Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PPTP VPN - Dual Authentication methods?

Status
Not open for further replies.

snickm

Technical User
Feb 18, 2002
12
0
0
AU
Just a quick one.

I have a PIX 515 running version 6.3. I would like to configure it as a PPTP server for Microsoft remote access clients. My question is:

Is it possible to set up the authentication so that the PIX queries a local user database first and if that fails forward the request on to a Radius server?

The reason is that I have two distinct groups of users that need to connect to the VPN, our suppliers and our staff. Our suppliers only need to get to one specific IP Address for telnet whereas we want staff to be able to get in and access everything they can access from in the office. I would prefer not to have to set up the suppliers with an acocunt in Active Directory.

Also, if there is a better way of doing this type of thing please post, I am fairly new to PIX.

Thanks

PS. I have also started the same thread in the VPN forum
 
When you setup AAA, you can specify multiple sources for authentication, I would imagine first local, then the server and you could use both. Seems to me that the best idea would be to use ACS or something similar for all authentication to the network.

I'm curious to know if this would work, let me know what you find :).

Best regards,
Ryan Lindfield
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top