10-05-2010 03:00 AM
Can any VPN user change their user account password through tunnel which configured on local database of ASA 5510?
10-05-2010 03:12 AM
Hi Manish,
I don't think there is any way a vpn user can change the password ( or the user account) after getting connected to the ASA, except maybe by telnet or ssh to the inside interface of the ASA, login to it and change the password.
When a vpn client connects, the only thing that changes is that it can access the remote internal networks, including the ASA's inside interface. If user on vpn client wants to login to ASA, he still needs to authenticate to it.
Let me know if this helps,
Cheers,
Rudresh V
10-05-2010 04:37 AM
Hello,
I don't think there is a procedure to let the users change their own password on the ASA local DB.
You can find this option with the UCP application in the Cisco Secure ACS,
and if you have more then few users to manage, I think you need some RADIUS server.
Regards,
Marco.
02-09-2012 09:12 AM
just finished researching this, and came to the conclusion that there are only a few limited options:
-Cisco ACS vmware "device
-cisco acs appliance
-Microsoft AD database with ldap integration to asa
-Microsoft AD database with radius integration to asa
I have configured ACS + radius + ad, but this was on older ACS software, where ACS only supported UCP. now it appears like ACS 5.X supports change password from its local database (not the ASA), so you don't need to pass this to M$ AD. Cisco really needs to develop the code to do PWD change on the ASA local user accounts option. that would help smaller organizations with 10-30 accounts, for example.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide