Change password error on VPN using Cisco 5250 and RADIUS



I have a complicated issue. My company has a Cisco 5250 VPN device and
it is setup to use RADIUS for authentication. I wrote an application
that changes the users Active Directory password and it works great
when connected on the network. However, trying to change your password
via VPN gives me a Constraint Violation. I have tried everything and I
don't even know where to look.
Is it failing because the correct credentials are not making it to the
AD server? (double hop) Or is there some settings on the RADIUS server
to allow password updates?
Cisco VPN has a setting that looks GREAT! It is called Enable password
updates with RADIUS authentication, but when that is checked VPN asks
for a domain and I wasn't able to log in.
So any info will be greatly appreciated. Please help!

.



Relevant Pages