I didn't really get your question. Do you wanna perform Certificate
authentication at group level or at xauth level ?

Level 1 authentication is used for peer (device) authentication
(groupname/pass). We can definitely use certificates for this type of
authentication. I have seen such things work. However , you would
still need to manually insert the xauth/pass ! Also, even if its
possible to use certificate for Xauth (which I doubt), I think it
would add complications and would not be scalable !

Having said that , I'm sure you can use Token based Xauth (like RSA)
with VPN client.

Hope this helps. If not, please can you elaborate the question a bit.

Aditya Govind Mukadam

On Thu, Jul 17, 2008 at 6:53 PM, Petr Vyhnal <vyhnal@xxxxxx> wrote:
Hi all,

I have one quick question. I usually configure PIXes for VPN client in
two level authentication mode. Level 1 is vpngroup/password and level 2
is XAUTH using RADIUS server. Is there possibility (with PIX or ASA) to
use per-user generated certificates instead vpngroup/pass auth with
XAUTH/RADIUS second level auth as well?


