ISAKMP Profiles

Jul 20, 2006 0 Replies

I have enabled ISAKMP profiles on a Cisco 2801 router. The router terminates a DMVPN and VPN Client access to it's Dialer 0 interface. Everything works fine but 1 x thing is annoying me. I could not get the VPN Client connection to work without XAUTH enabled on the router. I have the following entries on the router:



aaa authentication login userauthen local aaa authorization network hw-client local username XYZ password ABC username QWE password DEF



and.... under the ISAKMP VPN Client profile:



client authentication list userauthen isakmp authorization list hw-client



When I remove the above lines, i.e. revert to use the client VPN Group Name & Password under the profile for authentication, the router won't accept the connection. Add the above lines back in and all is OK. Does this mean that ISAKMP profiles only work with XAUTH.



Regards



Darren


Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required