Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > VPN3000 Question

Reply
Thread Tools

VPN3000 Question

 
 
Steve Ray
Guest
Posts: n/a
 
      06-25-2007
Guys

I'm setting up a VPN3000 Series VPN concentrator

I have initially setup the user authentication on the unit itself, this was
done as we had less than 20 users on the unit who were test bedding the
system

I have now offered this service out to around 1000 of users users and have
come in work today with over 100 requests for this service (allowing them to
work from home)

I've noticed that under the authentication settings I can allow "Windows
NT", it looks like the settings are looking for an AD server

My question is:

If I change the settings in the authentication box to point to "Windows NT"
do I immidiatley lose the users (and passwords) in the VPN server or if I
decide that I have chosen the wrong option and I change it back will I still
have these users and not have to re-create all the users again

I'd be interested in trying this but do want to "just try" incase I
seriously upset my userbase

TIA

Steve

 
Reply With Quote
 
 
 
 
Trendkill
Guest
Posts: n/a
 
      06-25-2007
On Jun 25, 8:54 am, "Steve Ray" <nocha...@all.com> wrote:
> Guys
>
> I'm setting up a VPN3000 Series VPN concentrator
>
> I have initially setup the user authentication on the unit itself, this was
> done as we had less than 20 users on the unit who were test bedding the
> system
>
> I have now offered this service out to around 1000 of users users and have
> come in work today with over 100 requests for this service (allowing them to
> work from home)
>
> I've noticed that under the authentication settings I can allow "Windows
> NT", it looks like the settings are looking for an AD server
>
> My question is:
>
> If I change the settings in the authentication box to point to "Windows NT"
> do I immidiatley lose the users (and passwords) in the VPN server or if I
> decide that I have chosen the wrong option and I change it back will I still
> have these users and not have to re-create all the users again
>
> I'd be interested in trying this but do want to "just try" incase I
> seriously upset my userbase
>
> TIA
>
> Steve


Not sure if they will save or not, but you should be able to backup
your user database and config prior to the change and restore
immediately upon issues. Check out that option and let us know.

 
Reply With Quote
 
 
 
 
notaccie
Guest
Posts: n/a
 
      06-26-2007
On Mon, 25 Jun 2007 13:54:40 +0100, "Steve Ray" <>
wrote:

>Guys
>
>I'm setting up a VPN3000 Series VPN concentrator
>
>I have initially setup the user authentication on the unit itself, this was
>done as we had less than 20 users on the unit who were test bedding the
>system
>
>I have now offered this service out to around 1000 of users users and have
>come in work today with over 100 requests for this service (allowing them to
>work from home)
>
>I've noticed that under the authentication settings I can allow "Windows
>NT", it looks like the settings are looking for an AD server
>
>My question is:
>
>If I change the settings in the authentication box to point to "Windows NT"
>do I immidiatley lose the users (and passwords) in the VPN server or if I
>decide that I have chosen the wrong option and I change it back will I still
>have these users and not have to re-create all the users again
>
>I'd be interested in trying this but do want to "just try" incase I
>seriously upset my userbase
>
>TIA
>
>Steve



If you would like to try it out, create another group to test. It
actually works fine. Creating additional groups are easy. Once you
are comfortable, you can then move users into a "production" group as
is convenient.

We didn't use straight AD authentication because we wanted to
strictly authorize who could access our network with the VPN.

If you are an MS AD shop, think about using IAS/RADIUS and create an
AD group that has the users whom you wish to access the VPN. One
nice feature is that RADIUS with expiry allows the remote access user
to change an expired domain password. Very convenient.

We settled on mutual authenticaton with a MS machine or user cert
issued by our internal PKI and the RADIUS authentication. An easy to
understand, two-factor authentication.

good luck.


 
Reply With Quote
 
Steve Ray
Guest
Posts: n/a
 
      06-26-2007
This is great,

I'll give this a go

Steve

"notaccie" <> wrote in message
news:...
> On Mon, 25 Jun 2007 13:54:40 +0100, "Steve Ray" <>
> wrote:
>
>>Guys
>>
>>I'm setting up a VPN3000 Series VPN concentrator
>>
>>I have initially setup the user authentication on the unit itself, this
>>was
>>done as we had less than 20 users on the unit who were test bedding the
>>system
>>
>>I have now offered this service out to around 1000 of users users and have
>>come in work today with over 100 requests for this service (allowing them
>>to
>>work from home)
>>
>>I've noticed that under the authentication settings I can allow "Windows
>>NT", it looks like the settings are looking for an AD server
>>
>>My question is:
>>
>>If I change the settings in the authentication box to point to "Windows
>>NT"
>>do I immidiatley lose the users (and passwords) in the VPN server or if I
>>decide that I have chosen the wrong option and I change it back will I
>>still
>>have these users and not have to re-create all the users again
>>
>>I'd be interested in trying this but do want to "just try" incase I
>>seriously upset my userbase
>>
>>TIA
>>
>>Steve

>
>
> If you would like to try it out, create another group to test. It
> actually works fine. Creating additional groups are easy. Once you
> are comfortable, you can then move users into a "production" group as
> is convenient.
>
> We didn't use straight AD authentication because we wanted to
> strictly authorize who could access our network with the VPN.
>
> If you are an MS AD shop, think about using IAS/RADIUS and create an
> AD group that has the users whom you wish to access the VPN. One
> nice feature is that RADIUS with expiry allows the remote access user
> to change an expired domain password. Very convenient.
>
> We settled on mutual authenticaton with a MS machine or user cert
> issued by our internal PKI and the RADIUS authentication. An easy to
> understand, two-factor authentication.
>
> good luck.
>
>


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
deleting files on VPN3000 lehman.alan@gmail.com Cisco 1 08-22-2005 11:54 AM
VPN3000 LAN-to-LAN tunnel question. terry_zarelli@yahoo.com Cisco 1 06-11-2005 03:12 PM
VPN3000 v4.7 Wil Schultz Cisco 0 03-12-2005 06:25 PM
CISCO VPN3000 - Million Dollar Question Matthew Cisco 1 10-01-2004 04:56 AM
VPN3000, radius: error = -9 ("ENOBUFS") Dietmar Romer Cisco 0 08-02-2004 06:34 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57