Cisco AAA/Identity/Nac :: ACS 4.2 Changing IP Address
Apr 6, 2013I need to change the IP address of existing primary cisco ACS 4.2 (windows based). What is the required procedure to change the IP address?
View 4 RepliesI need to change the IP address of existing primary cisco ACS 4.2 (windows based). What is the required procedure to change the IP address?
View 4 RepliesI need to change the timezone of two ISE 1.1.2 servers. One primary and one secondary. Both are set to "EST" timezone and i would like to change them to AMERICA/Montreal because they are now one hour late since day light saving change.
According to the release notes, it is not recommended to change the timezone on ISE after the installation. I'm thinking of doing a backup of the ISE application (in the maintenance GUI or CLI) and then changing the timezone on both servers. After the change the ISE servers will gain one hour. So after i will do a restore of the backup i did just before the timezone change. The timestamp of the backups will be older then the current time of the servers.
Will this work? Is it the best way to change the timezone?
I use ACS appliance 1120 for cisco devices administration. The identity store is external. I use Active directory. Actually, Authentication, authorization and accounting work well but users can not change theirs Active directory password when they have expired. Do you now how to configure ACS to permit password changing?
View 5 Replies View RelatedI tried changing my ip address using ipconfig / release. I tried to fix what I did using ipconfig /renew but it tells me no operations can be performed on local connection 5 while it's media is connected.
View 12 Replies View RelatedI am trying to configure a router with a satellite connection. I am following a HughesNet guidline. At step four after typing in the required IP address , nothing happens.There is no place to type user name and password.
View 2 Replies View RelatedHow to change ip address in windows 7?
View 1 Replies View RelatedI am connected to a static ip network. This network sets local ips to connected computers but general ip is the same: static ip of network. When i go to "whatismyipaddress", I can see this static ip. I want to change my ip address. I have no chance to use proxy server or router connection. Is there a way to change my ip address? (Because some sites ban ip address, ex:rapidshare etc. and I need to change my ip)
View 1 Replies View RelatedI found this good guide how to do it, but some things remain unexplained to meI would like to get more information about step:3. Change the IP address of your current PCMaybe more questions will follow, but that's the only problem I am having right now.
View 11 Replies View RelatedI've had the same IP address for years and want to change it to a new one - I have a dynamic IP but for some reason it will never change.It looks as if it's always static-what settings I need to change on Windows 7 to get it to roll over onto a new IP address?
View 1 Replies View RelatedTrying to change my IP address in windows 7. I downloaded Desktop Central 7.Server and Desktop Management Software: Now what am I suppose to do?
View 2 Replies View RelatedI am trying to move a device from the Default location to a sub group and get the following message when I try (either with IE or Firefox)
This System Failure occurred: Index : 0, Size: 0. Your changes have not been saved. Click OK to return to the list page.
it also gives me the same error if I try and change the Device type from default to a sub group. I'm sure I could do this previously. The ACS build is (VMWARE install):
Cisco Application Deployment Engine OS Release: 1.2ADE-OS Build Version: 1.2.0.228ADE-OS System Architecture: i386
Copyright (c) 2005-2009 by Cisco Systems, Inc.All rights reserved.Hostname: ACS1
Version information of installed applications---------------------------------------------
Cisco ACS VERSION INFORMATION-----------------------------Version : 5.3.0.40Internal Build ID : B.839
I'm suspecting it a read/write issue with the database or a database corruption. I have stopped and started the application acs via the console and show application status acs has the following to say about itself.
ACS1/admin# show application status acs
ACS role: PRIMARY
Process 'database' runningProcess 'management' runningProcess 'runtime' runningProcess 'view-database' runningProcess 'view-jobmanager' runningProcess 'view-alertmanager' runningProcess 'view-collector' runningProcess 'view-logprocessor' running
I added a new server and created a new static NAT assignment on the ASA 5510 to the server's IP. When I browse to the web to check what public IP it's reporting, it shows the wrong IP. I disabled the network interface on the server, ran "clear xslate", reenabled the network interface, ran "sho xlate" and while the correct translation was in the table, the server still reported the wrong IP address.I even ran a packet trace and it showed the IP address being correctly translated to the proper public IP, but when I browse to the web I get the same erroneous public IP. [code]
View 8 Replies View RelatedI have a new 881 router and am simply trying to change the ip address from the default 10.10.10.1 to 192.168.15.1
I tried doing this both in the CCP Express app loaded on the router, and also using the desktop CCP client. I can change other parameters without any problems, but when I change the ip address of the vlan the program hangs (as expected since the ip address should be changing). I then try to open it back up and reconnect but get no response from the router.
I can ping it no problem, and the http server is running according to the serial terminal.
How can I change my ip address on windows 7. Someone hacked my computer before and now im afraid that he will do it again. I want to secure it by changing my ip address..
View 2 Replies View RelatedMy Network is running Windows Server 2003 and with more than 150 Users. But last week, I notice that a program is changing my DHCP server IP Address scope.
View 2 Replies View Relatedwell i had the same problem because i got bored and i was like hmm i wonder if i can change my IP and i tried it and i had the same problem but when i did system restore it still did not work, now i have to get a new operateing system...
View 10 Replies View RelatedI have a new router. this seems to be a very simple problem relating to the most basic configuration options.
Hardware Version: A1 Firmware Version : 1.01NA
go to SETUP -> "NETWORK SETTINGS"
change "Router IP Address" to 192.168.73.1
change "DHCP IP Address Range" to: 192.168.73.10 : 192.168.73.200
Save Changes Wait for reboot. change my client system's local IP address... so that I can reconnect. direct web browser to http://192.168.73.1/
seen: login page has a select-box for a userid, but no text inside. there is no prompt to ask me to login. I press enter (or whatever... I login). every form interface on all web pages looked at have no labels on text boxes.
I did a view source... and used web-dev tools to look at the page. it looks like the apparent js function, show_words(), is not defined.
change ip address and dhcp address range back to default save changes. wait for reboot. reverse changes to local system things are back to normal. login page has useful text. after logging in, there is something to read.
looking at source again. I see, now, that the js function "show_words" is defined in a file called public.js.
How i can change my ip address without changing my internet connection??
View 3 Replies View RelatedMuch of the time my wireless printer is offline relative to computers on my LAN because the IP Address has been changed to some value different than what the computer thinks it should be. So I have to figure out what the IP Address is of the printer then modify the printer port on the PC to point to the correct address. If this only happened rarely or if I could easily remember the steps I have to take to remedy the situation, I guess this would not be such a big deal. But it happens a lot and I'm old and alzheimery. So my question is: how do I get the router to assign the same IP Address to the printer all of the time?
View 2 Replies View Relatedhow to change the IP Address on a Dell C3760dn Color Laser Printer?
View 4 Replies View RelatedI'm adding another router to my home network to extend my WiFi range. (Linksys e2500.) I'm trying to change its IP from the default 192.168.1.1 so that it doesn't conflict with my primary (dhcp) router.
To isolate matters I've reset the router to factory settings, turned off my mac's WiFi and then connected the Mac to a Lan port on the router. Now I can view the router's admin page at 192.168.1.1.
Now I change its local IP to 192.168.1.3 and leave the subnet as 255.255.255.0. The router reboots and after several minutes is inaccessible at any IP I try (still hardwired to the Mac with WiFi off). Ifconfig doesn't show the router and the only way I can get it back is to factory reset it again.
I have verizon fios internet and a wireless home network with verizon internet security and I want to ghange my IP adress on my laptop
View 6 Replies View RelatedHow can I change the IP Address of cisco ACS 5.2 itself through the web?
View 3 Replies View RelatedIs it possible to create an ip address pool for ip address assignment in ACS 5.3, like it used to be possible in 3.x and 4.x?
View 2 Replies View RelatedWe recently had to rebuild our ACS server. Now when we have an 802.1x authentication failure and look at the RADIUS logs for the specific user, it does not show us the MAC address of the device the user tried to login with. We use this all the time because users have PDAs and other mobile devices that they save their passwords on. Then when they change their domain password on their laptop, they don't change it on their PDA which then tries to authenticate them using the wrong password and eventually locks them out. We need to see the MAC address so we can pinpoint which device is causing the lockout. The report I am generating is when you go to this location: Monitoring & Reports > ... > Reports > Catalog > User > User_Authentication_Summary
View 4 Replies View RelatedCustomer is running acs4.2 and need to upload thousands of mac addresses in ACS database for MAB. how can this be done? does cisco suport csv file import in acs4.2 or any other utility?
View 1 Replies View RelatedA short background. Our corporate SSID is being migrated from using PEAPv0 to EAP-TLS. This restricts access only to company notebooks. Additionally we have barcode scanners which are used to inventory assets. Those devices are not able to use EAP-TLS as they cannot be integrated in the domain and being unable to do certificate based authentication.
As a workaround we planned to use another SSID with access to the same network but using PEAPv0 as authentication method, basically the same SSID but with a different name. As this naturally allows anyone to access the corporate network with a valid username/password I now wanted to add another step into the authentication process - the MAC of the device. I know I can do the filtering at the WLAN controller, but as it has a limited database as well as the fact that it is cumbersome to maintain the MAC list on all the controllers I thought I can do it over our ACS system.
I am now trying to accomplish the following: The user gets authenticated via the internal user store, which is succesful. Now I want to authorize the user via the MAC address, which is stored in the internal host store of the ACS, if access is granted or not.
For this I created the following policy:
Service Selection Policy -- (Rule based result selection)
-- (NDG:Device Type in All Device Types:Wireless And RADIUS-IETF:Called-Station-ID contains <SSID>) | Result: PEAP access
-- Default | Result: DenyAccess
Service PEAP access Identity: Internal Users -- (Single result selection) Authorization -- (Rule based result selection) -- Internal Hosts:HostIdentityGroup in All Groups:Valid_MACs
When I then try to access the wireless network I won't get authenticated. The error I get, when I look into the logs is: 15039 Selected Authorization Profile is DenyAccess
Is it not possible to use one identity store as "attribute database" for the other identity store?
I want to use RADIUS (of Secure ACS 5.3) to authenticate users within an ISP environment. Users log connect to a network using a point to point connection (L2) and then they are sending a RADIUS request to get IP adresses. Secure ACS is not quite easy to look through in that case.
View 3 Replies View RelatedI'm currently evaluating a scenario where AAA request are load balanced across multiple ACS 5.3 instances. The application delivery controller runs in L3 mode, which naturally causes the original packet's source IP address to be replaced by a randomly selected proxy address.As far as RADIUS is concerned, I can perfectly determine the originating NAS by means of a 'Device Filter' condition. Unfortunately, ACS seems to lack the possibility of achieving the same for TACACS+. According to the user manual, only the actual IP address from the received packet is taken into account. I've also come across the 'NAS-Address' attribute in the protocol dictionary, but it can't be used in a custom condition either.how to retrieve the initial device IP address from a TACACS+ request in order to use it for further policing?
View 8 Replies View RelatedWe have c3750s running NAC 4.8. Occassionally, a workstation will flap between the untrusted and trusted vlans. We updated the NIC drivers on the workstation, we verified SNMP was functioning correctly on the switch, and we allowed the phones to act as the pass-through between the workstation and the switch. What could cause the workstation IP Address to not redirect to a TRUSTED VLAN from the NAC_UNTRUST VLAN? All updates have been downloaded to the workstation.
View 1 Replies View Relatedi would like to use the ACS 5.3 as TACACS Proxy. Basically it works. But when checking the logs on the destination TACACS Server (ACS 4.2) i see that all requests (Source-NAs) came from the IP of the TACACS-Proxy. Not from the original source IP.
This is useless for my scenario, because on the destination TACACS Server the policies are built on the NetworkDevices Groups and AAA Clients = source IPs.
I have a running L2TP/IPsec VPN setup with authentification against a radius server (freeradius2 witch mysql). I would like to have some of my VPN users get a fixed IP address instead of the dynamically assigned IP Pool.
The radius server is returning the correct parameters, I think.
It´s a Cisco 892 Integrated Service Router. Code...
using ACS 4.2 and I can't find a way to bind an incoming NAS port to a specifc IP Pool:
When a user connects the request to auth comes from 2 possible NAS ports randomly (this cannot change). Depending on which NAS makes the requests determines the IP range required, so I need 2 IP Pools. There is no way to say 'if request comes from NAS1 give IP from Pool1 and if request comes from NAS2 give IP from Pool2'
I have gone around and around with NAFs and NARs, but cannot do this.I can create 2 ACS groups with the specific NAS and specific IP pool within, but then I cannot have a single username bound to both groups.
I moved the auth to an AD group in the hope that I could bind that single AD group to the 2 ACS groups; and so have a single username, but no joy.