I just setup a pix520 with VPN and W2k IAS radius for domain authentication. If I disable the crypto client authentication to the radius server, I can successfully VPN with the Cisco 3.5 w2k client. (obviously with the right group name and shared secret.) But as soon as I turn on the authentication to radius, I do get a domain login screen for login name and password. But always get an authentication failure. Why? Yes the IAS looks to be configured right. Yes the user dial-up permission is set to allow. I dont have the pix config at hand (i'm at home) but I will reply with it tomorrow.
please advise.
please advise.