
5
Release Notes for Cisco VPN 3002 Hardware Client Release 3.5.2
78-13971-02
Release 3.5 New Software Features
• If you try to access resources on the network behind the VPN Concentrator
that are not web-based, for example, email, the connection will fail until you
authenticate.
• To authenticate if your browser does not automatically redirect you to the
login pages, enter the IP address for the private interface of the VPN 3002 in
the browser Location or Address field. The browser then displays the login
screen for the VPN 3002. To authenticate, click the Connect/Login Status
button.
You configure individual user authentication on a group basis on the VPN
Concentrator at the central site, which then pushes the policy to the VPN 3002.
RADIUS with Password Expiry
RADIUS with password expiry is an IPSec authentication method that you
configure on a VPN Concentrator on a group basis. This option lets the VPN 3000
Concentrator that is attempting to authenticate an IPSec client to an external
RADIUS server (acting as a proxy to an NT server) determine when a user’s
password has expired and prompt for a new password. By default, this option is
disabled.
Enabling this option allows the VPN 3000 Concentrator to use MS-CHAP-v2
when authenticating an IPSec client to an external RADIUS server. That RADIUS
server must support both MS-CHAP-v2 and the Microsoft Vendor Specific
Attributes. Refer to the documentation for your RADIUS server to verify that it
supports these capabilities.
Because of the use of MS-CHAP-v2, when this option is enabled on the VPN 3000
Concentrator, the VPN Concentrator can provide enhanced login failure messages
that describe specific error conditions. These conditions are:
• Restricted login hours.
• Account disabled.
• No dialin permission.
• Error changing password.
• Authentication failure.
The “password expired” message appears when the user whose password has
expired first attempts to log in. The other messages appear only after three
unsuccessful login attempts.
Comentarios a estos manuales