cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1564
Views
0
Helpful
3
Replies

FlexVPN for anyconnect remote access with local authentification

ngtransge
Level 1
Level 1

Hello,

 

 

I am interesting if it is possible to configure ISR 1941 Router as FlexVPN Server, with simple local user/password authentication, without certificate and external RADIUS server and connect with AnyConnect VPN client. Can you provide configuration templates for this kind of configuration ?

 

 

Thank you,

3 Replies 3

Graham Bartlett
Cisco Employee
Cisco Employee

Hi


To answer your question bluntly, but 'no', for username/password (EAP) authentication a certificate is required for the headend (as mandated by the IKEv2 RFC).

 

There's a feature request for IOS to act as a RADIUS device, but i've seen no traction on this since I raised it..

 

Sorry.

 

Maybe you could look at using certificates and the 1941 as the CA ?

cheers

Jacob Zartmann
Level 1
Level 1

im facing the same issue, i have no idea why this is not working.