Ticket #12 (new defect)

Opened 3 years ago

Incorrect handling of Xauth next token

Reported by: Ryan Shultz Owned by: mgrooms
Priority: major Milestone: Version 2.2.0
Component: ike daemon Version: 2.1.4
Keywords: next token Cc: RShultz@…

Description

Describe Problem:
When attempting to connect to a Cisco VPN 3000 with RSA authentication enabled I am able to connect under most circumstances. Only when the concentrator prompts for the second token rotation does the authentication error out and fail. I do not get the prompt like I normally would with the Cisco client. Here is the process:

1. Connect to VPN profile
2. Prompt for credentials
3. Put in login, private pin and current code on the RSA keyfob
4. The connection fails with "User authentication error" - "tunnel disabled" - "detached from key daemon"

If I go to another machine that is not x64 and use the client from Cisco that works with x32 I would get a prompt to put in the next token/fob code that would rotate up. If I put in that next code, I would authenticate without issue.


Client/Gateway? Information:
VPN Client Version: 2.1.4
Windows OS Version: x64 Windows Vista Ultimate
Gateway Make/Model?: Cisco 3000 VPN Concentrator
Gateway OS Version: Unavailable

Note: See TracTickets for help on using tickets.