Re: PPTP, IAS Radius and Cisco 1801



Masterx81 wrote:
Hi to all...
I've a big trouble trying to get work a cisco 1801 os vpn pptp dial in
(winth ms vpn client)
I'm no able to use encryption nor compression... If i set encryption
(most important thing) on the client i get 742 error...

This is pieces of the config that are involved:

aaa new-model
!
!
aaa authentication attempts login 5
aaa authentication login console none
aaa authentication login telnet local
aaa authentication ppp VPNDialIn group radius
aaa authorization exec default local
aaa authorization network default if-authenticated
!
aaa session-id common

vpdn enable
!
vpdn-group VPNDialIn
! Default PPTP VPDN group
accept-dialin
protocol pptp
virtual-template 1
!

interface Virtual-Template1
description $FW_OUTSIDE$
ip unnumbered Vlan1
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
peer default ip address dhcp-pool sdm-pool1
no keepalive
compress mppc
ppp encrypt mppe auto required
ppp authentication ms-chap ms-chap-v2 callin VPNDialIn
!


radius-server host 192.168.x.x auth-port 1812 acct-port 1813
radius-server key xxx
radius-server vsa send authentication




The client connect only without encryption and comrpession (radius
communications seem ok).

Thanks to all!!!



Is this on Vista?

Since 40bit and ms-chap are not very secure maybe they are disable by
default in Vista.

Just a thought? Maybe you could capture the traffic and post the results?
.



Relevant Pages

  • PPTP, IAS Radius and Cisco 1801
    ... I'm no able to use encryption nor compression... ... on the client i get 742 error... ... aaa authentication login console none ... Default PPTP VPDN group ...
    (comp.dcom.sys.cisco)
  • SNA 3270 to IP TN3270 Conversion =?ISO-8859-1?Q?=96?= Data Stream Encryption
    ... asked them on their thoughts regarding data stream encryption, ... which means that all data is encrypted before it is sent to the client. ... certificate and the keys from three different places: ... SSL client authentication provides additional authentication and access ...
    (bit.listserv.ibm-main)
  • Re: Wireless: Key Confusion
    ... Is the process basically the same if the encryption is WPA? ... The client sends its network access identifier, ... The RADIUS server will respond to the client with its digital ... This tunnel provides a secure data path for client authentication ...
    (microsoft.public.windows.server.networking)
  • Re: 802.1x without encryption ?
    ... I got cisco aironet 1230 with 12.3.. ... I tested some but wasn´t able to achieve unencrypted authentication. ... WPA, by definition, means encryption ... On the Client system, you cannot select WPA, as that only allows TKIP or AES. ...
    (microsoft.public.internet.radius)
  • Re: is pptp via VPN secured ?
    ... i suppose to mak VPN from denver to cairo but i'm wondering is the ... authentication process encrypted using PPTP? ... Also, make sure you have the right encryption for your country, I'm not sure ...
    (microsoft.public.windows.server.networking)