RADIUS vs. AD

Hi folks,

I'm having trouble setting up VPN authentication with a PIX 6.3(4) and Microsoft's Internet Authentication Service on Windows 2003 Server, Enterprise Ed. I've tried the walkthrough on Cisco's website and even with logging turned up on IAS and aaa debug turned on, I've only had one auth attempt get logged in IAS' logs -- and this is out of a couple of dozen attempts. My next step is to open a ticket with the TAC but I thought I'd check in here and see if there are any options to IAS for authenticating through Active Directory. Any info is much appreciated.

formatting link
Thanks, Gary

Reply to
Gary
Loading thread data ...

I meant "alternatives" to IAS, not options.

Reply to
Gary

How about Cisco Secure ACS for Win2k3? It looks like it costs... is this a recommended alternative that's actually stable. I've been reading through archives of microsoft.public.internet.radius and so far I'm not impressed with the reliability of IAS.

-Gary

Reply to
Gary

Reply to
Wayne

You might want to look into Clearbox RADIUS and TACACS server. Much cheaper then Cisco Secure ACS.

Reply to
Wayne

Hey, thanks for the tip. ACS is very expensive and a bit overkill for our ~75 VPN users. I remember using the Solaris version of ACS at a NSP to manage several hundred thousand outsourced dialup accounts. I think I would prefer having a TACACS+ solution anyhow so this might be an ideal alternative. Does anyone here have any feedback on XPerience and this product? Much thanks.

-Gary

Reply to
Gary

I use it for our aprox. 40 VPN users as well as for our internal wireless clients. It's pretty easy to configure (much more so than IAS), the tech support is decent (I used their web based message board to ask a question and got a response within 6 hours), but the software does have some limitations (remember, it's only $400). Low risk, high reward. They give you a 30 day trial that they say has a few limitations, however I didn't find them, then after reading more on their message board I found out there aren't any limitations.

Reply to
Wayne

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.