Re: Changing Windows Passwords - VPN with a PIX, Cisco VPN Client and RADIUS Authentication




DCS wrote:
I have remote access configured between a PIX running IOS 7.2(1) and
Cisco VPN clients running 4.8. I'm currently authenticating using
RADIUS from IAS running on a Windows 2003 Server. This server is
configured as a stand-alone workgroup server and all users are
maintained on it.

How do I enable changes to the Windows password when a user's password
has expired or they first get their account and are required to change
the password at first login? All my users are remote and never local
so the VPN is their only access. I know this is possible using the
Concentrator but the PIX and ASA's should have evolved to the point to
accomodate this.

Also, my current RADIUS exchange takes place using PAP, which is
unencrypted. How can I change this to MS-CHAP v2? Thanks!

I now have the MS-CHAPv2 working between the PIX and IAS. I ensured
MS-CHAPv2 was allowed on the IAS side and then added the
"password-management" on the tunnel group ipsec-attributes being used
for the remote connection. I'm still unable to change Windows password
though the 7.2(1) documentation says it will. Is the RADIUS command to
do this supported in Cisco ACS and not IAS RADIUS?

.



Relevant Pages

  • Re: Radius question
    ... Note the following general exception to Windows CAL requirements: ... CALs are not required when access to the server software is unauthenticated ... who all can be RADIUS clients to Microsoft RADIUS Server? ... > authenticate against Active Directory if your remote access devices are not ...
    (microsoft.public.windows.server.networking)
  • Re: Configure Radius
    ... You can automate the configuration of IAS by using the SDO interfaces. ... > Is there a way to setup a RADIUS server with some command-line tool. ...
    (microsoft.public.internet.radius)
  • Re: 802.1x authentication for wireless issues w/ ISA 2004
    ... Click on RADIUS under Authentication Services and check the box to ... IAS on ... a server other than the SBS, I'm wondering whether ISA2004 is blocking ... Successful Network Logon: ...
    (microsoft.public.windows.server.sbs)
  • Re: 802.1x authentication for wireless issues w/ ISA 2004
    ... The do support WPA-EAP and the radius ... authenticate the computer and this is trying to authenticate the user and not ... If you can post perhaps 10 lines from the IAS log, ... represent my IAS server or the client laptops. ...
    (microsoft.public.windows.server.sbs)
  • RE: rras, dhcp question
    ... Based on my research RRAS server cannot achieve the goal. ... Additionaly, IAS ... Authentication Dial-In User Service server in Windows 2000 Server ...
    (microsoft.public.windows.server.networking)

Loading