Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > L2TP ppp authentication protocol for ASA 5510

Reply
Thread Tools

L2TP ppp authentication protocol for ASA 5510

 
 
willsmith1701@yahoo.com
Guest
Posts: n/a
 
      04-17-2007
Is anyone using L2TP for remote access connections to an ASA 5510? If
so, what PPP authentication protocol are you using?

Cisco TAC assisted in configuring the L2TP remote access on the ASA,
and configured it with PAP saying that was the only protocol that
would work because the authentication server we are using is Kerberos
(the server is a Windows Active Directory domain controller). I'm wary
of using a protocol that sends the password in clear text. Can this be
right? Shouldn't I be able to use Chap v1 or 2?

The fos version on the asa is 7.2(1). We're using the cli for
configuration.


Any specific suggestions as to how this might be set up with a more
secure authentication protocol would be appreciated.

 
Reply With Quote
 
 
 
 
martin.rublik@gmail.com
Guest
Posts: n/a
 
      04-18-2007
Hi,

this is what worked for me,

tunnel-group DefaultRAGroup general-attributes
password-management

tunnel-group DefaultRAGroup ppp-attributes
no authentication chap
authentication ms-chap-v2

This way you'll enable password change through VPN client. You can
finde more info here http://tinyurl.com/39g646

Regards

Martin

napísal(a):
> Is anyone using L2TP for remote access connections to an ASA 5510? If
> so, what PPP authentication protocol are you using?
>
> Cisco TAC assisted in configuring the L2TP remote access on the ASA,
> and configured it with PAP saying that was the only protocol that
> would work because the authentication server we are using is Kerberos
> (the server is a Windows Active Directory domain controller). I'm wary
> of using a protocol that sends the password in clear text. Can this be
> right? Shouldn't I be able to use Chap v1 or 2?
>
> The fos version on the asa is 7.2(1). We're using the cli for
> configuration.
>
>
> Any specific suggestions as to how this might be set up with a more
> secure authentication protocol would be appreciated.


 
Reply With Quote
 
 
 
 
willsmith1701@yahoo.com
Guest
Posts: n/a
 
      04-19-2007
Martin,

Thanks for the reply, but I'm using the integrated windows l2tp client
with kerberos authentication, not the cisco client with radius
authentication, so I don't think the link you referred me to applies
to my situation.



On Apr 18, 2:55 am, martin.rub...@gmail.com wrote:
> Hi,
>
> this is what worked for me,
>
> tunnel-group DefaultRAGroup general-attributes
> password-management
>
> tunnel-group DefaultRAGroup ppp-attributes
> no authentication chap
> authentication ms-chap-v2
>
> This way you'll enable password change through VPN client. You can
> finde more info herehttp://tinyurl.com/39g646
>
> Regards
>
> Martin
>
> willsmith1...@yahoo.com napísal(a):
>
> > Is anyone using L2TP for remote access connections to an ASA 5510? If
> > so, what PPP authentication protocol are you using?

>
> > Cisco TAC assisted in configuring the L2TP remote access on the ASA,
> > and configured it with PAP saying that was the only protocol that
> > would work because the authentication server we are using is Kerberos
> > (the server is a Windows Active Directory domain controller). I'm wary
> > of using a protocol that sends the password in clear text. Can this be
> > right? Shouldn't I be able to use Chap v1 or 2?

>
> > The fos version on the asa is 7.2(1). We're using the cli for
> > configuration.

>
> > Any specific suggestions as to how this might be set up with a more
> > secure authentication protocol would be appreciated.



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASA 5510 log messages %ASA-4-419002: Duplicate TCP SYN Tilman Schmidt Cisco 5 02-18-2008 12:07 PM
IPSec PIX 501 - ASA 5510 -> log flooded with %ASA-4-402116 Tilman Schmidt Cisco 0 01-24-2008 10:49 AM
4506 acting as LNS with L2TP over IPsec and IPsec over L2TP. AM Cisco 1 02-20-2007 07:20 AM
PPP Authentication with AAA PPP Default records fails Georg Dingler Cisco 3 09-15-2006 11:06 AM
VPN over L2TP patchy connectivity while L2TP Traffic without VPN is fine. Gary Cisco 2 04-24-2005 02:48 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57