RE: Authentication using MS AD [7:74928]

2003-09-08 Thread Georgescu, Aurelian
With AD you will have to use RADIUS to authenticate. If you go straight from the VPN 3005 to the domain controller (using NT domain authentication on the 3005) the domain name is not passed over to the domain controller, that's way it fails. You have to change to RADIUS with expiry authentic

Re: Authentication using MS AD [7:74928]

2003-09-06 Thread Koh Jeff
Hi ppl. I am tryin to made a VPN 3005 to authenticate to a MS AD for remote access users. However, on the bonx's event log, it says invalid password, even thought the password is valid on the domain login. I have even created a new account in the AD but still failed in invalid password. Anyone got

RE: PPP authentication [7:74551]

2003-09-02 Thread Reimer, Fred
e password the remote device used in its encryption process. The access server then encrypts the concatenated information with the newly retrieved password-if the result matches the result sent in the response packet, authentication succeeds." Both routers authenticate each other; it's

PPP authentication [7:74551]

2003-09-02 Thread Kenneth
"ppp auth chap" to the interfaces. However, when doing this, the link becomes more of a flapping link, and, running "debug ppp auth", there is no authentication success. However, if I were to do this: Router2(config)# username Router3 password abc Router2(config)# username

Re: 802.1x authentication - minimal requirements? [7:74563]

2003-08-31 Thread Jeff Ryan
, Jeff ""Jsnatan ^. Jsnasson"" wrote in message news:[EMAIL PROTECTED] > Hi, > > Im new to this list(first post, been watching it for a while though) > I'm having a hard time trying to find the minimal requirements for 802.1x > authentication. > > L

802.1x authentication - minimal requirements? [7:74563]

2003-08-31 Thread Jónatan Þ. Jónasson
Hi, Im new to this list(first post, been watching it for a while though) I'm having a hard time trying to find the minimal requirements for 802.1x authentication. Like what version of Cisco Secure ACS do I need (is 3.0 enough?) Are all switches supported (like 3500XL for example) And what

vpn concentrator authentication [7:72053]

2003-07-09 Thread Ciaron Gogarty
Hi GS, Does anyone know off hand whether you can authenticate a group on a Cisco vpn concentrator (3030) with digital certificates and the user with Secure ID?? So far I can do one or the other as it seems that the although the SDI server authenticates a user it is configured at group level and s

RE: Authentication [7:71977]

2003-07-07 Thread Antero Vasconcelos
Hi. You can use the cisco software ACS. CCO has tips and configs for that software. Antero VAsconcelos -Original Message- From: Alexandre Chaves [mailto:[EMAIL PROTECTED] Sent: segunda-feira, 7 de Julho de 2003 12:45 To: [EMAIL PROTECTED] Subject: Authentication [7:71977] Dear Friends

Authentication [7:71977]

2003-07-07 Thread Alexandre Chaves
authentication. I always do this with Linux (squid). Can I do with Cisco? Can the login data base be in the router or in a radius server? Thanks in advance! Alexandre Chaves Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=71977&

Re: mode enable on aaa authentication [7:70800]

2003-06-18 Thread Frederico Madeira
I4m using radiusd-cistron-1.6.6-2. Frederico Madeira Coordenador de Suporte N. Landim Comircio Ltda PABX: 81. 3497.3029 e-mail: [EMAIL PROTECTED] - Original Message - From: "Jim Wang" To: Sent: Wednesday, June 18, 2003 3:00 PM Subject: Re: mode enable on aaa authenticatio

Re: mode enable on aaa authentication [7:70800]

2003-06-18 Thread Jim Wang
I'm not familiar with Huiwa router. I use a similar command, aaa authentication enable default tacacs+ local, on our routers and it works. What type of AAA authentication server are you using? -Jim Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=7087

Re: Slightly OT: Website Authentication [7:70863]

2003-06-18 Thread John Neiberger
>>>> John Neiberger 6/18/03 9:33:55 AM >>> >When you navigate to a secure website and you get a popup challenge to >authenticate, what type of authentication is this? It doesn't seem like it >would be CHAP or PAP, but it could be a close relative. The par

Re: mode enable on aaa authentication [7:70800]

2003-06-18 Thread Frederico Madeira
Jim, In fact i use huawei router . When i put the command aaa authentication enable default radius local return me incorrect command. Frederico Madeira Coordenador de Suporte N. Landim Comircio Ltda PABX: 81. 3497.3029 e-mail: [EMAIL PROTECTED] - Original Message - From: "Jim

Authentication on Radius server [7:70855]

2003-06-18 Thread Frederico Madeira
-server host ip_rad_server2 radius-server key passwordkey radius-server retransmit 3 aaa-enable aaa authentication ppp default radius local aaa authentication login default radius local tanks. Frederico Madeira Coordenador de Suporte N. Landim Comircio Ltda PABX: 81. 3497.3029

Slightly OT: Website Authentication [7:70863]

2003-06-18 Thread John Neiberger
When you navigate to a secure website and you get a popup challenge to authenticate, what type of authentication is this? It doesn't seem like it would be CHAP or PAP, but it could be a close relative. The particular site I'm interested in (an internal test site) is all HTTPS so I c

RE: mode enable on aaa authentication [7:70800]

2003-06-17 Thread Jim Wang
login to the "enable privileged" prompt directly. "enable options" on ACS have no effect Second Case: Not using "Shell/Exec option", but using "enable options" in conjunction with device "enable" aaa authentication command: -- aaa authentication ena

mode enable on aaa authentication [7:70800]

2003-06-17 Thread Frederico Madeira
i4ve configure my router with aaa authentication. Username and password prompt only in login. I want that prompt in enabel mode than. How i make it ??? Tanks. Frederico Madeira Coordenador de Suporte N. Landim Comircio Ltda PABX: 81. 3497.3029 e-mail: [EMAIL PROTECTED] Message Posted at

Fwd: RE: VPN authentication [7:70186]

2003-06-06 Thread maine dude
: =?iso-8859-1?q?maine=20dude?= Subject: RE: VPN authentication [7:70186] To: Bosco Sachanandani In-Reply-To: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 8bit Content-Length: 1711 X-Converted-To-Plain-Text: from multipart/alternative by Gr

RE: VPN authentication [7:70186]

2003-06-05 Thread Bosco Sachanandani
SDN interface. When the ISDN interface realises that there is a packet for the remote network, it will dial out automatically using the phone number and authentication credentails. No need for any config on the WYSE terminal. BR Bosco -Original Message- From: maine dude [mailto:[EMAIL PROTEC

VPN authentication [7:70186]

2003-06-05 Thread maine dude
dial on demand and connect fully so the user does not see any authentication requests the user request should be done automatically but i cant find how to do that via config unless* brainstorming here* the type should be network instead of client ??? Thanks in advance, Dj

RE: multiple isakmp policies question-No authentication [7:70076]

2003-06-04 Thread Daniel Cotts
>> Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=70076&t=70076 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

RE: multiple isakmp policies question-No authentication [7:70051]

2003-06-03 Thread Mark W. Odette II
authentication [7:70043] Hi.. Sorry me again, I just realise that W2K can act as a RADIUS server, is it true?? I tried to installed cisco CSACS software on my W2K server, it prompt me that another program is using RADIUS port, pls disable it, it means my W2K server come with RADIUS? Where to

RE: multiple isakmp policies question-No authentication [7:70043]

2003-06-03 Thread Richard Campbell
0 >From: Daniel Cotts >To: "'Richard Campbell'" , [EMAIL PROTECTED] >Subject: RE: multiple isakmp policies question-No authentication [7:69996] >Date: Mon, 2 Jun 2003 18:25:38 -0500 > >In the following config RADIUS is used to authenticate the Clients. IIRC &

RE: multiple isakmp policies question-No authentication [7:70034]

2003-06-03 Thread Richard Campbell
act as the RADIUS server to authenticate? (I prefer to authenticate locally in PIX515 without install radius server) >From the config shown below, what is aaa.bbb.ccc.10 ? a IP address of RADIUS server? can we make authentication done locally in PIX515? aaa-server AuthInbound (inside) h

RE: multiple isakmp policies question-No authentication [7:69996]

2003-06-03 Thread Richard Campbell
Hey... thanks.. finally I got response from my PIX515, but it just hang at securing communication channel stage (see below) and it doesn't authenticate the users. What config should I add to point it to my authentication server 192.168.1.201? For your info, my VPN client is install

Problem with RSA ACE SERVER (aka SecureID) authentication for [7:69995]

2003-06-03 Thread d tran
seconds 3600 crypto dynamic-map vpnremote 10 set transform-set set1 set2 set3 crypto map outside 20 ipsec-isakmp dynamic vpnremote crypto map outside client configuration address respond crypto map outside client authentication ACE-SERVER outside interface outside isakmp enable outside isakmp key

RE: Microsoft IAS and VPN 3000/Client Authentication [7:66703]

2003-04-02 Thread Mark W. Odette II
Though I haven't done it myself, you should be able to keep the IAS box (Windows 2000 Member Server) and the NT4PDC Box separate. You're authentication AND access can be defined by the IAS box. You would only need to allow RADIUS Ports... 1645 RADIUS Authentication 1646 RADIUS Acco

Microsoft IAS and VPN 3000/Client Authentication [7:66703]

2003-04-02 Thread kwindancer
Hello All: I'm looking into using Microsoft IAS and Windows NT4 PDC to authenticate VPN client users who are accessinga VPN 3000 concentrator. I want home VPN client users to utilize the NT4 PDC for their login authentication. The VPN 3000 concentrator is located on the outside interface o

Re: OSPF Virtual link authentication - observations [7:65628]

2003-03-18 Thread The Long and Winding Road
ber all the stuff I've read about this over the years. This recent observation tells me that the virtual link is an odd animal that is really part of the transit area. It doesn't quite follow the other OSPF rules. I know what the VL is supposed to do. It links the non adjacent area directly

Re: OSPF Virtual link authentication - observation [7:65628]

2003-03-18 Thread Cisco Nuts
: This works...but why?? I always thought that you had to specify the md5 authentication in the virtual-link cmd. but it appears not so. Here is what did catch my eye: When specifying the md5 key, the VL does use key 1 Ex. Message digest authentication enabled Youngest key id is 1 but when NOT

Re: OSPF Virtual link authentication - observations [7:65628]

2003-03-18 Thread The Long and Winding Road
ber all the stuff I've read about this over the years. This recent observation tells me that the virtual link is an odd animal that is really part of the transit area. It doesn't quite follow the other OSPF rules. I know what the VL is supposed to do. It links the non adjacent area directly

Re: OSPF Virtual link authentication - observations [7:65628]

2003-03-18 Thread Nigel Taylor
djacency". So as you noted it would be safe to say that a virtual-link is governed by the termination points of it's unnumbered p-2-p links. So where your transit-area uses MD5 authentication so must your virtual-link. Alex Zinin's Cisco IP Routing [pg. 489] clearly states that the vir

OSPF Virtual link authentication - observations [7:65628]

2003-03-17 Thread The Long and Winding Road
something like this: ( commands under the ospf process ) area X authentication area X virtual-link y.y.y.y authentication area X virtual-link y.y.y.y authentication-key WORD where X is the non zero area number over which the virtual link transits. In other words, for purposes of structure, the

Re: OSPF Authentication Reference Chart [7:65601]

2003-03-17 Thread The Long and Winding Road
> thanks Chuck , it has cleared my doubts on OSPF authentication. > > ""The Long and Winding Road"" wrote in > message news:[EMAIL PROTECTED] > > For those struggling with OSPF authentication, I have created an OSPF > > authentication reference chart

Re: OSPF Authentication Reference Chart [7:65601]

2003-03-17 Thread NKP
thanks Chuck , it has cleared my doubts on OSPF authentication. ""The Long and Winding Road"" wrote in message news:[EMAIL PROTECTED] > For those struggling with OSPF authentication, I have created an OSPF > authentication reference chart on my web site: > >

OSPF Authentication Reference Chart [7:65601]

2003-03-17 Thread The Long and Winding Road
For those struggling with OSPF authentication, I have created an OSPF authentication reference chart on my web site: http://www.chuckslongroad.info/OSPF_Authentication.htm While visiting, you might also want to read through the essay I wrote on this topic a couple of months back on Groupstudy

ppp authentication problem [7:64682]

2003-03-06 Thread Deepak N
Hi all I am facing a problem in ppp authentication. The configuration is simple. on the serial interface one one end i have the conifguration name#sh run int s1/0 Building configuration... Current configuration : 173 bytes ! interface Serial1/0 ip address 5.5.5.5 255.0.0.0 encapsulation ppp

ospf md5 authentication [7:63580]

2003-02-23 Thread Paul Dong So
Hi all, Here is the another question i came across in the lab When plain text passwd (type 1) is used as ospf authentication, it checks the actual passwd. when md5 (type 2) is used, a wrong passwd was set on purpose, surprisingly the adjacency was still able to be established. Read Doyle book, it

Re: semipermanent connections & radius authentication [7:62526]

2003-02-05 Thread [EMAIL PROTECTED] (Kaj J. Niemi)
Milan, In mail.net.groupstudy.pro, you wrote: > I have problem that when I use local authentication on access-server for ppp > authentication for semipermanent connection, the username that I use where > send to radius server. Can anybody tell me why this happens because it > sh

semipermanent connections & radius authentication [7:62526]

2003-02-05 Thread Milan Jovancic
Hello all, I have problem that when I use local authentication on access-server for ppp authentication for semipermanent connection, the username that I use where send to radius server. Can anybody tell me why this happens because it shouldn't send local username to radius? The aaa model

RE: URGENT: Modem Authentication Failure [7:61292]

2003-01-19 Thread Karagozian Sarkis
HAmid, One thing u can do is, on the ACS/AAA server clear and re-enter the the shared KEY xxx. Qn? have u tried connecting directly into the Console port of 3660 and enter the Local Username , Password. Also are u trying to telnet into the 3660 ? or directly connecting to Console Port ... an

RE: URGENT: Modem Authentication Failure [7:61292]

2003-01-19 Thread Hamid Ali Asgari
Yes, I know. But the problem is that on just one platform I have this problem.(On the 3660s). I have tried replacing the modules (NM-16AMs). Very strange. Any comments? Hamid > Wll Hamid , > The Local means you must be able to use the Local Username xxx and > PAssword yxyxyxyxy on the local

RE: URGENT: Modem Authentication Failure [7:61292]

2003-01-18 Thread Karagozian Sarkis
Wll Hamid , The Local means you must be able to use the Local Username xxx and PAssword yxyxyxyxy on the local router config. as a last resource which is the case now So u shd be able to log in to the router itself, if AAA/ACS is not available. IS this happening on all the routers/Switche

RE: URGENT: Modem Authentication Failure [7:61292]

2003-01-18 Thread Hamid Ali Asgari
Yes, I have guessed that. I created a local account on the router, and still I had the same problem. (Ihave configured aaa for local authentication). Do you know what error code 13 means? ( FAIL (13) ) > HI Hamid, > > This seems to be a password or Username Authentication Failure) >

RE: URGENT: Modem Authentication Failure [7:61292]

2003-01-18 Thread Karagozian Sarkis
HI Hamid, This seems to be a password or Username Authentication Failure) you can try to delete and re-enter the username and password for that group on the ACS/AAA server. Also is there a Firewall before accessing/Authenticating to the ACS server? This is not passing the User Authentication

RE: URGENT: Modem Authentication Failure [7:61292]

2003-01-18 Thread Hamid Ali Asgari
o.com/warp/public/480/tacacs_pppdebug.html > > Martijn > > - -Oorspronkelijk bericht- > Van: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Namens Hamid > Ali Asgari Verzonden: zaterdag 18 januari 2003 8:34 > Aan: [EMAIL PROTECTED] > Onderwerp: URGENT: Modem Authentication Fa

RE: URGENT: Modem Authentication Failure [7:61292]

2003-01-18 Thread mjans001
://www.cisco.com/warp/public/480/tacacs_pppdebug.html Martijn - -Oorspronkelijk bericht- Van: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Namens Hamid Ali Asgari Verzonden: zaterdag 18 januari 2003 8:34 Aan: [EMAIL PROTECTED] Onderwerp: URGENT: Modem Authentication Failure [7:61292] Hi

URGENT: Modem Authentication Failure [7:61292]

2003-01-17 Thread Hamid Ali Asgari
: --- Call Handle failed for Modem 5/2 %LINK-3-UPDOWN: Interface Async163, changed state to up TPLUS: Queuing AAA Authentication request 634 for processing TPLUS: processing authentication start request id 634 TPLUS: Authentication start packet created for 634(testuser) TPLUS

RE: IAS Authentication with Pix 515 [7:61023]

2003-01-14 Thread Greg Owens Jr
Behalf Of Patrick Matthews Sent: Tuesday, January 14, 2003 9:34 AM To: [EMAIL PROTECTED] Subject: Re: IAS Authentication with Pix 515 [7:61023] I used the following document and it worked great - Very easy. Logs all VPN access in both the IAS log files and on the Domain Controller running AD. The 3rd

Re: IAS Authentication with Pix 515 (Disregard) [7:61028]

2003-01-14 Thread Kevin O'Gilvie
I found it.. Thanks, Kevin - Original Message - From: Kevin O'Gilvie To: [EMAIL PROTECTED] Sent: Monday, January 13, 2003 10:16 PM Subject: IAS Authentication with Pix 515 Hi All, Does anyone know how to make IAS use Active directory to authenticate VPN users.. I

Re: IAS Authentication with Pix 515 [7:61023]

2003-01-14 Thread Patrick Matthews
/products_configuration _example09186a00800b6099.shtml ""Kevin O'Gilvie"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Hi All, > > Does anyone know how to make IAS use Active directory to authenticate VPN > users.. > I have the sample from c

IAS Authentication with Pix 515 [7:61023]

2003-01-14 Thread Kevin O'Gilvie
Hi All, Does anyone know how to make IAS use Active directory to authenticate VPN users.. I have the sample from cisco but that only displays local authentication.. Thanks a bunch, Kevin Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=61023&

Re: Revisited - OSPF Authentication - WAS : Tonight's Homily - [7:60321]

2003-01-04 Thread Howard C. Berkowitz
the absence of air. > >In this Augustinian viewpoint, when no area authentication is configured >then what you have is nothing. Which leaves the mystery of interface >authentication and it's purpose. Have you considered, then, the theological significance of the null interface? &g

Revisited - OSPF Authentication - WAS : Tonight's Homily - OSPF [7:60314]

2003-01-04 Thread The Long and Winding Road
area authentication is configured then what you have is nothing. Which leaves the mystery of interface authentication and it's purpose. However, if one takes an anti-Augustinian view, which it appears that the Cisco developers did, then when you read the documentation that states that the de

RE: Tonight's Homily - OSPF authentication - I didn't know [7:60281]

2003-01-03 Thread Kaminski, Shawn G
ject: Tonight's Homily - OSPF authenitcation - I didn't know that! > [7:60275] > > As many of you know, I've been reading Parkhurst's OSPF book for a number > of > reasons. So I'm fooling around in the chapter on interface commands, when > something hits me

FW: ACS Authentication/Auth/Accounting [7:59393]

2002-12-17 Thread John Cianfarani
I'm also assuming you have the actual TACACS+ server configured with the key? tacacs-server host tacacs-server timeout 15 tacacs-server key Also try changing the line to: aaa authentication login default group tacacs+ local To specify going to all T

Re: ACS Authentication/Auth/Accounting [7:59393]

2002-12-17 Thread not enough time to study
ot;>news:[EMAIL PROTECTED]... > Okay I've got my login authentication, authorization and accounting working > on most of my switches and router through a ACS (TACACS+). But I have this > one router that gives me an "% Error in authentication" message as soon as I > pu

RE: ACS Authentication/Auth/Accounting [7:59393]

2002-12-17 Thread Jim Brown
30 PM To: [EMAIL PROTECTED] Subject: ACS Authentication/Auth/Accounting [7:59393] Okay I've got my login authentication, authorization and accounting working on most of my switches and router through a ACS (TACACS+). But I have this one router that gives me an "% Error in authentication&q

RE: ACS Authentication/Auth/Accounting [7:59393]

2002-12-17 Thread Xueyan Liu
Do you have an enable password configured on the router? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=59396&t=59393 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Non

Re: ACS Authentication/Auth/Accounting [7:59393]

2002-12-17 Thread Amer
Yes I do... ""Xueyan Liu"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Do you have an enable password configured on the router? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=59397&t=59393 -- FAQ, list archi

ACS Authentication/Auth/Accounting [7:59393]

2002-12-17 Thread Amer
Okay I've got my login authentication, authorization and accounting working on most of my switches and router through a ACS (TACACS+). But I have this one router that gives me an "% Error in authentication" message as soon as I put in my username. It doesn't even allow me

VDPN authentication based on Caller ID [7:59063]

2002-12-12 Thread Mohamed Elkomy
Dear all, Concerning the VPDN model as far as I know the VPDN authentication can be done using dnis or domain name but what about the caller ID?? Can anyboday help me with this?? is it possible?? and if yes can anybody guide me to some paers that'd help in VPDN configuration based on c

Re: Last Minute Thought - OSPF authentication issue? [7:58352]

2002-12-01 Thread Steven A. Ridder
ate Dead Time Address Interface > 222.222.222.7 1 FULL/DR 00:01:58149.22.4.7 Serial0 > 222.222.222.111 FULL/DR 00:00:38149.22.252.2 Ethernet0 > Router_10# > > interface Serial0 > ip address 149.22.4.10 255.255.255.0 > encapsul

Re: Last Minute Thought - OSPF authentication issue? [7:58352]

2002-11-30 Thread The Long and Winding Road
""Silju Pillai"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Hi, > > I tried this too. I am pasting the results. > > R5# > interface Serial0/2 > ip address 192.168.1.209 255.255.255.252 > ip ospf authentication > ip os

RE: Last Minute Thought - OSPF authentication issue? [7:58352]

2002-11-30 Thread Silju Pillai
Hi, I tried this too. I am pasting the results. R5# interface Serial0/2 ip address 192.168.1.209 255.255.255.252 ip ospf authentication ip ospf authentication-key cisco router ospf 10 log-adjacency-changes area 0 authentication network 30.30.30.0 0.0.0.255 area 0 network 192.168.1.208

Recall: Last Minute Thought - OSPF authentication issue? [7:58355]

2002-11-30 Thread Vicuna, Mark
Vicuna, Mark would like to recall the message, "Last Minute Thought - OSPF authentication issue? [7:58352]". Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=58355&t=58355 -- FAQ, list archives, and subsc

RE: Last Minute Thought - OSPF authentication issue? [7:58352]

2002-11-30 Thread Vicuna, Mark
30, 2002 8:03 PM To: [EMAIL PROTECTED] Subject: Last Minute Thought - OSPF authentication issue? [7:58352] check this out. R10 -- Neighbor ID Pri State Dead Time Address Interface 222.222.222.7 1 FULL/DR 00:01:58149.22.4.7 Serial0 222.222.222.111 FULL

Re: Last Minute Thought - OSPF authentication issue? [7:58352]

2002-11-30 Thread Henry D.
It would seem you wanted to use md5 authentication but you used plain text authentication keys. In this situation - when there are no md5 authentication keys specified - I think the routers will use null key, meaning no authentication will take place... ""The Long and Winding Road&q

Last Minute Thought - OSPF authentication issue? [7:58352]

2002-11-30 Thread The Long and Winding Road
149.22.4.10 255.255.255.0 encapsulation frame-relay no ip route-cache ip ospf authentication message-digest ip ospf authentication-key 7 qwertyzzyzx R7 - Neighbor ID Pri State Dead Time Address Interface 222.222.222.101 FULL/BDR00:01:57149.22.4.10

Re: RADIUS Authentication [7:54628]

2002-10-02 Thread Robert Edmonds
to configure the MSFC2 on my 6506 to use RADIUS authentication > from my Windows 2000 Server. What I would like is to have the MSFC > authenticate users using the RADIUS server on login. I would also like a > backup account locally in case RADIUS authentication is not available. If &

RADIUS Authentication [7:54628]

2002-10-01 Thread Robert Edmonds
I am trying to configure the MSFC2 on my 6506 to use RADIUS authentication from my Windows 2000 Server. What I would like is to have the MSFC authenticate users using the RADIUS server on login. I would also like a backup account locally in case RADIUS authentication is not available. If it is

Re: chap authentication LONG !!! [7:54234]

2002-09-27 Thread Russell Heilling
""Magondo, Michael"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Russell > > Are you saying that CHAP is not capable of one way authentication?? And > to do this one has to use PAP??? Almost, but not quite... CHAP can operate in 2 mo

RE: chap authentication LONG !!! [7:54234]

2002-09-27 Thread Magondo, Michael
Russell Are you saying that CHAP is not capable of one way authentication?? And to do this one has to use PAP??? Michael -Original Message- From: Russell Heilling [mailto:[EMAIL PROTECTED]] Sent: 27 September 2002 12:10 PM To: [EMAIL PROTECTED] Subject: Re: chap authentication LONG

Re: chap authentication LONG !!! [7:54234]

2002-09-27 Thread Arni V. Skarphedinsson
Ok I have tested this and got it to work with out the dual usernames on bouth router, as I was talking about in the previous post but that still leves my orginal question, and if any one can see anything from the debug, that would be great. Message Posted at: http://www.groupstudy.com/form/re

Re: chap authentication LONG !!! [7:54234]

2002-09-27 Thread Arni V. Skarphedinsson
Ok thanx for the explanation to get this 100% I just have one more question If I am calling an ISP Router 1 has in its config dialer 0 ppp authentication chap calli ppp chap hostname bla ppp chap password bla1 and that works to authenticate to the ISP router, but as chap is two way, do I

Re: chap authentication LONG !!! [7:54234]

2002-09-27 Thread Russell Heilling
any hostname or password to put in my router to authenticate the > ISP router > > Or do I What you are describing is what happens in PAP authentication (as used with most single user dial ISP accounts), with CHAP *both* routers need to authenticate with each other, so you will need to pu

Re: chap authentication LONG !!! [7:54234]

2002-09-27 Thread Arni V. Skarphedinsson
Do I have to have the hostname of each router in each other, if I am calling an ISP I just get a username and password, that I send the ISP router, I dont get any hostname or password to put in my router to authenticate the ISP router Or do I Message Posted at: http://www.groupstudy.com/fo

Re: chap authentication LONG !!! [7:54234]

2002-09-26 Thread dildog
I just spent a second reading the debug... did you put the hostname of each router in the other and use the same password? In reference to: > 00:03:55: BR0:1 CHAP: Username jal-3660 not found Also verify that multilink and ppp authentication chap are set in both. - Original Mess

Re: chap authentication LONG !!! [7:54234]

2002-09-26 Thread Arni V. Skarphedinsson
It´s my understanging that when I use ppp authentication chap callin i dont have to have the username on my router, as if I was calling into an ISP then the ISP´s route would have to have a username on my router, and I dont think that is the that is used. Message Posted at: http

Re: chap authentication LONG !!! [7:54234]

2002-09-26 Thread MADMAN
looks quite similiar to a recent thread. username jal-3660 password blahblahblah remember CHAP is a two wat authentication. Dave "Arni V. Skarphedinsson" wrote: > > Well I have some more chap authentication issues, and if someone can give me > any pointers that wou

chap authentication LONG !!! [7:54234]

2002-09-26 Thread Arni V. Skarphedinsson
Well I have some more chap authentication issues, and if someone can give me any pointers that would be great, I have two routers a 1003 who is calling an 3660 over ISDN this is the debug from the 100300:03:54: %LINK-3-UPDOWN: Interface BRI0:1, changed state to up 00:03:55: %DIALER-6-BIND

RE: PPP authentication problem [7:54047]

2002-09-26 Thread Arni V. Skarphedinsson
The thing is that is I am calling an ISP so I have no control over the router I am calling into, I cant use that routers hostname as a username as I have an account there with a username that I have to use, and the problem seems to be sending that username to the ISP router.. Message Posted at:

RE: PPP authentication problem [7:54047]

2002-09-25 Thread [EMAIL PROTECTED]
: Wednesday, September 25, 2002 6:12 AM To: [EMAIL PROTECTED] Subject: PPP authentication problem [7:54047] I am having problems with a ISDN router calling into an ISP, the CHAP authentication is not sending the correct username. the debug i get PPP BRI0:1: CHAP challenge from 3640 00:10:21: PPP

Re: PPP authentication problem [7:54047]

2002-09-25 Thread Scott
Do you have the following on the router giving the error: username 3640 password ""Arni V. Skarphedinsson"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > I have already tried using ppp authentication chap callin, and that does not > change

RE: PPP authentication problem [7:54047]

2002-09-25 Thread Arni V. Skarphedinsson
I have already tried using ppp authentication chap callin, and that does not change anything yes the IP unnumberd is just there for testing, as this router I am using can not do IP address negoitedted, and NAT but the production router will be able to. Could that be the issue, from the debug

RE: PPP authentication problem [7:54047]

2002-09-25 Thread ORiordan Brian
Hi Arni, The one thing to note about CHAP is that the Authentication process is bi-directional. That is to say that, in a normal CHAP Setup your Router will send a USERNAME/PASSWORD combination to the Remote End and the Remote End will send a USERNAME/PASSWORD combination to your Router. This is

PPP authentication problem [7:54047]

2002-09-25 Thread Arni V. Skarphedinsson
I am having problems with a ISDN router calling into an ISP, the CHAP authentication is not sending the correct username. the debug i get PPP BRI0:1: CHAP challenge from 3640 00:10:21: PPP BRI0:1: USERNAME 3640: lookup failure. 00:10:21: PPP BRI0:1: Unable to authenticate for peer. it always

Re: OSPF Authentication with one Spoke only.... [7:53366]

2002-09-18 Thread Erick B.
u guys! How do I > enable ospf md5 > authentication in a hub and spoke multipoint > network. > > I need authentication between a single spoke and the > hub. I do not want auth > between the same hub and the 'other spoke'. Remember > this is

Re: EIGRP authentication. [7:53513]

2002-09-18 Thread Brian Liu
I am trying this in the lab, so... "clear ip route *" doesn't work. I have tried clearing both the "neigh" and the "route", no effect at all. The way I can make authentication works is configure it from the beginning, before Router A and B ha

Re: EIGRP authentication. [7:53513]

2002-09-17 Thread Dain Deutschman
rect me if that is the case. Dain. ""enginedrive2002"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > If Router A and Router B are connected using serial interface, both of them > are running EIGRP. > > On Router A, I have config

Re: EIGRP authentication. [7:53513]

2002-09-17 Thread enginedrive2002
"clear ip eigrp nei" doesn't work for me. Router A and B can still see each other and send the routing update. Looks like this problem only exist when Router A and B is already running EIGRP and you want to add the authentication later. When I configure the Router A with authenti

RE: EIGRP authentication. [7:53513]

2002-09-17 Thread ccie fan
Configuration basically correct on router A side. Can you try a 'clear ip eigrp nei' and see what happen? I have experience I have to apply this config in router twice to get it work. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=53517&t=53513 --

EIGRP authentication. [7:53513]

2002-09-17 Thread enginedrive2002
If Router A and Router B are connected using serial interface, both of them are running EIGRP. On Router A, I have configure "ip authentication mode eigrp AS# md5" and "ip authentication key-chain eigrp AS# " under interface configuration mode, also configure the "key c

NTP and Authentication [7:53088]

2002-09-11 Thread [EMAIL PROTECTED]
Hello Everbody, >From what I have seen, no matter what key or md5 authentication key you configure (different in both sides), a client router will synchronize with its server router. I did not find a Cisco URL saying that MD5 authentication is just for Symmetric Active/Passive Mode mode, s

Re: RIP v2 authentication [7:52647]

2002-09-03 Thread Nigel Taylor
Kelly, What does the debug of the RIPv2 MD5 error look like? Trying posting it (the debug of the authentication, I mean) to the list, I'm sure someone have seen the error before and can let you know if you've missed anything other than what you might have already cover

RE: OSPF virtual link authentication [7:52238]

2002-08-28 Thread James Johnson
Darn, left off the area 0 thing. Knew it was something simple. Thank you. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=52254&t=52238 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report

RE: OSPF virtual link authentication [7:52238]

2002-08-28 Thread Roberts, Larry
Remember that the virtual link is part of area 0, so did you do area 0 authentication message-digest? Also how did you specify the key.. Router ospf 100 Area 0 authentication message-digest Area X virtual-link a.b.c.d message-digest-key 1 md5 password This must be on both routers. I am

OSPF virtual link authentication [7:52238]

2002-08-28 Thread James Johnson
My OSPF link will not come up. I'm trying to do MD5 authentication across a virtual link. I thought there was a trick to this but I can not remember. Any help? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=52238&t=52238 -

RE: AAA Authentication [7:51668]

2002-08-19 Thread Maccubbin, Duncan
No problem, this will explain it(watch the wrap): http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secu r_c/scprt1/index.htm -Original Message- From: Robert D. Cluett To: [EMAIL PROTECTED] Sent: 8/19/02 4:29 PM Subject: AAA Authentication [7:51668] I am going to

AAA Authentication [7:51668]

2002-08-19 Thread Robert D. Cluett
I am going to install some sort of accounting and privlidge managment on an access server. Essentially I want to restrict certain commands from being used and log the amount of time that a user has used the system. Is there a method or application that will best suit this? Message Posted at:

  1   2   3   >