
B-6
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Appendix B Configuration Examples for Other Remote Access Clients
Xauth with RSA Ace/Server and RSA SecurID
Token Enabled
When a connection is being established to the PIX Firewall, the user is prompted to enter the username
and passcode. The client can recognize that a Software Token has been installed on Windows NT systems
(provided the Token Software is installed), such that if the PIN is entered, then the passcode is
automatically obtained by the client Software Token, and is sent to the AAA server through the
PIX
Firewall. With a Pinpad, or on operating systems other than Windows NT, the prompt requests a
username and passcode. Enter the PIN on the Pinpad or in the Software Token dialog box and use the
passcode displayed on the token (See
Figure B-2).
Figure B-2 Software Token Dialog Box—Cisco VPN 3000 Client Version 2.5
Next Tokencode Mode
If the user enters an incorrect passcode or PIN, the token status is changed to the Next Tokencode mode.
In this case, when the user tries to connect the next time, and enters a correct passcode in the first prompt,
another prompt requests the user to enter the next tokencode.
New PIN Mode
This mode is seen when the user is first assigned a token and needs to connect before a PIN can be
assigned or created by the user (Case 1), or if, for some reason, the administrator puts the token in the
New PIN Mode (Case 2).
Case 1: User has no PIN’s previously assigned or the PIN has been cleared.
In this case, enter the value that is currently being displayed in the SecurID message box.
Case 2: User has an existing PIN and needs to change it.
Commentaires sur ces manuels