Cisco AAA/Identity/Nac :: ACS.3 Unable To Access Web Interface

Sep 10, 2012

Just got my server team to install ACS 5.3 on a virtual machine.Unable to access the web interface url...Nothing happens when i try and access this.how i can fault find this as i have cli access.

View 8 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: ACS 5.2 Configure Command Set Only To Allow Interface Access?

Jul 6, 2011

I had insatalled the ACS 5.2 on Vmware . As per my requirement i need to configure a user to restricted privilege so that he should be able to execute only the below commands on the switch .
 
-Show ver
-Show interfaces
-Show ip Interface Brief
-Configure terminal
-Interface <interface name >
-Shutdown
-No shutdown
 
The users should not be authorized to execute any other commands than above listed one .After the configuration i was not able to restrict the config mode commands . Once the user is  authoized for  Configure terminal access  he will have full access on the device. How to configure the command set only to allow  interface access and he should be able to apply Shutdown and No shutdown command .

View 6 Replies View Related

Unable To Access My Routers Interface

Jun 6, 2011

I can't seem to be able to access my wireless routers settings on my iMac, whenever I type my router's ip adress in my browser's adress bar it's unable to connect. According to the network settings menu my router's ip adress is 78.21.0.1, I don't know if that has anything to do with it.

View 8 Replies View Related

Cisco :: Unable To Access ASA5510 - Cannot Ping Interface

Oct 22, 2012

I have been working on figuring out a VPN problem on my companies ASA5510. I was accessing the device via: ASDM, SSH using Putty, and even initially with a console cable (also using Putty) using a computer in the networking closet. All 3 of these access methods worked properly for me.I believe I may have inadvertently changed something as of Friday using ASDM. I am mostly assuming this because, as of yesterday I can no longer connect to the device. I actually cannot even communicate with it (ping the interface I normally use to manage, which I could previously ping). No computer on the same subnet as me is able to ping the interface. The device is still accepting VPN connections, dishing out DHCP addresses and everything else it normally does, but I really need to be able to gain access to it again. I am thinking to reboot the device when there is some downtime, in the hopes that ASDM doesn't save to startup-config and only to running-config.

View 5 Replies View Related

Cisco Wireless :: AP1261N - Unable To Access Bvi Interface From Different Subnet

Apr 23, 2013

I can't access the bvi interface I use to manage the AP1261N from an IP address that is not in the same subnet of the bvi interface. The AP is configured as root bridge. Obviously I've the same behaviour for the non-root AP connected to it. For sure it's an ap configuration problem as other devices in the same vlan (vlan1) are reachable by the vlan I'm connected to. This is the conf:
 
version 15.2
no service pad
service timestamps debug datetime msec

[Code].....

View 13 Replies View Related

Cisco :: 5508 - Unable To Access Controller Using Management Interface

Apr 3, 2013

I configure IP address on the management interface port 1 of 5508 controller when i connect it direct to my laptop i can't ping or access controller from my laptop even i connect through layer 2 switch still i can't not.
 
IP Address of management interface : 10.21.0.50
Laptop IP Address : 10.21.0,51

View 13 Replies View Related

L-WR740N - Unable To Access Router Interface After Altering Its IP Address

Jun 17, 2012

I've been trying to configure a TP-Link L-WR740N to act as an access point using the instructions here as a guide. As stated in the guide, I've been changing the IP address of the TP-Link router to a new address that lies outwith the pool of available DHCP addresses in my combined modem/router but with less than resounding success. After rebooting the TP-Link router, I am unable to access the set-up interface - the newly allocated IP address doesn't work, neither does the original IP address work. What is happening here? If I change the IP address to one that lies within the DHCP pool and reboot, I can access it ok with the new address. However, that obviously clashes with the set-up instructions.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Unable To Access CS ACS 1113 Appliance After Enabling HTTPs

Nov 2, 2011

I've recently installed a certificate on my ACS 1113 appliance and in the Admin setup enabled management access over HTTPS. Since then I've not been able to access the GUI console. I have done some troubleshooting and I'm fairly certain that I have a certificate issue as Firefox gives me the error: Certificate type not approved for application. (Error code: sec_error_inadequate_cert_type)when I try and connect. So I want to either reconfigure the management access to use just HTTP or remove the certificate. I have logged on to the serial console and there are no options her to do this. The RADIUS and TACACS functions are working correctly - I just can't logon via the GUI.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACL 122 - Setup Identity Firewall On ASA Version 5.6 On DMZ Interface

Aug 27, 2012

I have setup an Identity Firewall on a ASA version 5.6 on a DMZ interface.I have installed the ADAgent on a domain member Win2008 and configured as follows: [code]
 
where ashdew is a domain user and ACL 122(only one line) is applied on the dmz interface and NAT is properly configured.The ADagent has been properly tested and ASA can register to it.The ASA can connect to AD DC controller and query user database.I have placed a laptop ip 172.17.h.x on the DMZ and can ping the DMZ interface.
 
The laptop cannot authenticate on the domain and the asa does not seem to retrieve the user identity.Do I need to add extra rules in the access-list 122 to permit trafic to DC?Can I check on the AD Agent if it can retrieve the user to ip mapping ?

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Identity Groups - Restrict Device Access

Apr 14, 2011

I have ACS 5.2 running as a VM.  I'm AD, then local authentication successfully for device access, but I want to define ACS user groups to restrict login. I don;t see any way to do this.  If I use AD groups, they don;t show up as selection options on the policy screens, just the ACS locallyy defined groups. 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Web Interface Not Working

Mar 31, 2011

We have a Cisco Access Control Server (TACACS+ version 5.1) with an additional 2 port NIC card. This produces 4 ports on the ACS server(G0 through G3).After initial setup of the ACS server with an IP address on G0, I connected a Windows 7server with IE8 to G0. The ACS web interface appears (after accepting certificate) and Ientered some user accounts and NDGs.I then connected the ACS server to a configured port with port-security on our 6500switch. The port becomes err-disabled since the MAC address does not match up. It appearsthat the onboard NIC on the ACS server is bonded thus producing the MAC address issue.To fix this connection issue, on the ACS server, I cleared out G0 and setup G2 (additiional NIC card) with the IP address. After connecting to the 6500 switch, the ACS server port works fine. I removed the connection to the 6500 and connected the Windows server to the ACS.I can ping the ACS server but the web interface is now unavailable unlike before. I do not get a certificate warning on IE, it just states that internet not available. On ACS, the 'show' status of acs shows all the processes are running and initialized. It has got me stumped as all I did was change NIC configurationon the ACS server.

View 8 Replies View Related

Cisco AAA/Identity/Nac :: C4948-10G / Tacacs+ Not Working On VRF Interface?

Feb 3, 2013

C4948-10G switch running IOS 15.0(2)SG ?ACS 4.2 cannot authenticate on the vrf interface. The issue on vrf aaa authentication.
 
aaa new-model
!
!
aaa authentication login default group tacacs+ local
aaa authentication login no_tacacs local
aaa authentication enable default group tacacs+ enable

[code]....

View 13 Replies View Related

Cisco AAA/Identity/Nac :: 4500 / Interface Is Up / Line Protocol Is Down (not Connect) / Dot1x?

Aug 11, 2011

I configured dot1x on my swicth 4500 series, Here is the interface configration:

interface FastEthernet3/2
description Test dot1x
switchport mode access
load-interval 30
authentication event fail action authorize vlan 800
authentication host-mode multi-host
authentication port-control auto

[code]....
 
When I remove the port-control configuration on the interface, the status change to UP/UP.

View 1 Replies View Related

AAA/Identity/Nac :: Cat4500e ISE Support On Third Party Switch Doing 802.1x Authentication On Interface

Jun 8, 2013

how ISE support on third party LAN switch, if the requirement is doing 802.1X based flexauth.Refer to the diagram i attached; 01 topology.png
 
Concern  1: if the 3com switch with 802.1X feature, but still without the full  feature to support FlexAuth, policy encforcement, DACL etc. In this kind  of situation, will user still able to authenticate (using method  PEAP-MSCHAP v2), but authorization just grant with permit any any?
 
Concern  2: Can i assume i authenticated the 3com switch using  MAB? But this will cause endpoint with no 802.1X, am i right?
 
Concern  3: cisco switch C4507-E, loaded with IOS version  Cat4500e-UNIVERSALK9-M, version 03.04 and Supervisor Engine  :WS-X45-SUP7-E, is this platform is supported in Cisco TrusctSEC?

View 2 Replies View Related

Cisco Switches :: Unable To Get To Web Interface For SG200-18

Aug 24, 2011

I got a new switch and am trying to connect a UCS server to it.  I can ping the switch just fine but when I try to use IE8 or firefox, I can't get to the web interface to configure it.
 
Here's my setup:
 
Cisco UCS C210 M2
IP = 192.168.1.100
Subnet = 255.555.255.0

[Code].....

View 2 Replies View Related

Cisco :: Unable To Configure An 887va Vdsl Interface

Aug 24, 2012

Just got hold of my first 887va for my home, never configured a vdsl interface before and was just wondering if my setup looked good to someone whos done it a few times.

View 6 Replies View Related

Cisco WAN :: 1760 Unable To Enable Policy Map On Interface

Sep 6, 2012

Class and Policy maps are defined properly but when I am going to apply the policy-map on interface ,throwing an error as "'set' command is not supported in a 2nd level policymap".
 
Class/Policy map configuration given below ....
 
class-map match-any cm_traffic_control
  match access-group name acl_traffic_control
class-map match-any BE
  match access-group name be
[Code] ....

View 8 Replies View Related

Cisco AAA/Identity/Nac :: Unable To Use ACS 5.2 With Logs?

Sep 6, 2011

I have 3 ACS servers placed throughout N. America. I it set up so that ACS01 is primary and ACS02 and ACS03 are secondary. When i look at the logs for passed/failed authentications in radius or tacacs I cannot see anything from ACS03 logging. This is weird because just a few weeks ago it worked perfectly. In fact, ACS03 is the most active server since this site is using it for wireless phones and tacacs and the other 2 are just using ACS for wireless networking. I went through the log settings and every server is set up the same as the others (except the primary) so it should be logging ACS03 the exact same as 01 and 02.Anyway it seems like a small problem but i need the logs to work correctly to properly administrate security.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Unable To Upgrade To ACS 5.4?

Nov 11, 2012

I'm currently running ACS 5.3 Patch 7 in a VM on VMware ESXi. I download the application upgrade bundle, and placed it in my SFTP repository, and ran "application upgrade filename repository name". It throws an error that the manifest file is not found in the bundle.
 
I tried putting the ACS.gz file in an FTP repository, and even in an ISO file to attach to the VM. In all cases I receive this same error.I did verify the md5sum on the file to make sure it wasn't corrupted..

View 6 Replies View Related

Cisco AAA/Identity/Nac :: Unable To SSH To ACS 4.2.0.124 SE Appliance

Feb 20, 2010

I could not SSH to ACS SE appliance? Why I could not, however I can do on another ACS SE.
 
note that I can ping the ACS SE, after disabling the CSA, so netowrk connectivity is ok.
 
Cisco Secure ACS: 4.2.0.124.

View 5 Replies View Related

Cisco WAN :: 886VA / Unable To Set PPP Multilink On Interface BRI0 And Dialer / IOS

Oct 15, 2012

I am configuring ISDN Interface on 2 Cisco 886VA Version 15.2(3)T . I am unable to set ppp multilink on the BRI0 interface and on the dialer interface. It's like the command doen't exist anymore.How can I fix that so that i can have 128 K bandwidth between ma 2 sites ?.

Router1#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router1(config)#int bri0
Router1P(config-if)#ppp multilink

[code]....

View 2 Replies View Related

Cisco Switching/Routing :: Unable To Ping / SSH To Interface On 3925?

Jan 9, 2013

I just barely put in a Cisco 3925 on our network. I've configured gigabitethernet 0/2 to live on our management VLAN with an IP address of 10.129.0.31/16. I did a "no shut" on the interface. Everything should be ready to allow me to ping and/or SSH to that interface but I can't. It's really weird because I've done this a thousand times (at least on ASAs). I must be missing something. At any rate, the default gateway of the management VLAN is 10.129.0.1. I can ping that from the router. I can also ping that from my laptop (which lives on a completely different VLAN). But I can't ping the router from my laptop or vice versa.
 
Building configuration...
 
Current configuration : 1360 bytes
!
! Last configuration change at 19:05:13 UTC Thu Jan 10 2013
!

[Code].....

View 4 Replies View Related

Cisco Switching/Routing :: Unable To Policy Switchport Interface Of 861

Jul 24, 2012

I'm unable to apply a policing limit in a switchport of the CISCO861 router. This is my configuration:interface FastEthernet0, service-policy input wired-input,service-policy output wired-output end.

View 3 Replies View Related

Cisco Firewall :: ASA 5510 - Unable To Communicate Between Interface Networks

Apr 20, 2011

I have an  ASA 5510 working in Routed mode for a company with the following networks. everything works fine as desired. Below are the interfaces, security and  ip addresses .
 
Ethernet0/0   DC_SERVER   security-level 100
ip address 172.16.11.12 255.255.255.0 
Ethernet0/1  Branches  security-level 50

[Code]....

View 1 Replies View Related

Cisco Firewall :: ASA 5505 - Unable To Assign IP To DMZ Vlan Interface

Oct 26, 2012

I have ASA  5505 with base license. I created 3rd  vlan on it.it was created. but i am unable to assign IP to it. i assign ip address it takes it. But when i do sh int ip brief it does not show any ip.
 
Code...

View 7 Replies View Related

Cisco Firewall :: ASA 5510 Unable To Ping From Outside Interface Or Cloud

Nov 27, 2012

One of my client has BSNL leased line with LAN IP POOL we configured those on ASA 5510 nad Internet working fine but from cloud we are not getting any response for ping requiest please find running configuration below:
 
ciscoasa(config)# sh run
: Saved
:
ASA Version 8.2(1)

[Code]....

View 4 Replies View Related

Cisco Firewall :: 4710 - Unable To Ping From MZ To Virtual Interface Of ASA

May 3, 2012

one of my SNMP server 10.242.103.42 sits in MZ zone,and ACE 4710 is connected to core switch,coreswitch is connected to firewall asa.
 
Now iam trying to ping from MZ zone SNMP server to loadbalancer ip 10.242.105.1,iam unable to ping my LB interface to discover SLB on my SNMP server.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Unable To Make Backup In ACS 5.1

Jan 28, 2012

When I'm trying to make backup in ACS5.1(in log collector node) it gives me the following error:

FullBackupOnDemand-Job     Incremental Backup Utility     System     Wed Jul 13 16:50:23 EEST 2011     Incremental Backup Failed: CARS_APP_BACKUP_FAILED : -404 : Application backup error     Failed,I did it via Monitoring Configuration -> System Operation -> Removal and Backup and then "Backup now" bottom.

I tried to restart ACS services through cli (application stop/start) and different repositories (ftp, tftp) but without success.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Unable To Change Password

Mar 16, 2011

Since some months I'm running ACS 5.2 appliance without any problems.When I want to change the password from a local user there's a popup message:
 
"This System Failure occurred: {0}. Your changes have not been saved.Click OK to return to the list page." I tried different users but I am not able to change any password. Always the same message.

View 12 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.x - Unable To Backup By SFTP

Apr 5, 2011

I am not able to backup ACS 5.x server by means of SFTP protocol. We use ACS 5-2-0-26-2. My configuration of repository is:
 
repository SFTP
url sftp://x.x.x.x/home/user
user user password hash 455ad
 
command 'backup acs01 repository SFTP' does not work and I receive the following error message on ACS server:
 
%SSH connect error
 
On my sftp server I can find the following error messages:
 
Apr  6 06:57:46 CR01 sshd[8561]: Accepted password for user from 10.20.86.72 port 47924 ssh2Apr  6 06:57:46 CR01 sshd[8563]: Received disconnect from 10.20.86.72: 11: disconnected by user

How to successfully performed backup by means of SFTP protocol? Do I need any other configuration settings except repository? Do I need to store my SSHD RSA key to ACS? I am able to copy files using SFTP from other computers, so it seems that SFTP server is set correctly.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Unable To Make Backup In ACS 5.1

Jul 12, 2011

When I'm trying to make backup in ACS5.1(in log collector node) it gives me the following error:
 
FullBackupOnDemand-Job     Incremental Backup Utility     System     Wed Jul 13 16:50:23 EEST 2011     Incremental Backup Failed: CARS_APP_BACKUP_FAILED : -404 : Application backup error     Failed
 
I did it via Monitoring Configuration -> System Operation -> Removal and Backup and then "Backup now" bottom.
 
I tried to restart ACS services through cli (application stop/start) and different repositories (ftp, tftp) but without succes.

View 8 Replies View Related

Cisco Wireless :: 6500 Unable To Reach WISM2 Management Interface

Mar 28, 2012

I've just reset our WISM2 in the test lab back to factory default as I needed to reconfigure the 6500 and the WISM2 itself. Bearing in mind I had it working before.I've just renamed and re-addressed some of the vlans so things flow better and make it easier to add more WISM2s in the future.Now I've run through the initial configuration and it's rebooted ok and show WISM status is showing Oper-Up and there's a port channel 407 been created as I would expect. However, I am unable to get to the management interface via GUI or SSH. In fact from the 6500 I can't even ping the management interface (but I can the service port).The Vlans have been changed in the 6500 config so it knows the native-vlan and service vlan etc and all the vlans are up/up.

View 17 Replies View Related

Cisco Firewall :: 5510 Two Subnet Unable To Talk To Each Other On Same Inside Interface

Mar 8, 2011

I have setup two different subnet 192.168.1.0 and 192.168.2.0 on the same 'inside' interface. They are unable talking to each other. I can ping from firewall to both subnet. Both side unable talking to each other unless I add route on the both side systems.I have added the followings in ASA5510. [code]

View 8 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved