<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco PIX VPN and Active Directory Integration</title>
	<atom:link href="http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:13:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-46955</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Tue, 08 Dec 2009 16:27:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-46955</guid>
		<description>MAFHH,

Everything does route across the VPN. You&#039;d need to configure the firewall for a split-tunnel VPN setup. There are numerous guides available online to help you with this configuration.</description>
		<content:encoded><![CDATA[<p>MAFHH,</p>
<p>Everything does route across the VPN. You&#8217;d need to configure the firewall for a split-tunnel VPN setup. There are numerous guides available online to help you with this configuration.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MAFHH</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-46952</link>
		<dc:creator>MAFHH</dc:creator>
		<pubDate>Tue, 08 Dec 2009 11:04:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-46952</guid>
		<description>Hi,

The problem is once I am connected, I cannot access any internet ips (like google yahoo etc) as if my routing table routes everything over the vpn. How can I fix this?</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>The problem is once I am connected, I cannot access any internet ips (like google yahoo etc) as if my routing table routes everything over the vpn. How can I fix this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-45613</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Tue, 25 Aug 2009 14:56:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-45613</guid>
		<description>Back on 9/6/2008 Peter asked about users being prompted to change their AD password when it has expired when AD is how they authenticate.  I too would like to know if there is a way to make this happen.  We use AD for authentication through the VPN, but users are not prompted to change their passwords when they expire.  

We have the &quot;Enable notification upon  password expirtion to allow user to change password&quot; checked, along with the &quot;Enable notification prior to expiration&quot; box under that with a &quot;14&quot; day notify prior to expiraion.  But the users never get notified that their password has either expired or is about to expire.  We do not have the &quot;Override account-disabled indication from AAA server&quot; right above this checked.

Am I missing something to enable password expiration notifications?</description>
		<content:encoded><![CDATA[<p>Back on 9/6/2008 Peter asked about users being prompted to change their AD password when it has expired when AD is how they authenticate.  I too would like to know if there is a way to make this happen.  We use AD for authentication through the VPN, but users are not prompted to change their passwords when they expire.  </p>
<p>We have the &#8220;Enable notification upon  password expirtion to allow user to change password&#8221; checked, along with the &#8220;Enable notification prior to expiration&#8221; box under that with a &#8220;14&#8243; day notify prior to expiraion.  But the users never get notified that their password has either expired or is about to expire.  We do not have the &#8220;Override account-disabled indication from AAA server&#8221; right above this checked.</p>
<p>Am I missing something to enable password expiration notifications?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fars</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-44137</link>
		<dc:creator>fars</dc:creator>
		<pubDate>Mon, 06 Apr 2009 04:36:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-44137</guid>
		<description>Hi 
I need help 
i can telnet to pix with radius authentication but vpn connection failed with error 691 .
can help me?</description>
		<content:encoded><![CDATA[<p>Hi<br />
I need help<br />
i can telnet to pix with radius authentication but vpn connection failed with error 691 .<br />
can help me?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: drummelhart</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-43983</link>
		<dc:creator>drummelhart</dc:creator>
		<pubDate>Thu, 26 Mar 2009 00:14:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-43983</guid>
		<description>has anyone successfully VPN&#039;s using Vista?

I am having major problems with personnel

Any ideas?</description>
		<content:encoded><![CDATA[<p>has anyone successfully VPN&#8217;s using Vista?</p>
<p>I am having major problems with personnel</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-43717</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Thu, 26 Feb 2009 03:08:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-43717</guid>
		<description>Drummelhart,

I don&#039;t think you&#039;ll need ACLs for VPN users to access internal resources, but I could be wrong. It&#039;s been a while since I messed with this.

Good luck!</description>
		<content:encoded><![CDATA[<p>Drummelhart,</p>
<p>I don&#8217;t think you&#8217;ll need ACLs for VPN users to access internal resources, but I could be wrong. It&#8217;s been a while since I messed with this.</p>
<p>Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: drummelhart</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-43714</link>
		<dc:creator>drummelhart</dc:creator>
		<pubDate>Thu, 26 Feb 2009 00:18:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-43714</guid>
		<description>once complete, will I need to make access lists allowing users with the ip network address to access servers IP addresses internally? I actually configured this beast in an hour, minus the extra acl&#039;s</description>
		<content:encoded><![CDATA[<p>once complete, will I need to make access lists allowing users with the ip network address to access servers IP addresses internally? I actually configured this beast in an hour, minus the extra acl&#8217;s</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-43711</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Wed, 25 Feb 2009 21:31:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-43711</guid>
		<description>Drummelhart,

The secret key is for authentication between the Cisco firewall (RADIUS client) and the RADIUS server. It does nothing for user authentication whatsoever.</description>
		<content:encoded><![CDATA[<p>Drummelhart,</p>
<p>The secret key is for authentication between the Cisco firewall (RADIUS client) and the RADIUS server. It does nothing for user authentication whatsoever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: drummelhart</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-43710</link>
		<dc:creator>drummelhart</dc:creator>
		<pubDate>Wed, 25 Feb 2009 19:18:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-43710</guid>
		<description>I have a question regarding the secret key, in the 2nd and 3rd  line. So when built, my clients will need to type in a certain password, then AD will  send them the challenge request, and once accepted they are in the network via VPN?</description>
		<content:encoded><![CDATA[<p>I have a question regarding the secret key, in the 2nd and 3rd  line. So when built, my clients will need to type in a certain password, then AD will  send them the challenge request, and once accepted they are in the network via VPN?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.scottlowe.org/2005/11/22/cisco-pix-vpn-and-active-directory-integration/comment-page-1/#comment-42395</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 14 Nov 2008 15:39:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=121#comment-42395</guid>
		<description>Does anyone know if it is possible/how to integrate Microsoft Active Directory into Cisco ASA/FWSM policies such that a particular rule in a policy could use an Active Directory group as a source instead of a list of static IP addresses?

We want to ensure the user is a particular user in a group, especially when they come from a Citrix host with multiple users on a single source IP.

Thanks in advance.</description>
		<content:encoded><![CDATA[<p>Does anyone know if it is possible/how to integrate Microsoft Active Directory into Cisco ASA/FWSM policies such that a particular rule in a policy could use an Active Directory group as a source instead of a list of static IP addresses?</p>
<p>We want to ensure the user is a particular user in a group, especially when they come from a Citrix host with multiple users on a single source IP.</p>
<p>Thanks in advance.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

