Is there a bug in the ACS software? When I change the password in the ACS server with password aging configured ACS is supposed to prompt for the user to change the password upon the first try. In switches/routers, etc.. you ARE prompted to change the password but the VPN client does not provide an interface to do that which results in your password aging.