authentication from router

From: Wayne (Wayne_at_discussions.microsoft.com)
Date: 03/15/05


Date: Tue, 15 Mar 2005 07:55:02 -0800

Hi,
I have a cisco router set up to authenticate VPN clients using a windows
2000 ISA box. I am concerned about sending the passwords over the wire.
Cisco Document 13838 states that user passwords are encrypted, but user names
are not. The only way we could get the server to authenticate the clients
was to select PAP on the server side. This seems to conflict with the
information in the Cisco document. I need to verify if the password is sent
encrypted from the router to the server, and how do I document this? Network
Monitor? This is a production server and I cannot take it down or mess with
the bandwidth.
Thanks - Wayner



Relevant Pages

  • RE: VmWare and Pen-test Learning
    ... Setup a tftp server on your client machine. ... Use John the Ripper to crack the passwords. ... (dictionary attacks, brute force, single mode). ... Download FREE whitepaper on how a managed service can help ...
    (Pen-Test)
  • Cisco Security Advisory: Unity Vulnerabilities on IBM-based Servers
    ... Cisco Security Procedures ... direct IBM branding and installed with the Cisco Unity Server image disk ... Manager address and DHCP server address (no local user account "bubba"): ...
    (NT-Bugtraq)
  • Cisco Security Advisory: Unity Vulnerabilities on IBM-based Servers
    ... Cisco Security Procedures ... direct IBM branding and installed with the Cisco Unity Server image disk ... Manager address and DHCP server address (no local user account "bubba"): ...
    (Bugtraq)
  • [Full-Disclosure] Cisco Security Advisory: Unity Vulnerabilities on IBM-based Servers
    ... Cisco Security Procedures ... direct IBM branding and installed with the Cisco Unity Server image disk ... Manager address and DHCP server address (no local user account "bubba"): ...
    (Full-Disclosure)
  • Re: Strange SSID in the air...
    ... the cable modem assigning Gateway+DNS to the Linksys router etc.)? ... to verify that DNS lookups actually point to the real web site. ... from overloading one server, while another remains under-utilized. ... dumb applications that are not very smart about encrypting passwords. ...
    (alt.internet.wireless)