cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7742
Views
15
Helpful
8
Replies

Cisco VPN client did not prompt to change password when Radius ID is due expired.

wjlee1989
Level 1
Level 1

Greetings, I would like to know what is causing Cisco VPN client software at user PC did not prompt to change password when their Radius ID's password is expiring/expired. I would also like to know what is the solution to work around it. Thanks in advance.

.-asd-.
1 Accepted Solution

Accepted Solutions

Hi,

Is the "password-management" command configured?

For the password-expire feature to work in conjuction with Radius, that is all you need on the ASA.

Let me know.

Thanks.

View solution in original post

8 Replies 8

wjlee1989
Level 1
Level 1

Bumping my own thread, anyone can provide me answer?

.-asd-.

Hi Lee,

Could you please share the tunnel-group configuration?

Is the "password-management" command configured?

Please keep me posted.

Portu.

Thanks for replying, currently we are using ASA 5520, with ASDM 6.4 console. The configurations you had mentioned is located in the firewall, or RADIUS server?

.-asd-.

wjlee1989
Level 1
Level 1

Here is more details of the issue: After we have migrated VPN host from Concentrator to ASA5510, the user credentials are stored in RADIUS server, we have noticed when the VPN user's password expired and requires reset (or a few days before expiring), the VPN client will not prompt user to create new password and accept new credential, and they are stuck at the Username/Password prompt instead. Can anyone enlighten me how to solve this issue?

.-asd-.

Hi,

Is the "password-management" command configured?

For the password-expire feature to work in conjuction with Radius, that is all you need on the ASA.

Let me know.

Thanks.

From the guide which I have studied, that it is the command

"hostname(config-tunnel-general)# password-management"

is this correct? Is there a way I can view if it is being configured?

Regards.

.-asd-.

wjlee1989
Level 1
Level 1

After setting the password-management configuration the VPN client is able to prompt user to input new PIN when it is expired. From the white paper the default prompt message will warn the user 14 days before expiring. Thanks for the help!

.-asd-.

Great news

Thanks for counting on us.