Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco VPN and ACS server

Status
Not open for further replies.

nsglists

IS-IT--Management
Jul 20, 2006
57
US
I have a Cisco VPN concentrator which uses a Cisco Secure ACS server for authentication. Currently all the accounts are on the local ACS database. I have a Windows domain and I want to use the accounts in this domain.
So, on a test domain server, I setup ACS and for accounts which will use VPN, I gave "grant dial in permission". I configured the same on the ACS server. Now after following everything from the book. I pointed the vpn server to this ACS server and then I tried to authenticate. It seemed to work fine and when I check under reports and activity for passed auth,

09/19/2006 12:49:48 Authen OK name Default Group IP#1 name vpnIP

but, it prompted me to enter again. I am pretty sure I am entering the right login info. I tried entering the wonrg password and a similar log was registered for failed auth,

09/19/2006 12:49:22 Authen failed name Default Group IP#1 External DB user invalid or bad password .. .. name vpnIP

So, it means that it is able to see the accounts in AD, but it is still not authenticatin. What am I missing here.
Kindly advice.

Kindly let me know if I should post this in any other forum.
Thanks,
 
When I said any other forum, I meant any other subject in tek-tips.

Also,
"Verify that "Grant dialin permission to user" setting has been enabled from within the Windows User Manager for users configured for Windows User Database authentication" was checked. I also made sure that the domain was available.

Thanks.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top