Hub - Backup for authentication of users

Users in the Group should be authenticated through RADIUS. Therefore, I put the ipsec authentication to RADIUS. Everything works fine, but when the RADIUS server is not accessible, users cannot connect through the hub.

In this case, the hub must switch on the internal server process. Is this possible?

Thank you

Edgar

Once you set up a group to use Radius Authentication, then it will only use the Radius Authentication, it will not fail during theInternal of database failure.

What you can do is to set up a second Radius server in the hub, and if it is not answer first that there are failed over and try the second. As I said though, it will not failover to a different authentication mechanism.

Tags: Cisco Security

Similar Questions

  • Cisco VCS and LDAP for authentication of users

    I have a question about setting up LDAP for authentication of the user on the VCS. I want to have redundancy in my LDAP link. I believe that this is possible by setting a FULL domain name to the address of the LDAP server, then selecting a type of SRV resolution. What I'm not clear on is what the value for the server address would be if I used actually as SRV type of resolution. I should also add that I am looking to use TLS

    To clarify, if my AD domain name is myad.netcraftsmen.net. I have set the field as server address:

    myad.netcraftsmen.NET: assuming that VCS properly interrogate the DNS for the _service._proto correct parameters?

    or would I need to create an SRV record to that effect and set the field server address with the address (including the fields of _service._proto)

    or I need to specify one of the SRV records formats used by MS AD areas (there are several).

    If the latter, then what SRV record for TLS. I don't see records with port 389 (non-secure).

    My intuition tells me that this is probably the first option, but I could be far away.

    Anyway, thanks in advance for any input.

    Kind regards

    Bill

    Hi William,.

    I just checked it on a X6.1 VCS, and it seems that VCS searches SRV _ldap._tcp.domain (where 'domain' has been entered as the server address), both when the encryption is set to 'None' and 'TLS '.

    Hope this helps,

    Andreas

  • How Anyconnect VPN users will connect with cisco ASA, which uses the server (domain controller) Radius for authentication

    Hi team

    Hope you do well. !!!

    currently I am doing a project which consists in CISCO ASA-5545-X, RADIUS (domain controller) server for authentication. Here, I need to configure Anyconnect VPN and host checker in cisco asa.

    1 users will connect: user advanced browser on SSL VPN pop past username and password.

    2. (cisco ASA) authentication: VPN sends credentials to the RADIUS server.

    3 RADIUS server: authentication: receipt and SSL VPN (ASA) group.

    4 connectivity creation: If employee: PC so NAW verified compliance, no PC check Assign user to the appropriate role and give IP.

    This is my requirement, so someone please guide me how to set up step by step.

    1. how to set up the Radius Server?

    2. how to configure CISCO ASA?

    Thanks in advance.

    Hey Chick,

    Please consult the following page of installation as well as ASA Radius server. The ASA end there is frankly nothing much difference by doing this.

    http://www.4salesbyself.com/1configuring-RADIUS-authentication-for-webvp...

    Hope this helps

    Knockaert

  • Reliable backup for Mac?

    Hi all

    I wish I had a solution for online backup for my mac, since I don't trust so that site comments more that increasingly are biased, I would rather ask my other consumers based on their experience!

    What are the reliable online backup solutions for Mac users out there?

    Features, I would love to find:

    -Backup crypted

    -Files/backups scanned and protect with antivirus and antimalware systems

    -Reliable in the sense that it is 200% of course, proven and protected that they will not share or disclose my data and they have secure servers

    -If possible, accessible from a Windows computer in case I need it

    I was thinking about everything that I wanted to put backup password protected DMG files (which are encrypted right?) and then upload to Google Drive, since at least Google servers should be online forever almost, but you are limited to 15 GB per account, anyone has any experience with the help of Google?

    Thank you!!

    The problem with online backup killer, is it will take perhaps as long as three days for any transfer out or or on your Mac. It is simply not practical.

  • Firefox doesn't show popup for authentication

    I use firefox for internet access through my University proxy. I type my password and my user account.
    Recently, firefox does not show the popup for authentication, where I type my user account and my password, so I can't access my network of the University. I have not changed the proxy configuration (I checked it, it's as it should be).
    When I try to access any Web site, I get the message "access to the cache of refused" and it says that I have to authenticate to access. However, there is no authentication window to enter my user account and password.
    I tried to configure Chrome and Safari, and they worked perfectly.
    My computer is a mac running the mavericks.

    See:

    In Firefox 30 and later NTLMv1 auth has been disabled, NTLM supported on platforms other than Windows is now obsolete

    In Firefox 31 for NTLMv1 auth has been restored to only secure connections (Bug 1023748).

    • Network.Negotiate - auth.allow - insecurity-ntlm-v1 = false
    • Network.Negotiate-auth.allow-insecure-NTLM-v1-https = true
    • bug 1023748 - Allow NTLMv1 via SSL/TLS or intranet access is broken on Firefox 30 for platforms other than Windows
  • Restoration of an IPad 2 for a new user

    I want to give my IPad2 my husband without my data. I have new IPad that includes the data I want my old. How to restore the old to its original settings? I'm afraid of losing my songs, photos, etc. from my new IPad Pro.

    Hello

    Now access iCloud backup

    Then turn off find my ipad, and then restore it back to factory settings ipad.

    This removes you ipad apple ID is now ready for the new user.

    Make sure that your husband has its own apple ID.

    See you soon

    Brian

  • Manual backup for PC. message "there is not enough free space.  My last backup is 1.3 GB, 124 GB available, without encryption.

    Manual backup for PC. message "there is not enough free space.  My last backup was 1.3 GB, four weeks ago.   My disc is 256 GB total with more than 162 GB available.  I do not use encryption. I am running windows 10 with 4 GB of memory system, iOS 9.2.1 and iTunes 12.3.2.35.  The only thing that has changed to realIy is the latest update to iTunes. I found this page and tried the steps.

    If you are unable to make a backup of your iPhone, iPad or iPod touch - Apple Support iTunes

    I cleaned my recycling, did the reboot of my iPhone 5 s and my computer, disconnect all devices except iPhone and mouse, checked my security software (off), reset the lockdown folder.  Uninstalled/reinstalled iTunes 12.3.2.35.  No joy.

    I can do the manual backup on the PC of my wife, and she has more than 500 GB of available and uses the same version of iTunes, but on Windows 7.  Any ideas?

    Is the part of the computer which, by default, stores the backup on a smaller partition by accident?

    The part is \Users\yourusername\appdata\roaming\apple computer\mobilesync\backup.

    If this is not the case, the other thing I guess try would be to temporarily move the backups that exceed in this folder there and test if the prior backup is the problem of not being able to back up now.

  • Can't backup windows because Backup has encountered a problem during backup of the C:\Users\marcel\Documents\Youcam file. Error: (the system cannot find the specified file. (0 x 80070002))

    can not backup windows because: Backup has encountered a problem during backup of the C:\Users\marcel\Documents\Youcam file. Error: (the system cannot find the specified file. (0 x 80070002))
    Backup has encountered a problem during backup of the C:\Users\marcel\Documents\Youcam file. Error: (the system cannot find the specified file. (0 x 80070002)).

    Maybe it's because I disabled the camera to prevent other people using the computer?

    [Moved from comments]

    Hi Marrcel,

    Thank you for keeping us posted.

    The issue can be due to turning the camera off. I suggest you to activate the camera and try.

    Please come back for any clarification on this or any issue of Windows. We will be happy to help you.

  • I'm currently having a batch file. I need to enable authentication of users can u it... Please tell me how I can run?

    I'm currently having a batch file. I need to enable authentication of users can u it... Please tell me how I can run?

    the in-house batch file calls a few .jar files... the requirement is I need to restrict who uses this batch file.
    I can either store the user name and password in a separate file or...
    Please suggest me... Thanks in advance.

    Hi Alexander,.

    Your question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please ask your question in the following forum.

    Windows XP IT Pro category

  • Vista Backup utility, is by user or it saves ALL user data?

    I don't speak of the "Files backup" utility in Vista, not the "Complete PC Backup" utility.

    I am the admin, the rest are "standard" users It backup for all users when I run it as an administrator?

    I read the help files, but there is no mention. Thank you.

    Hi MalG,

    He will back up all your user accounts.

  • Windows 7 backup error: "backup Windows ignored C:\Users\... because it's on corrupt C:\ drive.»

    Hello

    I bought a new computer recently with Windows 7 installed and regularly use Windows backup since my purchase with no problems.  However, a couple of days, I tried to backup my system and received a message saying that the backup completed, but some files were ignored.  As soon as the journal view, that's what I find:

    Windows skipped C:\Users\Jonathan\Documents backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Public\Documents backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Music backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Public\Music backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Pictures backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Public\Pictures backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Videos backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Public\Videos backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\AppData\Roaming backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\AppData\Local backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\AppData\LocalLow backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Contacts backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Desktop backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Downloads backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Favorites backup because it is about corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Links backup because it is about corrupt C:\ drive.
    Backup Windows ignored C:\Users\Jonathan\Saved games as it is on corrupt C:\ drive.
    Windows skipped C:\Users\Jonathan\Searches backup because it is about corrupt C:\ drive.

    It seems that Windows Backup jumped basically every valuable piece of data on my PC.  I did a search for answers and it seems that when people have this problem backup Windows still do not know the same libraries (pretend to prove that it is not a problem of material with the HARD drive). and the only suggestion I could find was to run the chkdsk utility, then attempt a backup again.  I have since run the utility chkdsk twice and it found no errors, and I continue to have this problem when you save.

    Beyond running the chkdsk utility and reboot for a third time, can anyone help?

    Thanks in advance.

    I think that this is the case because of a virus (incase your pc is not protected or a new threat has developed).

    Please install an antivirus.
    I suggest Microsoft Security Essentials.Scan all the files and then try again.
    Or try freeing up space on the drive you store the backup in the c DRIVE.
    or try to move your important files to an external USB key or hard drive and format your pc :)
    That will solve almost all your problems.
    In case you need help with anything else or this does'nt resolve your problem, mail me or reply to this post of mine.
    Nanou NASH.
    The computer assistant.
  • is it possible to make the machine and authentication of users in the same permission profile?

    Hello

    I want to know is - it possible to machine authentication authentication of users arrive at the same time? Something like that...

    Condition

    IF (wired_802.1x and AD:externalgroup computer dommain EQUAL AND Some_domain_user_group EQUAL AD:exteranalgroup)

    Permissions

    then Vlan x

    Basically, I'm just checking a machine in the domain and user is valid only while he should be able to have full access.

    Any help will be of great value.

    Hello

    IF (wired_802.1x and AD:externalgroup computer dommain EQUAL AND Some_domain_user_group EQUAL AD:exteranalgroup)

    -Not possible

    As the authentication of the user and the machine occur in different contexts.

    ACS cannot check them both at the same time.

    With the help of MAR, you can, although club together and reach:

    "machine is part of the domain and user is valid only while he should be able to have full access"

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/users_id_stores.html#wp1235978

    Tips for MAR configuration:

    (1) set the client to authenticate user or computer.

    (2) create two rules in the authorization for the user and and the other for the machine (identity them using the ad group membership).

    (3) enable MAR on the AD on ACS configuration page and set the aging time.

    (4) in rule user, customize and use the condition "Has been authenticated machine" and the value is false.

    Rate if useful

  • ACS 5.4 ASA 8.2.5 disable AAA for the particular user

    Hello!

    I want to disable journaling Ganymede + for the particular user. This user is used only for automated (python script) pooling of vpn tunnel ASA (limited command set - permission on ACS) group to verify the number of users authenticated via VPN. The problem is that this user generate a bunch of logs according to authentication authorization and accounting on ACS. Is there a solution, disable Ganymede + newspapers on ACS for this particular user? Maybe it is possible to modify the AAA on ASA to not connect this particular user?

    Thanks in advance.

    Hi Pawel,

    You can create filters collection for that specific user. When you configure monitoring filters & Report Viewer does not record these events in the database.

    Navigate to: Configuration of the analysis > System Configuration > filters Collection > add a filter

    What follows is the attributes that can be used. You must use the user.

    -Access service

    -User

    -Mac-add

    -Nas - IP

    Example: We get several hits of ASA by 'user' and we want ACS to ignore it. Create a filter by using the user. ACS must now ignore any attempt from the IP Address of the NAS.

    Jatin kone
    -Does the rate of useful messages-

  • several hosts aaa server for authentication vpn

    ASA5510 - 7.2 (1)

    Using the following configuration, I try to have several radius servers configured for authentication backup in case of failure of the primary vpn. This seems to work ok. But once the main server upward when the asa will begin to use it again. The release of "aaa-Server 172.25.4.20 host" said

    Server status: FAILURE, server disabled at 08:04:25.

    How do reactivate you it?

    RADIUS protocol AAA-server adauth

    adauth AAA-server 172.25.4.20

    key *.

    authentication port 1812

    accounting-port 1813

    adauth AAA-server 172.25.4.40

    key *.

    authentication port 1812

    accounting-port 1813

    tunnel-group group general attributes

    address pool pool

    authentication-server-group adauth

    by default-group-policy

    You can add the option in the Group aaa-server:

    "reactivation in timed mode.

    This causes a dead server is added to the pool after 30 seconds.

    The following link has some good info on the options available. I suggest looking for the doc for the "reactivation".

    http://www.Cisco.com/univercd/CC/TD/doc/product/multisec/asa_sw/v_7_2/cmd_ref/crt_711.PDF

    -Eric

    Be sure to note all the useful messages.

  • Windows 7 slow login / delay authentication question user wireless via ACS 5.8

    Just set up a new ACS 5.8 farm (only 2 servers) here and which I hope someone here can shed light on the difficulties.

    The new ACS server is set up to correctly authenticate administration network device and I am currently working on the definition of profiles for our wireless users authentication and business laptops.

    Being new to this version of ACS (we will migrate manually ACS 4) I followed an excellent example of this task described in a video on this site: http://www.labminutes.com/sec0044_ise_1_1_wireless_dot1x_machine_auth_peap

    I managed to have a Windows XP sp3 client authenticate properly, first with the authentication of the computer, then the authentication of users... and the domain logon process takes place in a short period of time< 1min="" and="" the="" user="" gets="" all="" their="" networked="" drives="" via="" the="" domain="" login="">

    However, I'm fighting to get our Windows 7 clients to authenticate properly.  It seems that the machine authentication does not work as expected (I can ping the laptop test from another machine on the network while the test machine is sitting at the login screen; and I see Authentication host recorded in the papers of authentication Radius ACS).  But, when a domain user logs in with his credentials, the connection process takes 4-5 minutes before an event to authenticate the user is entered in the register authentication Radius ACS, after which the login process completes, except that the domain logon script does not work and the user does not receive the drive mappings.

    Can someone point me in the right direction here?  I would be grateful any entry on this.

    Thanks in advance,

    John

    I had a similar problem with Wireless 802.1 x Win 7 clients unable to connect unless they had cached credentials of the AD.  Authenticate in the machine, but the user would take a lot of time if the Windows credentials have been cached.

    I could solve the problem by expanding the ACL of the air space used during the user authentication to include all DC in the environment.

Maybe you are looking for