<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Cisco PIX VPN and Active Directory Integration</title>
	<atom:link href="http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<pubDate>Tue, 06 Jan 2009 06:44:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Chris</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-42395</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 14 Nov 2008 15:39:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-42395</guid>
		<description>Does anyone know if it is possible/how to integrate Microsoft Active Directory into Cisco ASA/FWSM policies such that a particular rule in a policy could use an Active Directory group as a source instead of a list of static IP addresses?

We want to ensure the user is a particular user in a group, especially when they come from a Citrix host with multiple users on a single source IP.

Thanks in advance.</description>
		<content:encoded><![CDATA[<p>Does anyone know if it is possible/how to integrate Microsoft Active Directory into Cisco ASA/FWSM policies such that a particular rule in a policy could use an Active Directory group as a source instead of a list of static IP addresses?</p>
<p>We want to ensure the user is a particular user in a group, especially when they come from a Citrix host with multiple users on a single source IP.</p>
<p>Thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heino</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-42382</link>
		<dc:creator>Heino</dc:creator>
		<pubDate>Thu, 13 Nov 2008 10:30:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-42382</guid>
		<description>Hi Peter,

will the Password change request from DC passed through to the Cisco CPN Client?</description>
		<content:encoded><![CDATA[<p>Hi Peter,</p>
<p>will the Password change request from DC passed through to the Cisco CPN Client?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vpn service</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-41811</link>
		<dc:creator>vpn service</dc:creator>
		<pubDate>Thu, 02 Oct 2008 14:20:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-41811</guid>
		<description>Hi,
What I have seen using internal dhcp seems to be problematic. 
If you have any solutions for that, I had to hear them :)</description>
		<content:encoded><![CDATA[<p>Hi,<br />
What I have seen using internal dhcp seems to be problematic.<br />
If you have any solutions for that, I had to hear them <img src='http://blog.scottlowe.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-41226</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Sat, 06 Sep 2008 12:43:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-41226</guid>
		<description>Hi Scott,
I am new to this Blog and i have a question related to the AD Auth over PIX. 
A Remote User did not log into the AD for a certain time and his password in AD has expired and needs to be changed. 
Usually he will be asked to change his password when he is logging on in the Domain on Local LAN. 
But what about remote users? 
VPN Client Ver.5 from CISCO and the Firewall is a PIX 506e with 6.3. 
AD Authentication is allready working fine. 
Is there a way that the user will be asked to change his Password because it has expired? As Domain Server we use Windows 2008 Enterprise and Winows XP as Client.</description>
		<content:encoded><![CDATA[<p>Hi Scott,<br />
I am new to this Blog and i have a question related to the AD Auth over PIX.<br />
A Remote User did not log into the AD for a certain time and his password in AD has expired and needs to be changed.<br />
Usually he will be asked to change his password when he is logging on in the Domain on Local LAN.<br />
But what about remote users?<br />
VPN Client Ver.5 from CISCO and the Firewall is a PIX 506e with 6.3.<br />
AD Authentication is allready working fine.<br />
Is there a way that the user will be asked to change his Password because it has expired? As Domain Server we use Windows 2008 Enterprise and Winows XP as Client.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jared</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-39195</link>
		<dc:creator>Jared</dc:creator>
		<pubDate>Wed, 04 Jun 2008 15:15:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-39195</guid>
		<description>Good read, everything worked and I can connect into my network with no issue. 

The problem is once I am connected, I cannot access any internet ips (like google yahoo etc) as if my routing table routes everything over the vpn.  How can I fix this?</description>
		<content:encoded><![CDATA[<p>Good read, everything worked and I can connect into my network with no issue. </p>
<p>The problem is once I am connected, I cannot access any internet ips (like google yahoo etc) as if my routing table routes everything over the vpn.  How can I fix this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-37071</link>
		<dc:creator>David</dc:creator>
		<pubDate>Thu, 17 Apr 2008 23:17:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-37071</guid>
		<description>Hi guys, 

I am an IT manager trying to implement Cisco IPSEC VPN access along with including Windows Networking.  So, users remotely can browse our Network Neighborhood or access servers/desktops using their NETBIOS names.  I have not found any solid documentation on this type of implementation.  I am using an ASA/PIX 5510 IOS 8.0.3  This is a 2nd gen PIX.  Any help?</description>
		<content:encoded><![CDATA[<p>Hi guys, </p>
<p>I am an IT manager trying to implement Cisco IPSEC VPN access along with including Windows Networking.  So, users remotely can browse our Network Neighborhood or access servers/desktops using their NETBIOS names.  I have not found any solid documentation on this type of implementation.  I am using an ASA/PIX 5510 IOS 8.0.3  This is a 2nd gen PIX.  Any help?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-35208</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Sat, 26 Jan 2008 14:40:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-35208</guid>
		<description>Jo,

From what I've seen, using internal DHCP seems to be problematic. If you have any solutions for that, I'd love to hear them!</description>
		<content:encoded><![CDATA[<p>Jo,</p>
<p>From what I&#8217;ve seen, using internal DHCP seems to be problematic. If you have any solutions for that, I&#8217;d love to hear them!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jo</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-35205</link>
		<dc:creator>Jo</dc:creator>
		<pubDate>Sat, 26 Jan 2008 12:55:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-35205</guid>
		<description>Sure you can use AD to authenticate VPN clients via PIX. I'm using Cisco Secure ACS Engine Solution as a RADIUS and a Cisco Remote Client comes with it and it's installed on a member AD server. Works great.

Before that I was using Cisco Secure ACS software and to be honest I like it better because it doesn't require an additional client and once installed on a machine which is part of AD works great.

Back there (3 years ago) the ACS software was working only on MS WIN 2000 Server. I don't know what is the situation today but my new Solution Engine is running Win 2000 as well. I do not have access to the OS which is somehow good. The box is independent.

ACS could be used for any device on your network including switches/routers etc, anything that could use RADIUS or TACACS. Very useful appliance. A bit expensive... mine came in for $8500.

Does anybody use internal DHCP?</description>
		<content:encoded><![CDATA[<p>Sure you can use AD to authenticate VPN clients via PIX. I&#8217;m using Cisco Secure ACS Engine Solution as a RADIUS and a Cisco Remote Client comes with it and it&#8217;s installed on a member AD server. Works great.</p>
<p>Before that I was using Cisco Secure ACS software and to be honest I like it better because it doesn&#8217;t require an additional client and once installed on a machine which is part of AD works great.</p>
<p>Back there (3 years ago) the ACS software was working only on MS WIN 2000 Server. I don&#8217;t know what is the situation today but my new Solution Engine is running Win 2000 as well. I do not have access to the OS which is somehow good. The box is independent.</p>
<p>ACS could be used for any device on your network including switches/routers etc, anything that could use RADIUS or TACACS. Very useful appliance. A bit expensive&#8230; mine came in for $8500.</p>
<p>Does anybody use internal DHCP?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ScottG</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-34897</link>
		<dc:creator>ScottG</dc:creator>
		<pubDate>Thu, 03 Jan 2008 18:40:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-34897</guid>
		<description>Has anyone got this going with IPSec?  I have a PIX running IOS 7.1.  I want to eliminate group authentication on the PIX and have VPN clients authenticated against AD. Can I do this using the radius server or do I need something else?

Thanks.</description>
		<content:encoded><![CDATA[<p>Has anyone got this going with IPSec?  I have a PIX running IOS 7.1.  I want to eliminate group authentication on the PIX and have VPN clients authenticated against AD. Can I do this using the radius server or do I need something else?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fred</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/#comment-33731</link>
		<dc:creator>Fred</dc:creator>
		<pubDate>Fri, 12 Oct 2007 20:53:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-33731</guid>
		<description>Tom,

IPSec is a whole nother ball game.  The commands above won't help at all with IPSec VPN.</description>
		<content:encoded><![CDATA[<p>Tom,</p>
<p>IPSec is a whole nother ball game.  The commands above won&#8217;t help at all with IPSec VPN.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
