RE: VPN - RRAS - Verify Caller ID

  • From: <paul_lemonidis@xxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 20 Oct 2003 13:57:27 +0100

Hi all

What exactly is this option please? It seems like it is some sort of
preshared secret that is held in AD? I can see no option for configuring the
RRAS clienst to sue it if so?

Many thanks in advance.

Regards,

Paul Lemonidis.



----- Original Message ----- 
From: "William Robertson" <robertson.william@xxxxxxxxxxxxxx>
To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
Sent: Monday, October 20, 2003 1:50 PM
Subject: [isalist] RE: VPN - RRAS - Verify Caller ID


> http://www.ISAserver.org
>
> As far as I can tell, all of them.
> Caller-ID definitely does work.
>
> -----Original Message-----
> From: Jim Harrison [mailto:jim@xxxxxxxxxxxx]
> Sent: 20 October 2003 14:53 PM
> To: [ISAserver.org Discussion List]
> Subject: [isalist] RE: VPN - RRAS - Verify Caller ID
>
> http://www.ISAserver.org
>
> This happens to all or just some of them?
> Are you sure the caller ID is working properly?
>
>   Jim Harrison
>   MCP(NT4, W2K), A+, Network+, PCG
>   http://isaserver.org/Jim_Harrison/
>   http://isatools.org
>   Read the help / books / articles!
>
>
> On Mon, 20 Oct 2003 13:22:53 +0200
>  "William Robertson" <robertson.william@xxxxxxxxxxxxxx> wrote:
> http://www.ISAserver.org
>
> Hey guys,
> Anyone got a comment on this one...?
>
> -----Original Message-----
> From: William Robertson [mailto:robertson.william@xxxxxxxxxxxxxx]
> Sent: 17 October 2003 12:42 PM
> To: [ISAserver.org Discussion List]
> Subject: [isalist] VPN - RRAS - Verify Caller ID
>
> http://www.ISAserver.org
>
>
> Hi there
>
> I have a Cisco RAD device setup to use RADIUS authentication via Internet
> Authentication Services on my Domain Controller. This works hundreds!!
>
> My VPN clients are authenticated by a "Group Membership" policy within
RRAS
> on my ISA Server and this also works hundreds.
>
> EXCEPT if as part of my IAS authentication I enable the "Verify Caller ID"
> option in the Dial-In tab in AD Users & Computers, when I do this my VPN
> users are no longer able to connect and they get an error message stating
> the following:
> Error 649: The account does not have permission to dial in
>
> I have found the problem to be resolved simply by removing the "Verify
> Caller ID" option, but this then throws out the (limited) security that I
> can get by in actual fact ensuring that users are dialing in from
legitimate
> locations.
>
> Does anyone have any comments on this?
>
> Cheers
> William R.
>
>
>
> ---------------------------------------------------------------------
> Everything in this e-mail and attachments relating to the official
> business of Columbus Stainless is proprietary to the company. It is
> confidential, legally privileged and protected by law. Columbus
> Stainless does not own and endorse any other content. Views and
> opinions are those of the sender unless clearly stated as being that
> of Columbus Stainless. The person addressed in the e-mail is the sole
> authorised recipient.  Please notify the sender immediately if it has
> unintentionally reached you and do not read, disclose or use the
> content in any way. Whilst all reasonable steps are taken to ensure
> the accuracy and integrity of information and data transmitted
> electronically and to preserve the confidentiality thereof, no
> liability or responsibility whatsoever is accepted if information or
> data is,for whatever reason, corrupted or does not reach its intended
> destination.
> ---------------------------------------------------------------------
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=3Disalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=3DFAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> Leading Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site: http://www.msexchange.org
> Windows Security Resource Site: http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion List as:
> robertson.william@xxxxxxxxxxxxxx
> To unsubscribe send a blank email to $subst('Email.Unsub')
>
> ---------------------------------------------------------------------
> Everything in this e-mail and attachments relating to the official
> business of Columbus Stainless is proprietary to the company. It is
> confidential, legally privileged and protected by law. Columbus
> Stainless does not own and endorse any other content. Views and
> opinions are those of the sender unless clearly stated as being that
> of Columbus Stainless. The person addressed in the e-mail is the sole
> authorised recipient.  Please notify the sender immediately if it has
> unintentionally reached you and do not read, disclose or use the
> content in any way. Whilst all reasonable steps are taken to ensure
> the accuracy and integrity of information and data transmitted
> electronically and to preserve the confidentiality thereof, no
> liability or responsibility whatsoever is accepted if information or
> data is,for whatever reason, corrupted or does not reach its intended
> destination.
> ---------------------------------------------------------------------
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=3Disalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=3DFAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> Leading Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site: http://www.msexchange.org
> Windows Security Resource Site: http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion List as:
> jim@xxxxxxxxxxxx
> To unsubscribe send a blank email to $subst('Email.Unsub')
>
> ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*
>
> All mail from this domain is virus-scanned with RAV.
> www.ravantivirus.com
>
> ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*
>
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> Leading Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site: http://www.msexchange.org
> Windows Security Resource Site: http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion List as:
> robertson.william@xxxxxxxxxxxxxx
> To unsubscribe send a blank email to $subst('Email.Unsub')
>
> ---------------------------------------------------------------------
> Everything in this e-mail and attachments relating to the official
> business of Columbus Stainless is proprietary to the company. It is
> confidential, legally privileged and protected by law. Columbus
> Stainless does not own and endorse any other content. Views and
> opinions are those of the sender unless clearly stated as being that
> of Columbus Stainless. The person addressed in the e-mail is the sole
> authorised recipient.  Please notify the sender immediately if it has
> unintentionally reached you and do not read, disclose or use the
> content in any way. Whilst all reasonable steps are taken to ensure
> the accuracy and integrity of information and data transmitted
> electronically and to preserve the confidentiality thereof, no
> liability or responsibility whatsoever is accepted if information or
> data is,for whatever reason, corrupted or does not reach its intended
> destination.
> ---------------------------------------------------------------------
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=3Disalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=3DFAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> Leading Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site: http://www.msexchange.org
> Windows Security Resource Site: http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion List as:
paul_lemonidis@xxxxxxxxxxx
> To unsubscribe send a blank email to $subst('Email.Unsub')
>


Other related posts: