<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Configure Cisco ASA remote access VPN to use RADIUS</title>
	<atom:link href="http://www.binarywar.com/2009/10/configure-cisco-asa-remote-access-vpn-to-use-radius/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.binarywar.com/2009/10/configure-cisco-asa-remote-access-vpn-to-use-radius/</link>
	<description>My KB.  If it helps someone else who is searching for answers...great!</description>
	<lastBuildDate>Fri, 03 Feb 2012 15:07:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.2</generator>
	<item>
		<title>By: Aaron</title>
		<link>http://www.binarywar.com/2009/10/configure-cisco-asa-remote-access-vpn-to-use-radius/comment-page-1/#comment-87</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Wed, 13 Jan 2010 18:17:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.binarywar.com/2009/10/configure-cisco-asa-remote-access-vpn-to-use-radius/#comment-87</guid>
		<description>Thanks for the tip.  I&#039;ll keep that in mind.  I have not yet had a need for the more secure authentication methods as the ASA deployments I have done were for an environment where the LAN interface of the ASA was on the same local subnet as the RADIUS server.  Therefore, security of the RADIUS request was not of great concern.  I would obviously want something more secure if the ASA was sending requests from a DMZ or sending over the Internet.  Thanks again!</description>
		<content:encoded><![CDATA[<p>Thanks for the tip.  I&#8217;ll keep that in mind.  I have not yet had a need for the more secure authentication methods as the ASA deployments I have done were for an environment where the LAN interface of the ASA was on the same local subnet as the RADIUS server.  Therefore, security of the RADIUS request was not of great concern.  I would obviously want something more secure if the ASA was sending requests from a DMZ or sending over the Internet.  Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.binarywar.com/2009/10/configure-cisco-asa-remote-access-vpn-to-use-radius/comment-page-1/#comment-86</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Wed, 13 Jan 2010 16:13:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.binarywar.com/2009/10/configure-cisco-asa-remote-access-vpn-to-use-radius/#comment-86</guid>
		<description>It&#039;s not necessary to use unsecured PAP authentication.  MS-CHAP and MS-CHAPv2 are also supported authentication protocols, however the process of enabling this is not particularly intuitive.. which is to use password-management command in the VPN tunnel group.  This consequently enables password change functionality.. but for those who don&#039;t want to use it, you can disable the password reminder notification by setting the reminder threshold to zero.  See http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/p.html#wp1924502 for details.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not necessary to use unsecured PAP authentication.  MS-CHAP and MS-CHAPv2 are also supported authentication protocols, however the process of enabling this is not particularly intuitive.. which is to use password-management command in the VPN tunnel group.  This consequently enables password change functionality.. but for those who don&#8217;t want to use it, you can disable the password reminder notification by setting the reminder threshold to zero.  See <a href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/p.html#wp1924502" rel="nofollow">http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/p.html#wp1924502</a> for details.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

