Question : VPN 3000 , Domain Controller, ACS

I have got this scenario, Backup Domain Controller resides within my LAN, cisco secure ACS (uses RADUIS protocol) resides within my LAN as well.

http://img105.imageshack.us/img105/8886/vpnraduisdcrn6.jpg

Cisco Secure ACS configuration
------------------------------------
As you can see (Top figure) that VPN server -192.168.5.254- (concentrator 3000) was configured to be authenticated by ACS -192.168.5.50-.


VPN 3000 Configuration
---------------------------
In the bottom figure VPN server was pointed to "Server Type" as: RADUIS , and "server authentication" is : 192.168.2.11 (Backup Domain Controller ) ? Why has it not been pointed to Cisco Secure ACS 192.168.5.50 ?


VPN 3000 and Cisco Secure ACS both of them are connected to cisco core switch 4000,,,,,,,,default gateway should be switch.

VPN 3000 and Cisco Secure ACS both of them are running in parallel (i.e not behind not infront)

192.168.2.11 is running Microsoft IAS or RADUIS, as you can see in the link below.
http://img405.imageshack.us/img405/6386/iasorraduiscj1.jpg

If I am running Microsoft IAS on an AD server then we don't need Cisco Secure ACS to provide RADIUS. I think this is my case, but I want to make sure.

I tired to follow the instrcutions in step 5 in the link below :
http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a0080094a03.shtml

But I received the below error message :
http://img247.imageshack.us/img247/4973/errorvpnmylogintestkl1.jpg

At work (not remotely) I tried to test VPN , by entering my Active Directory's username and password but I received the error message in the link above, thought with same username and password I can access the VPN from remote area.

When I checked the Cisco Secure ACS -->  Reports and Activity --> Failed Attempts,,,,,,,Nothing was written to these reports.Doesn't that mean that ACS is not used ?
 

Answer : VPN 3000 , Domain Controller, ACS

Oh.  It is definately AD, then.  Otherwise, as the directions say, you will see either a failed login attempt in the Reports/Failed Logins, or a successful one in the Passed logins.

WGhen
Random Solutions  
 
programming4us programming4us