ASA5540 and RADIUS problem

ASA5540 and RADIUS problem

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
ASA5540 and RADIUS problem John Smith 05-30-2008
Posted by John Smith on May 30, 2008, 3:42 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Dear all,

I run into a problem when trying to use a radius server (on Solaris)
with ASA5540 for authentication (for RA vpn). In the appliance, I can
test it with:
# test aaa-server authentication my-aaa-gp host x.x.x.x username test
password pass
INFO: Attempting Authentication test to IP address <x.x.x.x> (timeout: 12)
INFO: Authentication Successful

With tcpdump, I got this:
15:25:42.850966 y.y.y.y.1025 > x.x.x.x..radius: rad-access-req 64 [id
37] Attr[ User Pass NAS_ipaddr [|radius]
15:25:42.851229 y.y.y.y..1025 > x.x.x.x.radius: rad-access-req 64 [id
37] Attr[ User Pass NAS_ipaddr [|radius]

Now when I try to make a vpn connection from Vista, the authentication
failed and tcpdump shown this:
15:36:15.536324 y.y.y.y.1025 > x.x.x.x.radius: rad-access-req 156 [id
39] Attr[ User NAS_port Service_type Framed_proto
NAS_port_type [|radius]

In ASA5540's log, there was an entry:
AAA authentication server not accessible ...

Can anyone what is going on here? Did I miss configure something? If
yes, how come the "test aaa-server" works?

Thanks in advance.

Network Magic Graduation 20% off animated banner
Posted by Morph on May 30, 2008, 5:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
wrote:

| Dear all,
|
| I run into a problem when trying to use a radius server (on Solaris)
| with ASA5540 for authentication (for RA vpn). In the appliance, I can
| test it with:
| # test aaa-server authentication my-aaa-gp host x.x.x.x username test
| password pass
| INFO: Attempting Authentication test to IP address <x.x.x.x> (timeout: 12)
| INFO: Authentication Successful
|
| With tcpdump, I got this:
| 15:25:42.850966 y.y.y.y.1025 > x.x.x.x..radius: rad-access-req 64 [id
| 37] Attr[ User Pass NAS_ipaddr [|radius]
| 15:25:42.851229 y.y.y.y..1025 > x.x.x.x.radius: rad-access-req 64 [id
| 37] Attr[ User Pass NAS_ipaddr [|radius]
|
| Now when I try to make a vpn connection from Vista, the authentication
| failed and tcpdump shown this:
| 15:36:15.536324 y.y.y.y.1025 > x.x.x.x.radius: rad-access-req 156 [id
| 39] Attr[ User NAS_port Service_type Framed_proto
| NAS_port_type [|radius]
|
| In ASA5540's log, there was an entry:
| AAA authentication server not accessible ...
|
| Can anyone what is going on here? Did I miss configure something? If
| yes, how come the "test aaa-server" works?

Did you configure the RADIUS to have the asa as client?

Posted by Its me Earnest T. on May 30, 2008, 8:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Check the logs on the SUN box. You didnt specify how the vista client was
connecting but you need to make sure the correct connection protocols
allowed on the SUN box. IE: CHAP, MSCHAP, PAP


> Dear all,
>
> I run into a problem when trying to use a radius server (on Solaris) with
> ASA5540 for authentication (for RA vpn). In the appliance, I can test it
> with:
> # test aaa-server authentication my-aaa-gp host x.x.x.x username test
> password pass
> INFO: Attempting Authentication test to IP address <x.x.x.x> (timeout: 12)
> INFO: Authentication Successful
>
> With tcpdump, I got this:
> 15:25:42.850966 y.y.y.y.1025 > x.x.x.x..radius: rad-access-req 64 [id 37]
> Attr[ User Pass NAS_ipaddr [|radius]
> 15:25:42.851229 y.y.y.y..1025 > x.x.x.x.radius: rad-access-req 64 [id 37]
> Attr[ User Pass NAS_ipaddr [|radius]
>
> Now when I try to make a vpn connection from Vista, the authentication
> failed and tcpdump shown this:
> 15:36:15.536324 y.y.y.y.1025 > x.x.x.x.radius: rad-access-req 156 [id 39]
> Attr[ User NAS_port Service_type Framed_proto
> NAS_port_type [|radius]
>
> In ASA5540's log, there was an entry:
> AAA authentication server not accessible ...
>
> Can anyone what is going on here? Did I miss configure something? If yes,
> how come the "test aaa-server" works?
>
> Thanks in advance.



Similar ThreadsPosted
PIX 501 PPTP VPN RADIUS authentication problem August 2, 2005, 1:14 pm
Help - 2610/Radius/PIX/NAT November 11, 2004, 2:12 pm
Radius Problems December 11, 2004, 6:50 pm
RADIUS authentication February 28, 2005, 1:29 pm
VPN Client, IOS, Radius July 15, 2005, 2:32 pm
IOS authentication with MS IAS (AAA/radius) July 28, 2005, 3:25 pm
Pix VPN Radius Accounting September 16, 2005, 9:19 am
Pix: VPN Radius Accounting September 21, 2005, 2:58 pm
radius authentication February 15, 2006, 7:54 am
Minor RADIUS POD bug in 12.3 June 8, 2006, 4:34 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map