cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
955
Views
4
Helpful
2
Replies

RADIUS Login Failure for Clientless or EasyConnect Client on ASA5520

paulmouat
Level 1
Level 1

I thought I would share my experience with the above.

Fist the environment

ASA5520 with Easy Connect Essentials License

I'd configured the VPN for clients connecting using the EasyConnect Client.

First I'd configured the authentication for LOCAL users which worked fine, the users could browse to the webpage on the ASA login using the LOCAL username then the EasyConnect client would connect.

Then I tried the RADIUS and then LDAP authentication both failed with "LOGIN FAILED" on the webportal webpage.

Checked the RADIUS server and the logs showed that the username had been granted access, so why was the ASA rejecting the login.

I ran "debug webvpn 15" on the ASA, and the only error that was showing was "User came in on group he wasn't supposed to come in on"

To get this working I had to go to in the ASDM

"Clientless SSL VPN Access"

Then "Group Policies"

Under "General" then "Connection Profile(Tunnel Group) Lock"

By default this is set to Inherit which I believe meant the the profile that the ASA was attempting to use was the wrong one. As soon as this was set to the SSL Profile I'd specifically setup everything worked fine.

2 Replies 2

Erik Ingeberg
Level 1
Level 1

Take a look at the real time log in ASDM when connecting. You should see in the log which tunnel-group and group-policy which is matched.

How do users choose to be in the "SSLClientProfile" tunnel group? They need to use either drop-down menu or group-url, otherwise the tunnel-group used will be "DefaultWEBVPNGroup".

Hi when i was testing this there was nothing shown in the ASDM log screen at all.

The DefaultWEBVPNGroup is not enabled at all on the external interface so the users are automatically pointed towards the sslclientprofile or in our case I've used an Alias to give it a more friendly name.

Plus remember this isn't a question everything is working I just thought I'd share, as it took me a while to get it working.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: