Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pix to RADIUS Server issue

Status
Not open for further replies.

phaseshift

IS-IT--Management
Dec 13, 2004
45
0
0
US
I have a PIX 501 setup to due Radius Auth.

Once I try and log into my network via the VPN I keep getting the same error at the radius server.

Er: "Unknown username or bad password"

Even though the account is correct. Any ideas on my is going wrong during the radius auth.

Thanks
Phaseshift
 
hello,

with the ms-ias this should be the configuration:

aaa authentication ssh console aaa_makeit LOCAL
aaa authentication telnet console aaa_makeit LOCAL
aaa authentication http console aaa_makeit LOCAL

aaa-server aaa_makeit protocol radius
aaa-server aaa_makeit max-failed-attempts 3
aaa-server aaa_makeit deadtime 10
aaa-server aaa_makeit (inside) host 172.16.1.32 pwd timeout 10

on the ms-ias i configured the pix as a standard radius-device...this works fine..

importaint:
aaa authentication http console aaa_makeit LOCAL

--> if the radius server does not answerer, the pix takes the LOCAL-DB for aaa. So you have to configure a username locally on the pix (command: username).

martin


----------------------------------
Martin Peinsipp, Austria
CCSA,
IT-Security-Administrator
 
i for got the config for the vpn-client-stuff:

crypto map crypto_outside 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map crypto_outside client authentication aaa_makeit



----------------------------------
Martin Peinsipp, Austria
CCSA,
IT-Security-Administrator
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top