Hope you can help me. I upgraded my juniper to 6.2r1.0 last night. Every thing seems to be ok, except that on one VS I have some local users. these users all seem to be gone. Now here is the strange thing. If i try and add the user back, it tells me there the user already exists, but i can't see the user nor login with the user.
Also
User Authentication fails but reason is not spesified.
Order:
LDAP
Radius
Then Fails saying username is incorrect.
User Log: Customer information masked
Major AUT21060 id=firewall time="2008-07-23 14:58:20" pri=2
fw= vpn=ive ivs= user= realm=""
roles="" proto=auth src=dst= dstname= type=vpn
op= arg="" result= sent= rcvd= agent="" duration= msg="AUT21060: Login
rejected from IP for / due to
internal error." Info AUT24326 id=firewall time="2008-07-23 14:58:20"
pri=6 fw= vpn=ive ivs=IS user=
realm="REALM" roles="" proto=auth src=
type=vpn op= arg="" result= sent= rcvd= agent="" duration=
msg="AUT24326: Secondary authentication successful for
/ from " Info AUT24326
id=firewall time="2008-07-23 14:58:20" pri=6 fw= vpn=ive
ivs= user= realm="" roles="" proto=auth
src=dst= dstname= type=vpn op= arg="" result= sent= rcvd=
agent="" duration= msg="AUT24326: Primary authentication successful for
/ from " Info AUT23278
id=firewall time="2008-07-23 14:58:20" pri=6 fw= vpn=ive
ivs= user= realm=" roles="" proto=
src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd=
agent="" duration= msg="AUT23278: Password realm restrictions
successfully passed for /"
System Version
6.2R1 (build 13255)
It also seams these users have reset their passwords. Got this article in KB
http://kb.pulsesecure.net/CUSTOMERSERVICE/index?page=kbdetail&record_id=0252030c8769b010da2c6020a006cb9
I wonder if the same problem is in new IVOS?
Regards,
Kerberos is not configured on the AAA server settings.
When re-creating the AAA server it fixed that problem but Local users are still missing and cannot be re-added as it complains they are already there, yet when they try authenticate they get an internal error.