Re: RAS and eTokens

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Peter och Maria Rydqvist (anonymous_at_telia.com)
Date: 03/21/04


Date: Sun, 21 Mar 2004 19:56:09 GMT

On Sun, 21 Mar 2004 12:36:03 -0500, "stan" <no@email.com> wrote:

>Hello All:
>
>Experiencing an issue trying to implement 2 factor authentication using
>etokens. Have the CA set up and the certificate end is fine. The problem
>arises trying to authenticate using the usb token. I can connect to the VPN
>server but it sits at the verifying username and password screen until it
>times out. Disabling the token login and I can vpn just fine.
>
>Did 2 seperate packet captures -
>
>First with tokens enabled and I see LDAP packets being passed and then it
>timesout
>Second without tokens and I don't see any LDAP packets and the connection is
>fine.
>
>Any thoughts on this would be appreciated.
>

I use eTokens with my RAS (VPN/PPTP).

The first you should check is the properties for the RAS server under
the tab Security.

There you need to activate the authentication method "Extensible
authentication protocol (EAP)".

Then, under your remote access policy you need to select the provider
"Smart Card or other certificate" under Authentication in the profile.

If you haven't issued a certificate for the server, I think you will
be able to ask for one at this point (it's quite a while ago I did
this).

Then you should be set. You will get a question at connect time if you
would like to accept the server certificate.

/Peter



Relevant Pages

  • Re: Need help configuring Wireless Connection profile
    ... "point" the info of the Radius authentication to your current Radius server. ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Need help configuring Wireless Connection profile
    ... I have an SBS 2003 server and a Server 2003 member server set up using RADIUS ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 PEAP ... Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: Need help configuring Wireless Connection profile
    ... "point" the info of the Radius authentication to your current Radius server. ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • WSE 3.0 Clarification
    ... maintaining all the authenticated tokens within the last X minutes etc... ... between Authentication, Authorization and Security. ... uses Security when talking about Authentication, ... Say we are dealing with X509 MutualSecurity, the client has a Certificate ...
    (microsoft.public.dotnet.framework.webservices.enhancements)