IAS

From: Dan Locey (danl@ascinet.com)
Date: 06/17/02


From: "Dan Locey" <danl@ascinet.com>
Date: Mon, 17 Jun 2002 11:03:54 -0700


I have a regular NT infrastructure with several W2K
servers thrown in. I loaded IAS on one of my W2K servers
as a RADIUS server. I am authenticating user logins to my
Cisco routers and PIX.

My question is, PIX seems to be sending requests in PAP.
I need to fully understand the use of the session keys in
the RADIUS client/server relationship to ensure that I am
not doing cleartext. If there is a way to specify that
client requests from my PIX be sent in CHAP or MS-CHAP, I
would appreciate that.

Also, I added a special user to my NT domain, after
setting up the RADIUS server and sucessfully
authenticating an existing user. After forcing a domain
sync and waiting about 4 hours, the new user is still not
recognized. Where does the IAS pull its info from? The
PDC/BCD of the domain, or does it go into BCD emulation
with its own database?

Please send all responses directly to me, if you could, at
danl@ascinet.com



Relevant Pages

  • Re: Cisco PIX515e and Server 2008
    ... an invalid password error. ... Server 2003 radius server. ... would cause the logon test to fail? ... Did you configure the PIX as a RADIUS client in NPS? ...
    (microsoft.public.internet.radius)
  • Re: Internet access
    ... I didn't work with RADIUS server never so I must read about that. ... If so, you may use local account on the pix, or use ... radius (IAS on the Windows server) to let them authenticate with their ... As i don't have a pix on hand, and i was used to bigger one, it may not be ...
    (microsoft.public.windows.server.security)
  • Re: Freeware Radius for Windows XP
    ... VPN user needs to be authenticated on Radius running on Windows XP (the ... system behind the pix). ... Radius server should be able to lock VPN account ...
    (microsoft.public.windowsxp.general)

Quantcast