Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > PIX515E VPN IPSec Local User Authentication

Reply
Thread Tools

PIX515E VPN IPSec Local User Authentication

 
 
Matt
Guest
Posts: n/a
 
      04-15-2004
We have a PIX515E firewall and have IPSec VPN set up (using vpngroup)

We are trying to set up user authentication for 4 users, however, we
do not went to set up a radius server for a handful of accounts (nor
do we want one group/group password for everyone)

From what I can tell, we can set up local users (in the PIX
configuration) using PPTP authentication but not IPSec.

Is there some way to create seperate user/passwords in the pix
configuration without configuring multiple IPSec VPN groups?

In addition, is there a way to set static VPN ip addresses for users
so that we can set up seperate access-lists per user?

Again, we are trying to stay away from using RADIUS or TACACS+ for
simplicity purposes.

Thanks.

- Matt
 
Reply With Quote
 
 
 
 
Chad Mahoney
Guest
Posts: n/a
 
      04-15-2004
Matt wrote:
> We have a PIX515E firewall and have IPSec VPN set up (using vpngroup)
>
> We are trying to set up user authentication for 4 users, however, we
> do not went to set up a radius server for a handful of accounts (nor
> do we want one group/group password for everyone)
>
> From what I can tell, we can set up local users (in the PIX
> configuration) using PPTP authentication but not IPSec.
>
> Is there some way to create seperate user/passwords in the pix
> configuration without configuring multiple IPSec VPN groups?
>
> In addition, is there a way to set static VPN ip addresses for users
> so that we can set up seperate access-lists per user?
>
> Again, we are trying to stay away from using RADIUS or TACACS+ for
> simplicity purposes.
>
> Thanks.
>
> - Matt

Matt,

You can setup a vpn group for each user. Each group would have its own
password.


Chad
 
Reply With Quote
 
 
 
 
Mark Green
Guest
Posts: n/a
 
      04-15-2004
(Matt) wrote in message news:< >...
> We have a PIX515E firewall and have IPSec VPN set up (using vpngroup)
>
> We are trying to set up user authentication for 4 users, however, we
> do not went to set up a radius server for a handful of accounts (nor
> do we want one group/group password for everyone)

You can use local authentication
with:
"aaa-server LOCAL protocol local"
and
"crypto map outside_map client authentication LOCAL"
(but you still needs the vpngroup password)
then just open users with privilege 0 on the pix:
"username youruser password xxx privilege 0"

>
> From what I can tell, we can set up local users (in the PIX
> configuration) using PPTP authentication but not IPSec.
>
> Is there some way to create seperate user/passwords in the pix
> configuration without configuring multiple IPSec VPN groups?


>
> In addition, is there a way to set static VPN ip addresses for users
> so that we can set up seperate access-lists per user?
>
> Again, we are trying to stay away from using RADIUS or TACACS+ for
> simplicity purposes.
>
> Thanks.
>
> - Matt

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
PIX515E Ipsec vpn can't access local hosts Tony2Time Cisco 0 06-23-2011 02:01 AM
Configure Cisco PIX515e PPTP VPN Clients to allow access to another network across a IPSEC Tunnel ashley.lawrence@gmail.com Cisco 2 08-22-2007 08:32 PM
how to config more than one site-to-site VPN in my PIX515E Benson Cisco 3 04-23-2005 02:00 PM
VPN Question on a PIX515E K Cisco 1 02-23-2005 03:23 PM
PIX515E configuration for VPN & Internet access Benson Cisco 3 10-21-2004 03:23 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57