FreeRadius & Cisco Pix Auth

James Taylor jtaylor at laszlosystems.com
Wed Jan 11 22:45:38 CET 2006


Hello everyone.

 

I am trying to use AAA for remote VPN access on a Pix 515E firewall.  The
following shows a debug of what I am seeing on the Radius Server during the
Auth process.  Not sure as to why the Radius server is sending an
access-reject after it verifies that my user is valid and should be
authenticated for remote access.  

 

Any pointers would be greatly appreciated.

 

Thank you.

 

James Taylor

 

rad_recv: Access-Request packet from host 192.168.42.1:1025, id=62,
length=94

        User-Name = "jtaylor"

        NAS-IP-Address = 192.168.42.1

        User-Password = "*********"

        NAS-Port = 49

        Cisco-AVPair = "ip:source-ip=192.168.43.250"

rlm_ldap: - authorize

rlm_ldap: performing user authorization for jtaylor

rlm_ldap: ldap_get_conn: Checking Id: 0

rlm_ldap: ldap_get_conn: Got Id: 0

rlm_ldap: (re)connect to intranet.corp.laszlosystems.com:389, authentication
0

rlm_ldap: bind as cn=Manager,dc=laszlosystems,dc=com/Laszl0 to
intranet.corp.laszlosystems.com:389

rlm_ldap: waiting for bind result ...

rlm_ldap: Bind was successful

rlm_ldap: Added password ********** in check items

rlm_ldap: looking for check items in directory...

rlm_ldap: looking for reply items in directory...

rlm_ldap: user jtaylor authorized to use remote access

rlm_ldap: ldap_release_conn: Release Id: 0

rad_recv: Access-Request packet from host 192.168.42.1:1025, id=63,
length=94

Sending Access-Reject of id 62 to 192.168.42.1:1025

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20060111/6457338a/attachment.html>


More information about the Freeradius-Users mailing list