Authentic group with and RSA - SIG authentic without Xauth

Hello

I want to migrate my VPN-users (customer dynamics) of the OTP token authentication to certificate-based authentication.

For a while, I'll have two methods of authentication on a VPN-endpoint (PIX).

For the Office of the Prosecutor, there are Xauth against an AAA server.

Now I want my cert users are exempt from Xauth. There is no need for user separate authentic.

See my review of configuration for later use.

===========================================================

access list 101 ip allow a whole

IP pool local VPNpool 192.168.0.0 - 192.168.0.50

vpngroup address pool VPNpool VPNgp

vpngroup idle 1800 rasadmin-time

vpngroup password VPNpass rasadmin

Crypto ipsec transform-set esp-3des esp-sha-hmac VPNts

crypto dynamic-map client 5 101 correspondence address

encryption dynamic-map client game 5 transform-set VPNts

Dynamics-isakmp crypto map 1024 vpn ipsec client

crypto GANYMEDE map vpn client authentication +.

vpn outside crypto map interface

ISAKMP allows outside

part of pre authentication ISAKMP policy 10

ISAKMP policy 10 3des encryption

ISAKMP policy 10 sha hash

10 2 ISAKMP policy group

ISAKMP life duration strategy 10 86400

ISAKMP policy 20 authentication rsa - sig

ISAKMP policy 20 3des encryption

ISAKMP policy 20 chopping sha

20 2 ISAKMP policy group

ISAKMP duration strategy of life 20 86400

===========================================================

How can I exclude Xauth rsa-GIS-users (authentication of the vpn client card crypto GANYMEDE +)?

Only the Group authentication to authenticate with the user name and password in addition to the authentic pré-partagées.

In my tests it seemed to me that Xauth can be enabled or disabled for all isakmp and VPN-groups policies.

Or is it possible to deviate from the policy group, pool, or something else?

I use 6.3 (4) PIX and latest CISCO VPN Client.

Thanks for your advice

Stephan

Unfortunately, as you have understood well enough already, XAuth is enabled at the global level, not by group. If you turn it on for some users, it gets turned on for all, no way around it.

Tags: Cisco Security

Similar Questions

  • Double authentication using LDAP and RSA

    I would use LDAP and RSA (double authentication) for my SSL VPN clients.  Can I authenticated users if my logon page requires users to enter a second username.  If I have the configuration so that they have to enter their username once, no authentication attempt is passed on to the authentication servers.  I'm under debug on LDAP and RADIUS (for RSA), which is what I know that authentication is never over if they are to enter their user name once on the login page.

    If I don't specify "use-primary-username" at the end of the 'secondary-authentication-server-group' command, users must enter their username twice and the authentication is successful.

    Does anyone know how to configure the ASA so that they have to enter their username once while using the LDAP (as principal) and RSA (RADIUS) (secondary)?

    Thanks in advance.

    Matt

    Hi Matt,

    I just tried on 8.3 (2) and it works as expected. I suspect that you are running in this bug:

    CSCte66568    Double authentication broken in 8.2.2 during use-primary-username is CONF.

    If you are running 8.2, upgrade to 8.2 (3) and you shoud be fine.

    HTH

    Herbert

  • Cisco ACS 5.1 and RSA Authentication Manager 6.1

    Hi all

    We recently had a Cisco Secure ACS 1120 and I improved the Unit 5.1 5.0 with all your support

    Now, I need to integrate Cisco ACS 5.1 with RSA Authentication Manager 6.1. I have config file of RSA ACE Server successfully downloaded and exported to 1120 ACS.

    I also added as NetOS Agent ACS in the RSA server during the process, I found a few warnings. The ACE Server is not able to resolve the IP address to the name (is it necessary?).

    I have not created any file of secret key for communication between FAC and RSA and I used encryption is FOR.

    Now, when I log into ACS and search for devices in the identity store sequences I am not able to get Sever Token RSA.

    Let me know what was wrong, where can I fix and also please tell me what is the communciaction between the RSA and ACS?

    Hoping that you guys help me as usual when I'm in a hurry...

    Sree

    Were you able to successfully create the RSA identity server. After selecting the sdconf.rec and you press on submit what happened? The RSA instance created OK?

    If you go to

    Users and identity stores > external identity stores > RSA SecurID Token servers, what do you see in the list?

  • I can't send an e-mail as a group, with or without an attachment, I always get error 0x800CCC0B the message, I have outlook express.

    cannot send error 0x800CCC0B group

    I can't send an e-mail as a group, with or without an attachment, I always get error 0x800CCC0B the message, I have outlook express (not sure which version) under XP, I used to be able to send a group with 500 more emails in it, I tried to narrow the group to 200, but it makes no difference can anyone help?
    Check out this link. Apparently there is a max of 100 recipients simultaneously and they also will disable your account temporarily if you try many times.
     
     
  • I have an ipod touch 128 GB... but I'm almost to reach its maximum.  I want to do is buy a new ipod touch 128 GB and add new music without synchronizing the entire library to it... I have 2 ipods in conjunction with other copies

    I have an ipod touch 128 GB... but I'm almost to reach its maximum.

    I want to do is buy a new ipod touch 128 GB and add new music without synchronizing the entire library to it... I have 2 ipods in conjunction with the other copies of the other.

    is this possible?

    What should I do?

    Matt

    When you get the new iPod, you can use iTunes on your computer to select and synchronize the music you want on it, in the same way that you synchronize your current iPod - your iTunes will recognize them as different devices and will remember your choice of synchronization for each, it will not (unless, for example, you restore the backup of your current on her iPod) put the same content on both.

    (I asked for your post be moved to the iPod Touch forum, where you have posted is the iPad forum use.)

  • I can't send messages, whatsapp for group discussions and I think that is the update of ios software that is not compatible with my iphone 5 s

    I can't send messages, whatsapp for group discussions and I feel really lost. my friends can't receive my message and I am only able to send individual text messages. I think that its because of the version update of ios which is not compatible with my iphone 5 s. is a solution to this problem?

    I have the same problem, started this morning.

    I'm in iOS 9.1, using the iPhone 6. Don't know what happened, but I have also opened a disturbance with Whatsapp support as well.

    A focus group work, group chat messages cannot be delivered. Individual messages are working properly. I tried to remove and reinstall the application, remove the discussion group and recreate, all has not helped.

    A lack of ideas.

  • Programs to freeze or close with and without notice.

    programs to freeze or close with and without notice, that it is not a difference if I'm on the internet or not.  I am constantly notices that a certain program has stopped working and will try to restart.  Sometimes it will be and sometimes not.  Sometimes I also get opinion that something or another can be read at 0xxxxfffff or something like that.  I had these problems all the time I've had this computer.  I tried everything I can think of to fix it without success.  I had my provider ISP here at least three times, I returned the computer to the gateway and had replaced ethernet card, I ran several other registry fixing programs, I've updated all the drivers, I rebooted windows program and started from zero to three times, I took the CPU back instead of purchase (new) they said they could find no problem.  Please help me, I want so badly to take this computer at the door, but I can't afford something different.

    Hi Cherarose,

    I suggest that you contact the manufacturer of the computer and to update the drivers from the chipset and updateBasic system of input/output (BIOS) to the latest version, check if this help.

    BIOS: Frequently asked questions

    http://Windows.Microsoft.com/en-us/Windows-Vista/BIOS-frequently-asked-questions

    Important: Change (CMOS) BIOS/complementary metal oxide semiconductor settings can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the configuration of the BIOS/CMOS settings can be solved. Changes to settings are at your own risk.

    Optimize the performance of Microsoft Windows Vista

    http://support.Microsoft.com/kb/959062

    I hope this helps!

    Halima S - Microsoft technical support.

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Hello! I use a PC and have problems loading my homepage of Muse. First of all, I made one with the address "nordensstjarnor" and updated several times without any problems. And once, I couldn't download on 'nordensstjarnor' any longer. Don't know why, s

    Hello! I use a PC and have problems loading my homepage of Muse. First of all, I made one with the address "nordensstjarnor" and updated several times without any problems. And once, I couldn't download on 'nordensstjarnor' any longer. Don't know why, when he got the address "nordensstjrnor". That me ok at first, but now I really need to give the first address once again, "nordensstjarnor". But when I try, the alternative of the site of ' publish on ' old isn't here. And if I try to create a new one, but with the old URL, the box turns red. What can I do?

    The reason why you cannot change nordensstjarnor.businesscatalyst.com is because a different Adobe ID is used for the publication of this site.

    t * [email protected] is used for the publication of nordensstjarnor.businesscatalyst.com

    t s. * [email protected] is used for the publication of nordensstjarnorindex.businesscatalyst.com

    You must make sure that Adobe ID is used in account publish, so that you can see a list of the websites published under this account. Go in Edition > Preferences > publish on Business Catalyst > publish with accounts

    You can pass the accounts for you can also make changes to the sites.

    Thank you

    Sanjit

  • I just bought the edition student pro Adobe Acrobat XI from amazon. The installation wizard does not recognize my valid serial number. I entered it with and without a hyphen. What should I do?

    I just bought the edition student pro Adobe Acrobat XI from amazon. The installation wizard does not recognize my valid serial number. I entered it with and without a hyphen. What should I do?

    Is the serial number a 24 digit code?

    It is best to contact the Support from Adobe and check with the serial number once:

    "Click the button still needing help, and then select the Chat option:

    https://helpx.Adobe.com/contact.html?step=CCSN_membership-account-payment_account-settings _stillNeedHelp

  • After you download CC Office at the beginning of the installation, I get the error 049. It was the 9th try to install for 1 week - with and without administrative rights.

    After you download CC Office at the beginning of the installation, I get the error 049. It was the 9th try to install for 1 week - with and without administrative rights.

    Hello

    Please see error download or update Adobe Creative Cloud applications

    Hope that helps!

    Kind regards

    Sheena

  • I have a problem with creative cloud applications is not to be downloaded or updated date on my i mac, current applications, I still have work. I uninstalled the cc application and re-installed but without success, in the apps tab there is no error code o

    I have a problem with creative cloud applications is not to be downloaded or updated date on my i mac, current applications, I still have work. I uninstalled the cc application and re-installed but without success, on the applications tab there is no code error only saying download error out area allowing you to charge applications call does not work... any suggestions?

    Hi James,

    Please follow the article: CC help | Download error in the applications tab of Creative Cloud Desktop Application to get this fixed number.

    Please let us know any questions.

    Thank you

    Yann Arora

  • I can't open anything without: "choose which program you want to use to open the file with" and "Application not found".

    I got a used computer and it worked fine for a while. I guess that I did something for her, because now I had a problem with the opening just like files and almost all of the icons in the start menu. I found someone had mentioned this on another post, but it has not been answered and I have the same problem:

    "I don't know what to do. I tried reseting IE back to its "settings by default, but nothing seems to work. It doesn't let me open any programs on my computer. I can't even find the virus because there asking what program I want to open it with and when to choose IE he sent me through a series of 'SAVE or RUN' windows and then back to the "choose a program you want to run the file with.» I am only able to access the internet via a shortcut of Internet Explorer button that I dragged on the start menu, because the original one on my desk does not open. »

    It's the best way I can explain this problem. I've had this problem for a while now and I have looked everywhere for an answer and still nothing. It would be great to get help, thank you!

    After much research, I found the answer here:

    http://WindowsXP.MVPs.org/exefile.htm

    But thanks for the help!

    This problem has not helped me with my problems to download iTunes correctly, that's why I set out to solve this problem in the first place. I also get a lot of it popping up every 10 minutes:

    "MobileDeviceService has encountered a problem and needs to close. We are sorry for the inconvenience. »

    The error signature is always:

    szAppName: AppleMobileDeviceService.exe szAppVer: 17.88.0.8

    szModName: kernel32.dll szModVer: 5.1.2600.5781 offset: 00012afb

    It won't do anything when I click to send error report or not, it does not close anything as it is normally would. I think it might have something to do with the steps I took to reinstall iTunes properly...

    And

    1. I use Microsoft Windows xp Version 5.1, at least that's the stuff I wrote, do not know if this is the answer you're looking for. I am not sure computers.

    2. my anti-virus software is ESET NOD32 Antivirus 4

  • Saving files with and without watermark from photoshop in lightroom

    Hi all

    I have problems with the registration of 2 of the same photo to Photoshop in Lightroom.

    So I opened my image in Lightroom and I change it, I then open in Photoshop and edit the rest of the way.  I then click on save (which places it in Lightroom).  I then went back to Photoshop and add my watermark, which

    I'm having a problem with and then saves this copy.  When I try to save the watermark image will replace the photo that I just saved which is a not the mark of the water, so instead of having all 3 (original, edit and edit watermark) I will have only 2.  How I can save the final edit, then save it again with the watermark that both end in lightroom?

    Hope that makes sense, I just downloaded them so that they are of the most recent edition.

    Thank you

    Hi JaydeWinkworth,

    Once you have finished editing your images in Lightroom, you can right click on the Image to change in Photoshop.

    Once you have plenty of Image in Photoshop, you can apply all the editing (including the watermark) and save it, once you save the images that he goes back to Lightroom as PSD or tiff (separate Image)

    Reference: Adobe Photoshop Lightroom Help | Editing photos Lightroom in Photoshop or Photoshop Elements

    It will be useful.

    Kind regards

    ~ Mohit

  • ASA and RSA SecurID

    Hello

    I have a question about Cisco AnyConnect and RSA SecurID.

    I need to define users to groups in the RSA SecurID server.

    When I try to create a profile and a group of tunnel and then authenticate with the server RSA I just see the user name.

    Successful AAA user authentication: server = 10.210.x.x: user = test

    I need the group name(for authorization) with name tunnel user to send to the RSA server.

    Successful AAA user authentication: server = 10.210.x.x: Group = tunnel: user = test

    There are good documents on this subject?

    You can create groups for some external user databases maps based on the combination of the external user database groups to which users belong. The following types of data are the types of database external user for which you can create group maps based on membership in a group together:

    Windows domains.

    Generic Lightweight Directory Access Protocol (LDAP).

    The following URL can help you in the group mapping configuration:

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.0/user/guide/QG.html#wp940457

  • IOS anyconnect vpn group lock and user restrictions

    Dear Experts,

    I now have two questions about cisco IOS vpn on ISR G2:

    1 is it possible to lock user group in IOS anyconnect VPN we can do in ASA? If so, can someone share the steps for her?

    2 - a customer wishes to restrict the anyconnect user login as it might turn the connection to the user on request. That is to say whenever the user wants to connect via vpn to ask the administrator to allow connection. can we do without deleting the username and create again?

    the other may be on ASA or IOS.

    Please see this guide:

    http://www.Cisco.com/c/en/us/support/docs/security/iOS-easy-VPN/117634-c...

    As he points out, "for the Cisco IOS group-lock and the ipsec: use vpn-group, it only works for IPSec (the easy VPN server)." In order to group-lock specific users in specific contexts of WebVPN (and strategies Group attached), authentication domains should be used. »

    If you lock a user to a policy that authenticates, but does provide real access permissions (say an ACL that blocks all traffic to the private network) then you have essentially made their ability to non-functional connection.

    If you use an external AAA server (for example, RADIUS or LDAP), then you can move in and out of the group which is authorized without disable VPN access / delete their account altogether.

Maybe you are looking for

  • 2 Air 10 iOS iPad dropping wifi

    I have an iPad 2 air in perfect condition, since it first came out. I have the cell phone/Wifi version with Verizon. My problem has been lately, when connected to wifi, the wifi shuts on the iPad many times when using, and more so at rest. Did somebo

  • Focus between two applications

    Hello I work with both applications at the same time, which is made with CVI and the other not (e.i. Explorer). The application made with CVI every 20 seconds displays a new Panel and take focus (hence the other app lose focus), but I would still kee

  • Windows Update error Code 80070663

    With the help of Ultimate and can not download patch PowerPoint published yesterday.  Using Office Pro 2007.  Continue to receive the update failed due to the error Code 80070663, Windows Update encountered an unknown error.  Have not been able to fi

  • not accepting CD/dvd driver not disk

    When I try to put a disk in my laptop, it spits out either back out or going in and out without reading the disc. What should I do?

  • Bluetooth on Dell place 8 Pro Running Windows 10 Technical Preview

    Hey I installed this last night and I'm pretty happy with it; wonder how 'done' experience currently is only the preview software. Read some negative reports how he is more Office-oriented now, but I'm when even love. Almost everything works - even m