Cisco AAA/Identity/Nac :: 802.1x With Alcatel Phone With Acs 5.0

Mar 24, 2010

How to do implementation of 802.1x with alcatel phone where pc will be behind the phone and cisco switch ports are configured as trunk. Trunk native vlan is data vlan for pc and trunk carrying voice vlan.when trunk mode is enabled I can not configure 802.1x on trunk interface.

View 1 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: ACS 5.2 Cannot Support Alcatel Switch

Dec 18, 2011

I have Some Alcatel Switch and I want to use ACS 5.2's tacscs+ for Alcatel Switch admin authentication.the Failure Reason:13011 Invalid  TACACS+ request packet - possibly mismatched Shared SecretsBut I was check the share secret is correct.Before I was tried associated ACS with vision 4.2 is work.

View 12 Replies View Related

Network Key For Alcatel Ot-5320?

Jul 29, 2012

I have an old Alcatel OT 5320 and I have put a pay as you go SIM in it and it has asked for a network key. What is it or where do I find it?

View 1 Replies View Related

Cisco Switching/Routing :: Connection Between 3550 And Alcatel 6400

Oct 4, 2012

We encouter problems flow between two switches at work. The first is a Cisco 3550 and the second is an Alcatel 6400. For the tests, I connected a PC on each switches on acces port. The 2 switches are connected by a trunk port (the 24th for each switches).

I forgot to tell that the 2 switches are on the same vlan (5). I made some tests and it takes about 2 minutes to transfer 45mo from one pc to the other one.
 
I can give a part of the configuration :

! Stack Manager :! Chassis :system name vxTargetsystem daylight savings time disable! Configuration:! VLAN :vlan 1 disable name "VLAN 1"vlan 5 enable name "toip"vlan 5 port default 1/1vlan 5 ip 192.168.0.0 255.255.255.0! VLAN SL:! IP :ip service allip interface dhcp-client vlan 1 ifindex 1ip interface "toip" address 192.168.0.253 mask 255.255.255.0 vlan 5 ifindex 3! IPX :! IPMS :! AAA :aaa authentication console "local"aaa authentication telnet "local"aaa [code] ..............

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Phone Mitel MAB Authentication In ACS 5.2 / 802.1X?

Oct 26, 2011

authenticate phone Mitel in ACS 5.2. I tried to authenticate a PC wich is behind of phone Mitel, but it doesn´t working.the solution work fine with vlan mapping.
 
This configuratión work fine with Phone Cisco but not for phone Mitel, and I had used this templace by both.
 
vlan 709 = guest
vlan 10 = voice
 inter fas 1/0/8
switchport access vlan 709
switchport mode access
switchport voice vlan 10

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Setting Up Hot Desk With Dot1x With Ip Phone

Aug 12, 2012

Is it possible to set up a multi use port that will use dot1x to authenticate several laptops, only 1 connected at a time, but I need the phone to automatically connect without having to make changes to the phone config as I don't have access to the Cisco call manager to set up the authentication.
 
Setup would be using catalyst 3650x at the access layer, various Cisco ip phones models and a Cisco acs 4.2 server doing the authentication. The laptops would be plugged in through the phone. The switch is already in use and setup and using both data and voice vlans, but now I need to enable it for several users. The acs is already setup to authenticate our wireless network so I'm planning on using the same setup for the wired side.

View 1 Replies View Related

AAA/Identity/Nac :: NAC 4.8.2 - IP Phone 9951 Not Registered / Active Call Getting Disconnected

Jan 30, 2012

I have deployed the NAC Solution. NAC Software version = 4.8.2 and Agent version = 4.8.3.1.The solution is working fine but the Cisco IP Phone CP9951 is getting restart after applying NAC (or port profiles) at some time interval. Time is not fixed but it doesn't seem stable. Sometimes, it is just disconnected while using the Phone and sometimes when you log-off or restart the PC.The Cisco IP Phone CP8945 is working fine in all cases.We are getting the message of "Phone not registered" and active call is getting disconnected.

View 0 Replies View Related

Cisco AAA/Identity/Nac :: 2960 Unprotected Identity Pattern Not Working As Expected

Oct 28, 2012

I'm trying to test such 802.1x wired environment:windows xp sp3 as supplicant windows NPS as radius server 2960 as authenticator latest anyconnect (3.1.01065) + nam and standalone profile editor.I have a question: What is the difference between protected identity pattern and unprotected identity pattern (set in nam profile editor)? As I understand documentation PEAP-MSCHAPv2 is a tunneled method and it uses un- protected identity pattern to protect user's identity during phase 0. But if I use any fake identity here (anonymous, anonymous@[domain], etc) access is rejected (Access-Reject in switch debugs). I have to use exacly the same pattern in unprotected identity pattern as in protected identity pattern ([username] or [username]@[domain]) to gain access, regardless of authenticaton mode (same in machine only, user only authentication).

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Group Mapping With LDAP External Identity Store

May 18, 2011

I have a new Cisco Secure ACS 5.2 on a VM. We want to use it to for administrative access to our Cisco equipment  with TACACS+. I am trying to map user permissions to different groups of devices based on active directory group membership, however it is not working.
 
I am using an LDAP (configured for secure authentication) external identity store. On the directory organization tab, I have confirmed the accuracy of the subject and group search base and the test configuration button shows that it's finding > 100 users and >100 groups.
 
On the directory groups page I have entered the groups according to the required format. cn=groupname1,ou=groups,dc=abc,dc=com
 
I have a rule based result selection under group mapping. I have two rules in the format below.
 
Conditon
LDAP:Externalgroups groupname1
Result
Identitygroup1
 
I have the default group set to a identity group named other. My problem is, no matter what user attempts to authenticate, the Default rule is applied, and the user is put into the other identity group.This occurs when I log on as a groupname1 user, groupname2 user, or as user that is not a member of either of those groups. LDAP authentication works and the user is able to logon to the device.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Create Microsoft Active Directory (AD) Identity Store?

Jul 11, 2011

We are using ACS 5.2 and we are trying to create a Microsoft Active Directory (AD) Identity Store. We have a user to be used in the Active Directory creation General page and we would like to know how the test communication / ACS to AD communication takes place.
 
Our user is a predefined user in AD and has admin rights, but the password expires every 60 days. Will this affect the communication between AD and ACS 5.2 at everytime the entered user's password expires?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Host Internal Identity Store / Per Group Modification

Jan 24, 2012

I'm currently looking for a solution in order to restrict the modification of the host internal identity store (add or delete MAC host) per group. The default administrator roles does not include "per group restriction". Under the ACS I defined one group per department? My objective it to allow each department to access their ACS MAC database to add or delete MAC addresses as required.

How to restrict internal identity store per group?Do I need to create new roles? and how?I was not able to get an answer from the ACS ADMIN manual.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ASA5550 / ACS 5.3 - 22056 Subject Not Found In Applicable Identity?

Dec 5, 2012

I have a new ACS 5.3 configure and a ASA5550 to authenticate VPN users using a remote LDAP server. Once I try to authenticate the users with the ACS it gives me the error message "22056 Subject not found in the applicable identity store(s)."
 
I checked out the documentation and have already configure the Identity store sequences to redirect everything to the LDAP server, I also did the Bind test and it says that is ok, but I still have the same problem.
 
I validated the Access Policies Menu, and tried to create a new Service Selection Rules, but whet I get to the option of modifying the Identity option I get the error: "This System Failure occurred: {0}. Your changes have not been saved.Click OK to return to the list page. " and I'm not able to modify the identity, not in this new option I created, nor in the ones already created in the ACS.

View 8 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Error - 22056 Subject Not Found In Applicable Identity

Oct 6, 2012

I have two ACS v 5.2 (primary and secundary) and some users are in the internal stor and the others are in the AD.The local site topology is like this:
 
PC - AP - WLC - ACS - AD
 
Authentication method is PEAP(EAP-MSCHAPv2) and all user have the certificate company installed. The OS in the client users is Windows 7.Users was working fine but some users reports intranet disconnections. I see in the ACS log  many "22056 Subject not found in the applicable identity store(s)." and "24415 User authentication against Active Directory failed since user's account is locked out" alarms.I believed it was because user wasn´t in the AD data base, but some times the same user is authenticated successfull and other i see the "22056...." or "24415...." alarms.
 
I switched the role for ACS primary to works as secundary and we see the same alarms.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Identity Groups - Restrict Device Access

Apr 14, 2011

I have ACS 5.2 running as a VM.  I'm AD, then local authentication successfully for device access, but I want to define ACS user groups to restrict login. I don;t see any way to do this.  If I use AD groups, they don;t show up as selection options on the policy screens, just the ACS locallyy defined groups. 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.x Identity Store Sequence And Token Validation

Dec 3, 2012

We have a ACS 4.3.2 installed with users authenticating against an Active Directory database. The AD database not only authenticate the users but also assigns the group that is used to select IP address pool.Now the requirements require to use token authentication with SafeNet. This authentication uses the same username but the password is composed of the original password + OTP.The problem is that the SafeNet server doesn't return the group membership.I've read about the Identity Store Sequence in ACS 5.x and I think I could use it in the following sequence:! configure an Authentication Sequence using the SafeNet token server (this works with ACS 4.x)I configure an Attribute Retrieval Sequence against the AD database. This would use the username only, no password and would retrieve the group membership.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ISE V1.1 ISE Authorization Rules Do Not Use Endpoint Identity Group

Dec 5, 2011

I'm looking for Cisco ISE v1.1 to use the following licensing feature. url...Endpoint is dynamically profiled by Cisco ISE and assigned  dynamically or statically to an endpoint identity group. Cisco ISE authorization  rules do not use this endpoint identity group.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1.0.44 External Identity Stores Account To Be Locked Out

May 11, 2012

I am currently running cisco ACS 5.1.0.44 and use active directory as the main authentication identity store to allow network administrators to have access to network devices in my organization .As per the established security policies in my organization , the ACS has to disable any account after 3 failed login attempts to any network devices .i have gone through all the settings oN the acs but couldn't find where or how it is done .

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Authenticate VPN Users Via ACS 5.4 And AD Via External Identity Store

Feb 22, 2013

I have installed ACS 5.4 and we are looking to authenticate our Anyconnect users with ACS via Active Directory. I think I have the correct commands in our ASA ( we had ACS 4 and authenticated our anyconnect users ).
 
I also have configured ACS to use Active Directory  and installed the server side cert in ACS. I'm just uncertain how to program ACS to use the security group that I have setup in Active Directory.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS5.3 - Configuring Multiple Identity Sources

Aug 28, 2012

I have an ACS 5.3 cluster, that is configured to use AD. There are a few wireless devices, and monitoring tools that do not have AD accounts. I would like to configure ACS to first check AD for the user authentication, and if that fails to roll over to the local (Internal Users) identity source where I can define these user accounts.
 
It seems that when the authentication hits the initial Identity Policy rule, it never moves onto the next one if the first fails.
 
Attached are screen shots that show how i'm configured for the test, i have a local user defined and I'm trying to log into the firewalls.
 
- Identity Definition : Screen shot of the main ACS definition for the rule i'm testing that's not working
- Identity Rule 1 : The configuration of rule 1 that if it fails i need it to move onto rule 2.
- Log Output : Screen shot for one of the failed attempts from the ACS View Log server.
 
Reason I need to configure it this way is:

- Wireless users authenticate to wireless using AD user accounts. Some hand held scanners do not support that and will need to authenticate using the MAC address.
- Authentication to Network devices for managment uses AD accounts. We have some monitoring tools that do not have AD accounts, and will need to    be able to log into Network devices to issue some commands (Examples: Cisco Prime LMS and NCS, Infoblox NetMRI).

View 4 Replies View Related

Cisco AAA/Identity/Nac :: WLC-2500 / Profiling In Identity Services Engine 1.1?

Apr 18, 2012

how profiling works exactly ?How intelligent is the profiling engine, meaning: Will it discover that one device has more than one different MACs and will merge the entries in the database ??
 
Example:This is in fact the same device, there is only one WLC-2500 in the network ....If it can discover that, what needs to be configured on the ISE to do that ?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACL 122 - Setup Identity Firewall On ASA Version 5.6 On DMZ Interface

Aug 27, 2012

I have setup an Identity Firewall on a ASA version 5.6 on a DMZ interface.I have installed the ADAgent on a domain member Win2008 and configured as follows: [code]
 
where ashdew is a domain user and ACL 122(only one line) is applied on the dmz interface and NAT is properly configured.The ADagent has been properly tested and ASA can register to it.The ASA can connect to AD DC controller and query user database.I have placed a laptop ip 172.17.h.x on the DMZ and can ping the DMZ interface.
 
The laptop cannot authenticate on the domain and the asa does not seem to retrieve the user identity.Do I need to add extra rules in the access-list 122 to permit trafic to DC?Can I check on the AD Agent if it can retrieve the user to ip mapping ?

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Connect To Multiple Identity Stores

Aug 15, 2012

I understand that Cisco Secure ACS 5.3 supports the integration with existing external identity repositories such as Windows Active Directory and LDAP servers. In fact, in my environment, my ACS 5.3 is now integrated with AD and RSA.My question here is can Cisco Secure ACS 5.3 integrate with "multiple" WIndows AD, LDAP, RSA Server etc.? if yes, is there a Cisco document stating this? The keyword here is multipple.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Multiple Identity Store For PEAP

Sep 25, 2011

I am trying to setup PEAP authentication for wireless users but I got stuck at place where I have single ssid and users are store in different identity stores like some will be using their active directory and some are locally created users on ACS. I created separate service for wireless authentication and under that I am unable to create rule to differentiate them with identity stores. any idea how to achieve this.
 
I tried creating identity selection based on role but it does not work as for protocol like radius.peap,ms-chap ACS does not look for another identity store once user not find in an identity stores.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Not Getting Single Result Selection Under Identity

May 19, 2013

After clicking on below path we are not getting option as should be reflected. Below is the snapshots for the issues.
 
Access Policies > Access Services > Default Device Admin > Identity

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS V5.3 Identity Selection For Authentication?

Jan 16, 2012

I configured before ACS v4.2 to authenticate network devices using internal users at first, and if the user is not found use AD list users.  But with v5.3 I have some problems doing this, on identity policies I use rule based result selection option, I configured 2 polices for Identity source, one for Internal Users and other policy for AD user, but it only works with the first policy, internal users or AD, but works only for the first policy identity.  how to do that, if the user is not found on first policy, continue to the next policy.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Identity Base Authentication

Jul 3, 2011

I need a specify users to allow access to particular devices and give privilege only for show command or show run. Here is how I tried to configured.
 
1. Configured two seperate Shell Profile and Command set with privilege level 4-5 and allowing only show run command

2. create seperate service selection rule with adding the require NDG and protocol TACACS and maching service "RestrictAccess"

3. In the RestrictAccess Service I have following configured; Identity: internal users, Group Mapping to a particular group where the user exists, authorization: matching the above created identity group, NDG, shell profile, command sets
 
All the steps are attached in the .doc file. However when I tried with the particular user he is able to access everything and he is not hitting the correct access rule.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ISE 1.0.4 - Identity Sequence Refuses To Use AD After RSA

Jan 24, 2012

We are running ISE 1.0.4 with a requirement that on the surface is simple, but fails to execute properly no matter how I tweak it it.  It is:
 
VPN users either need to be within a certain AD group or They need to authenticate against RSA.
 
I set authentication to use an identitysequence with RSA listed first, then AD second.
I set authorization to check identity server (using network access:AuthenticationIdentityStore).
- If it’s RSA, pass it.
- If it’s Active directory, AND the condition with a check on that group membership.  Pass if both pass.
- Set the default authorization rule to deny access.
 
This should work.  Here’s where it breaks down.  It all stems from the fact that the same userIds exist in RSA and AD and that ISE steadfastly refuses to attempt the second identity server method listed in the sequence if RSA is listed first.

• If I list RSA first and the “authentication failed” policy is set to Reject:  For users not in RSA that I want to authenticate against AD, it rejects – it attempts against RSA but never hits AD (second server listed in the Identity sequence).  This is what is brokenThis works for users in RSA

• If I list the RSA server first and the “authentication failed” policy is set to continue Users not in RSA will pass authentication that shouldn’t because the network access: AuthenticationIdentityStore value will be pointing to the RSA server, regardless of whether they actually passed to that server or not.Effectively users can connect regardless of whether their password is right or notThis option sets it to proceed from authentication to authorization

• If I list AD first in the sequence Since the same ID exists in both AD and RSA, it’ll fail as bad password against AD.  It'll never attempt against RSA. 

Am I missing a simple fix for this?  I have a testbed in which I can simulate the issue but since I don’t have an RSA server handy, I’m using an identity sequence with AD and fallback to internal.  It works as I’d expect, falling back from AD to local if the user doesn't exist in AD.  If the user is in AD, it never tries local and shows the attempt as a bad password.

View 3 Replies View Related

Cisco VPN :: VPN From 7965 Phone

Aug 18, 2011

I'm trying to get the phone VPN function working from a Cisco 7965 phone. I can connect fine to the SSL VPN via a normal PC. When I try from a phone, it tries to connect and returns with: "VPN Authentication Failed"
 
yet, when I look on the ASA with "sh vpn-sessiondb anyconnect" I can see the phone has connected fine:
 
Username     : fred                  Index        : 17
Public IP    :  x.x.x.x
Protocol     : AnyConnect-Parent
License      : AnyConnect Premium, AnyConnect for Cisco VPN Phone
Encryption   : AES128                 Hashing      : SHA1
Bytes Tx     : 2417                   Bytes Rx     : 676
Group Policy : SSLClientPolicy        Tunnel Group : SSLClientProfile
Login Time   : 15:05:53 GMT/BDT Fri Aug 19 2011
Duration     : 0h:00m:38s
Inactivity   : 0h:00m:08s
NAC Result   : Unknown
VLAN Mapping : N/A                    VLAN         : none

View 2 Replies View Related

Cisco :: CME Won't Pick-up From A Cell Phone

Feb 19, 2013

I have a CME that has a FXO card, I can call the CME's number from an on-site phone and it works just fine, but when I try from my cell phone it picks up but doesn't give the dial-tone like it's suppose to, but if I hook an analog line to the phone line I can call that no problem from my cell?

voice-port 0/0/0
supervisory disconnect dualtone mid-call
secondary dialtone
timeouts call-disconnect 2
timeouts ringing 30
timeouts wait-release 2
timing hookflash-out 500
caller-id enable

dial-peer voice 201 pots destination-pattern 9T port 0/0/0 and I can see it pick up.

I was under the impression that an FXO card didn't have any clue about inside/outside etc, all it knew was that it was getting a signal to ring.

View 1 Replies View Related

Cisco :: Phone Keeps Registering With Wrong CME?

Jan 6, 2011

I have a CME on the other end of my MPLS network. When troubleshooting phone issues i setup a phone on the CME system in question and point its TFTP server to the address of the CME router. Now, i need to point this phone to another CME but it keeps registering with the previous one no matter what i do (the TFTP server is pointed to the new CME). I have tried turning off the auto register, and i have deleted the ephone and its mac address all together but it always registers with the wrong CME.

The phone is a 7962 with a 7914 expansion module.

View 10 Replies View Related

Cisco :: IP Phone 7906 Is Not Registering With CCM

Feb 19, 2013

I am moving an IP Phone from one subnet to another subnet.I have deleted the IP Phone configuration in call manager(System version: 7.0.1.11000-2); however, when adding the same device (same MAC address) again in the call manager, the call manager associates the phone with the old IPv4 address (even though the phone is turned off). The phone is booting up and getting a different IP address on the new subnet, and is always in the "Registering" state. The phone has the right CM IP, TFTP IP, etc. the only difference is the phone IP address and the IP address that the CM is showing in the phone device configuration. I also tried resetting/rebooting and restore phone to default factory setting but it doesn't work, i have few more devices on this new subnet that are working fine.

View 5 Replies View Related

Cisco :: Manage Phone With Web Interface?

Sep 1, 2011

Is-it possible to manage Cisco phone by web interface? (Manage transfertdiversion... of IP phone)When i go to http://ip_cisco7961 and i give permissions in settings of user (web Access: Enabled)I have only information in read only.

View 4 Replies View Related

Cisco :: LMS 4.1 No Phone Registered In CUCM 6

Nov 6, 2012

the customer has CUCM in the inventory database of LMS 4.1. He has all accesses from LMS to CUCM. One phone 7961 is seen in the UT report. When the customer click on the CUCM in the inventory - there is no IP phone registered in the CUCM.                 

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved