Cisco Systems ISAKMP Profiles

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
ISAKMP Profiles Darren Green 07-20-06
Posted by Darren Green on July 20, 2006, 5:09 pm
Please log in for more thread options
I have enabled ISAKMP profiles on a Cisco 2801 router. The router terminates
a DMVPN and VPN Client access to it's Dialer 0 interface. Everything works
fine but 1 x thing is annoying me. I could not get the VPN Client connection
to work without XAUTH enabled on the router. I have the following entries on
the router:

aaa authentication login userauthen local
aaa authorization network hw-client local
username XYZ password ABC
username QWE password DEF

and.... under the ISAKMP VPN Client profile:

client authentication list userauthen
isakmp authorization list hw-client

When I remove the above lines, i.e. revert to use the client VPN Group Name
& Password under the profile for authentication, the router won't accept the
connection. Add the above lines back in and all is OK. Does this mean that
ISAKMP profiles only work with XAUTH.

Regards

Darren



Similar ThreadsPosted
ISAKMP Profiles July 20, 2006, 5:09 pm
peer matches *none* of the profiles February 7, 2005, 4:04 am
No persistant or DDR for ISDN Profiles? April 20, 2006, 11:48 pm
Cisco ACS - Limit Network Access Profiles to Active Directory User Group? March 30, 2008, 7:28 am
setting dialer enable-timeout with dialer profiles July 28, 2008, 2:55 am
PIX ISAKMP: invalid udp len July 12, 2005, 9:28 pm
resetting just one isakmp October 31, 2005, 11:05 am
isakmp key lenght July 2, 2005, 2:49 pm
VPN client ISAKMP. July 8, 2005, 2:07 pm
ISAKMP nat-traversal ? November 28, 2005, 5:54 am
have PIX with VPN, need to obtain isakmp key June 17, 2008, 3:13 pm
Quick question on isakmp (PIX) July 22, 2005, 2:39 pm
Support for ISAKMP/IKE over IPv6 January 12, 2006, 9:49 am
ISAKMP duplicate packets August 28, 2007, 4:15 am
Re: phase 1 isakmp failing November 4, 2008, 4:16 pm