06-05-2007 05:11 AM
i currently have my ASA authenticating VPN users against the active directory in conjunction with the Cisco VPN Client. I got this working great but it seems like anyone with the client is able to authenticate. In active directory under the dial-in tab for a user there is a Remote Access Permission
there are options for Allow Access
Deny Access
Control through remote access
if i have deny selected they can still vpn in.
PLease tell me if there is any way to accomplish this or a workaround. thanks
Darren
06-05-2007 06:08 AM
Normally, you configure the IAS profile for a specific AD-group. Please check if the user is a member of that group.
06-05-2007 06:28 AM
the vpn group specified in IAS does not have the user account i can connect with. here is my config for this
aaa-server IAS protocol nt
aaa-server IAS host 192.168.1.5
nt-auth-domain-controller dcpdc
the authentication protocol is NT, i dont know if that helps
06-06-2007 01:35 AM
He is talking about on your IAS server. Check your configuration of your Windows box, your answer is there.
06-06-2007 01:11 PM
I usually use Radius myself.
The configuration would look like this:
aaa-server RADIUS protocol radius
aaa-server RADIUS (inside) host "AD Domain controller"
This requires at least Windows 2000 servers that are running IAS.
Here is a link how to configure it:
06-18-2007 09:32 AM
I can tell you i'm almost sure there is no document good enogh to explain you that at cisco.com, so i've done a document by myself, i'm sorry it's on portuguese ( my lenguege) you can use some translator to understand it.
There is no explanation for IAS configuration in this document, but you said you have it already
Please hate the post if helps.
06-18-2007 09:38 AM
thanks for your post, but i got it just after posting this. The problem with using the aaa-server protocol nt
is that it uses ntlm authentication but no authorization. I ended up using radius for this since it is able to use both authentication and authorization. that was my issue
08-14-2007 11:08 AM
Did you make a radius server on windows 2000 or 2003?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide