Cisco AAA/Identity/Nac :: ACS 1113 SE - Windows Updates?
Jul 18, 2012
Does cisco provides updates for underlying windows server in ACS SE 1113 ? Patch updates are available for ACS 4.2 , but how can we update underlying windows server , Does patches for ACS is enough to secure underlying windows server .
I'm working with a 1113 ACS device running the 4.2.0.124 software. I'm trying to get multiple network device groups to use an existing Remote Agent set up for authentication against our Windows domain. For instance, we want our infrastructure switches to authenticate agains the local Active Directory and our WLC to authenticate users agains the same Active Directory. When I try and set both network device groups to use the same remote agent, it fails and reports either the host name is already in use or the IP address overlaps with an existing remote agent.
The question is:
Can I have multiple network device groups use the same remote agent? Or do I have to install the remote agent software on separate Windows servers in order to have different types of devices authenticate against the Windows AD?
we have a Cisco ACS 1113 SE running v4.0.1.44 and are trying to upgrade it to v.4.2.0.124 following the instructions to upgrade it to v4.1.1.24 first.
We are using the following CD "ACS SE Overall Upgrade CD ACS 3.3.4 and 4,1,1,24 Upgrades"
We can download the 4.1.1.24 image to the ACS appliance via distribution server but the upgrade fails- we obtained the following console output when attempted upgrade was tried;
Upgrade package was not verified Applying this upgrade package may corrupt the appliance Continue at your own risk!
I have some VSAs to import into my 1113 box, but I am stuck before I can even start :-( I have an accountActions.csv file containing some VSAs (this is just a test csv file.) I also have an FTP server that is accessible from the 1113 system.
When at the GUI for the 1113 I do System Configuration --> RDBMS Synchronization I get the RDBSM Synchronization Setup screen all right. I have entered all the parameters associated with the FTP server, and selected manual synchronization. The problem is that there are no entries in the AAA Servers window at the Synchronization Partners section at the bottom, and therefore I can't get the 1113 to retrieve my accountActions.csv file, an action that (I guess) is triggered by clicking on the Synchronize Now button.
I do have an AAA Server defined in the 1113. It's a RADIUS server called Self, not assigned to any NDG.I guess I do not understand this at all. I just want to import some external VSAs. Do I need to have an external AAA server to accomplish this? If not, how do I get my local Self server to appear in the list of synchronization partners?
3)applAcs_4.2.1.15.8.zip (ACS SE 4.2.1.15.8 cumulative patch)
take it forward to upgrade by step by step procedure. ( is that same like TFTP to transfer these packeges to appliance or different method? ) (we are using Windows XP system)
I tried to re-image a cisco 1113 ACS appliance into windows 2003 and was successful. I suppose to use this for my staging/LAB.My only problem is the NIC cards shows unknown since no appropraite driver was found. Googled for a few days but ends up nothing. What is the exact driver?
I want to gather an inventory of all devices that shows the AAA client name, IP addresses, authentication method and key under my Network Configuration on my ACS appliance. Is there a report to run in it that will shows this, or is something that has to be done manually?
I have an 1113 acs server which is not booting and hanged. Earlier its was working but i am facing the problem from today. I capture after reload the devices its asking for press F2 and F12 but when i try to do same its not allow to do the same.(Also attached the capture)
When i try to check the same through connect the desktop and reload the devices its showing the Cisco logo screen after that its showing the blank screen.is the ACS gone faulty or I will have to try with reimage the devices.
Our ACS appliance (Cisco 1113) has died and it is not cost effective to get it replaced as it will only be used until the end of this year.Is it possible to get the tacacs software to install on a Windows server? How do I go about sourcing the software as the original documentation is no longer available? Will the fact that I have a defunct appliance be sufficient proof to get a copy of the software? We are currently running v4.1
I just just purchased a CSACSE-1113-K9 and I need to wipe the Administrator password. I am also not sure what the default login credentials even are. There doesn't seem to be much out there for this device or maybe I'm just looking in the wrong place?
Having CSACSE-1113-K9 with ACS 4.2.15.I want to configure windows user database under extrenal user database but i get an error (attached) 'An error has occured while processing the Authen DLL Configure pagebecasue an error occured.I tried to stop the services and start agian but the same issue. The eappliance is secondary (backup) ACS. On the primary it is working fine.
I've recently installed a certificate on my ACS 1113 appliance and in the Admin setup enabled management access over HTTPS. Since then I've not been able to access the GUI console. I have done some troubleshooting and I'm fairly certain that I have a certificate issue as Firefox gives me the error: Certificate type not approved for application. (Error code: sec_error_inadequate_cert_type)when I try and connect. So I want to either reconfigure the management access to use just HTTP or remove the certificate. I have logged on to the serial console and there are no options her to do this. The RADIUS and TACACS functions are working correctly - I just can't logon via the GUI.
Any relevant doc for ACS4.2 on 1113 platform to be integrated with Unix Directory service having LDAP10.2.0.0 version from Oracle or guidance available.
I Have a requirement to migrate from ipv4 to ipv6, I have checked the scalability of all the devices for this migration except ACS 1113 Solution Engine, Version 4.2. I couldnt reach the proper documentation to check its support for ipv6.
We have currently LMS 3.2 installed. We know have some new switches C2960-48PST-L that are not supported in CiscoView and Common Services.When trying an update in Software Center | Device Update, we receive an error message:Error while downloading package information from Cisco.com for the selected products. See the C:/PROGRA~1/CSCOpx/log/psu.log file for details.
The psu.log file shows the following: [ Wed Sep 26 14:33:15 CEST 2012 ] INFO [SecurityHandler : getCSProxyLogin] : No proxy User Name configured [ Wed Sep 26 14:33:15 CEST 2012 ] INFO [SecurityHandler : getCSProxyHost] : No proxy Host configured [ Wed Sep 26 14:33:24 CEST 2012 ] INFO [SecurityHandler : getCSProxyHost] : No proxy Host configured [ Wed Sep 26 14:33:24 CEST 2012 ] INFO [SecurityHandler : getCSProxyPort] : No proxy port confgured [ Wed Sep 26 14:33:26 CEST 2012 ] INFO [SecurityHandler : getCSProxyHost] : No proxy Host configured [ Wed Sep 26 14:33:26 CEST 2012 ] INFO [SecurityHandler : getCSProxyPort] : No proxy port confgured
I am on my second 3520 Laptop (first one purchsed in November 2012, returned last week) and the same problem is happening. This is that after every Windows Update I am unable to connect to the Internet. Wi-Fi checks out and used by other PC's in the house, I thought I'd cured it recently by being able to go in and sign into Mcafee (22/1) then an update on 23/1 and BAM! No Internet, no way can I get into McAfee to sign in, and the only options are restore to 21/1 (did that still no joy) or back to Factory (23/12/12) and re-install Office 2010 AGAIN! I have spent over £10 in calling the Dell Premium line, I have emailed the Support Director who arranged the laptop swap and still have this problem. I have posted it on Windows 8 forums, other forums I can find, Googled 'No Internet after Windows8 updates' 'till the cows come home, have gone back to Factory about 10 times over the 2 machines, tried to create Restore points myself but they disappear after the updates, all very frustrating. I 'could' get a refund but this is the 6th Dell machine we've had and I like the support. This machine, like 2 others (1 on Vista about to be upgraded to Win7 the other just upgraded) this new one will be used in a church based Debt Advice charity so eventually will be in a cupboard and used every Wednesday by an admin volunteer. It will be a terrible pain to have this trouble as she's not that young nor a PC expert so I need a seamless, invisible solution that will work without a hitch like all updates in XP, Vista and Win7.
I have a ACS 1113 appliance (4.2 ver), I am trying to recover the forgotten password, when i insert the disc and restart the SE it's not showing the prompt to recover the password, i checked the boot path and priority everything is fine, the recovery disc is also fine ther r no issues with that it has been created as a bootable disc
we have some strange problem on our c7200 IOS 12.2(31) with an e BGP peer. the eBGP session begins as usual and without any problem, all prefixes (Full BGP table) are announced to the neighbor, of course during this time the CPU goes high up to 80%. Then the both peers are in sync and traffic run as usual, but after some minutes the CPU goes again up to 80% and the debug on the neighbor side shows that it gets again the BGP updates for all BGP prefixes from our 7200 with "rejected - duplicated" comments for every received prefix, it means that it gets the updates for prefixes which are already exists in BGP table.
And it happens every 3-5 minutes. Truly said I can't explain why our 7200 always tries to send the Full bgp table again and again. The work-around was to configure the peer with "soft inbound", it's OK and we'd like to use it anyway , but from my opinion BGP shouldn't send Full BGP table very 5 minutes without "soft inbound" as well.
Having issue in applying package updates in LMS 4.2.3?
I am getting an error whether going via the GUI or CLI. The key issue appears to be (according to the PSU.log):
[ Sat May 11 16:41:25 EST 2013 ] ERROR [PsuPkg Resolver : pick Unselected BasePackages] : Consistency check failed for base package SharedSwimRtr800(2.2) I have the version 2.0.1 of SharedSwimRtr800: 327.SharedSwimRtr8002.0.1SharedSwimRtr800 device package
And I can't seem to find 2.2 anywhere in the downloads section for LMS 4.2
I have a PS3 and I just got wireless internet. I was excited to update games and such and I knew it would be fast because both are close together. Every time I get done downloading one update, it gives me an error and I've found it to be dmz. It works on every other device but that one. I'm using a brand new Apple Airport Express and it's fully configured and I use Vista.
I have Prime 1.3, two WLC 5508 and 8 switches 2960s I try update my devices through Prime, but I can't.
When I start "Upgrade Analysis" and select switch (Catalyst WS-C2960S-24PS-L) and image (c2960s-universalk9-mz.150-2.SE2.bin) then click to "Run report"
Prime shows me that "Image not Applicable for this Device" I try different images, but it does not work.
And with WLC 5508 the same trouble. Why Prime can't do right analysis and updates devices?
I have a problem downloading software and device updates for LMS 4.0.1.
In the psu.log I get the following:
[ Mon Nov 26 12:51:51 CET 2012 ] INFO [SwUpdateAction : getUpdatesFromCCO] : Validated Cisco.com credentials.. [ Mon Nov 26 12:51:51 CET 2012 ] INFO [SecurityHandler : getCSProxyHost] : No
We are a relatively new Cisco partner. We used to work with CDW and now we are buying from distribution and selling directly. We buy a lot of ASA 5505 units from D&H.
My question is, aside from the disc that comes with the unit where do we download the latest firmware image and management software? It appears you have to have a contract ID to get these through the Cisco website. Do we not get "car blanche" access as a Cisco partner to these resources?
Also doesn't the Cisco ASA 5505 at least come with a license for the latest firmware? Many ship with very old software and even old CDROMs.
We have the RVS4000 and have IPS turned on. How can I be notified (email would work) when updates to the IPS signatures are available, so I can keep our IPS signatures current?
Im trying to setup 802.1x with ACS 5.2 but am struggling as its very differnet to ACS 4.2.I have setup the ACS to be the domain and think i have setup up the External Idnetity Store, however when i try to authenticate a pc using authentication Medthod 'PEAP (EAP-MSCHAPv2), i get a failure reason '22056 Subject not found in the applicable identity store'
I searched cisco documents where as all the documents are having example of ACS 4.0 but i am very keen to know with ACS 5.0 integrated with AD. Any document especially with ACS 5.0 , it would be great for me to understand the ACS 5.0 set-up.
Running Windows 7 64bit, ISP is EATEL connected through a PACE 3801HGV to a new Linksys EA6500. Since the initial setup ( I was walked through the setup via Linksys support) I cannot access windows update, (the error screen tells me to restart my computer, "Windows update cannot currently check for updates because the service is not running. You may need to restart your computer", and I have done so 25 times) and I cannot update my Microsoft security essentials. Windows firewall tells me that the 'advanced settings snap-in' failed to load. Is it safe to uninstall and try to reinstall these or is there a way to start the services?