to connect back to our Pix 520. Currently we are using a "pre-shared" key. I want to be able to authenticate users with Windows Active Directory. I am already doing this for our switches and routers, as well as wireless, but I can't seem to find a "how-to" document on the VPN client. Does anybody have a link or their own account of detailed instructions that need to be done in order for this to work? Any input is appreciated.
Thanks.
Hi,
Use Extended Authentication (Xauth) on Firewall for VPN Cleint. On ACS's user settings, use active directory which you already configured in External database as a password authentication type.
Use following reference to configure xauth on f/w.
Regards,
Mustafa