IAS VPN authentication only grants access to domain if user has certificate

From: Jon Clark (ja1clark_at_yahoo.com)
Date: 03/08/05


Date: Tue, 8 Mar 2005 14:54:57 -0800

I have Cisco PIX setup to use IAS as the Radius server. IAS
is also configured for EAP authentication from a wireless AP.
Hence I have 2 clients specified (PIX and AP).

I have 2 remote access policies in this order.
1. check to see if client is 802.11 and request EAP
authentication
2. default policy that allows 24 hour access and uses CHAP

This all works fine - wireless users cannot connect to AP
w/o a user certificate.
VPN users are challenged with a username, password box
using Cisco VPN client.

I can vpn to the PIX using a machine without a user
certificate and it grants me access to the IP network but I
have to reauthenticate to any domain resource as
DOMAIN\username.

The Issue is: If I VPN from a machine that does have a
valid user certificate then it grants me access to the IP
network and the domain. This implies that the RADIUS has
authenticated AND AD has authenticated. How does this work
as I do not seen it in any documentation and obviously I am
not being given AD authentication w/o the certificate.

Rgds, Jon



Relevant Pages

  • Cisco PIX / CS ACS: Downloadable RADIUS ACLs vulnerability
    ... When an administrator creates an ACL on the Cisco Secure Access Control ... The protocol used by the PIX to download the ACL works as follows: ... PIX sends Radius Access-Request to CS ACS to authenticate the user (the ... configured to use the very same CS ACS server for login authentication ...
    (comp.dcom.sys.cisco)
  • Re: Cisco PIX with SSH enabled on external port for maintenance
    ... I took the original poster as wanting to enable SSH to the PIX itself ... - PIX SSH does not support public key authentication. ... VPN fixes this by ...
    (Security-Basics)
  • 2811, Pix 515e, & 3005
    ... group & users internal to VPN. ... I am trying to setup IAS on 2003 box that is sitting behind Pix. ... 3005 and then pass user authentication to IAS. ...
    (comp.dcom.sys.cisco)
  • Re: 2811, Pix 515e, & 3005
    ... group & users internal to VPN. ... I am trying to setup IAS on 2003 box that is sitting behind Pix. ... 3005 and then pass user authentication to IAS. ...
    (comp.dcom.sys.cisco)
  • Re: IAS VPN authentication only grants access to domain if user has certificate
    ... > is also configured for EAP authentication from a wireless AP. ... > using Cisco VPN client. ... > valid user certificate then it grants me access to the IP ...
    (microsoft.public.internet.radius)