Cisco AAA/Identity/Nac :: ACS 5.2 Joined AD / Authorizing User Through Internal OK?

Apr 23, 2011

My ACS5.2 joined Windows 2003 Active Directory successfully. I created Support group with user1 in the internal store, also created Support-AD group with userad1 in the AD store. Identity Store Sequency is set Internal first, then AD. I can map Support-AD group to the local Support group without any problem.
 
Internal user gets authenticated and authorized OK. However, if the user is an AD user, the rule for AD users is not picked. So it goes to default.

View 4 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: ACS 5.2 Expiration Date Per Internal User?

May 2, 2011

Migrating from 4.2 to 5.2 acs and have noticed there is no expiration date per internal user added. We expire users at different times due to their time on site. Is there something that has to be added to get back this basic feature we had before?

View 6 Replies View Related

Cisco AAA/Identity/Nac :: Creating Internal User Account In ACS 5.2

Dec 12, 2011

I have an ACS 5.2 server integrated with Active directory . Now i need to create an internal user account to login to some radisu devices using internal user database  .I have near about 600 users all are authenticating through AD .

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Updating Internal User Database?

Jul 4, 2011

Using  a CSV file, I can not add user in the internal database of the ACS I have a permanent "error File Format Validation Failed" However the file I want to import is a really CSV file.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Password Rules Settings Per Internal User

Sep 27, 2010

I am looking for a way how to set the password-rules for individually for for some users or identity-groups.I just can find the global settings,Background of the requirement: We want to use password-aging for most admin-users, for some we dont want that pw expires.

View 10 Replies View Related

AAA/Identity/Nac :: Cisco ACS Can't Find / Authenticate Internal User On 3550 Switch

Apr 29, 2012

I'm doing some testing with ACS server on my windows box and I can't seem to get a barebone radius authentication to work with ACS internal users. I tested the same configuration with TACACS and it works fine, so there's something missing or misconfigured in my setup.
 
I have a cisco 3550 switch that I want users to login using their ACS username/password.
 
SW1
username cisco password 0 cisco
username admin password 0 admin

[Code].....

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 User Roles And Restricting User Access To Add Items?

Sep 22, 2011

We are running ACS 5.2 patch 6 and want to restrict access for users to be able to add devices to the system.For example, admin person in site A can only add devices into the site A group and cannot see/access other sites groups.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Host Internal Identity Store / Per Group Modification

Jan 24, 2012

I'm currently looking for a solution in order to restrict the modification of the host internal identity store (add or delete MAC host) per group. The default administrator roles does not include "per group restriction". Under the ACS I defined one group per department? My objective it to allow each department to access their ACS MAC database to add or delete MAC addresses as required.

How to restrict internal identity store per group?Do I need to create new roles? and how?I was not able to get an answer from the ACS ADMIN manual.

View 1 Replies View Related

Cisco Firewall :: ASA 5505 8.4(2) Allow User To Access Internal Www Server?

Aug 2, 2011

I tried the solution posted at [URL] however it did not work on my ASA5505 8.4(2). I thought that it may be because I only have a single public address so the web server is responding to port forwarding through the one public IP already. looking in ASDM it appears to indicate that a configured access list is blocking the server from responding to the internal hosts.
 
object network Private_IP
host 192.168.1.15
object network Public_IP
host 1.1.1.1
object-group network internal_net

[code]....
 
Can I fix an access list (or something) to make this work or am I wishing for too much with only one public IP? This worked by default on my Netgear firewall.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Gives Internal Error

Oct 8, 2012

On ACS 4.2.0.124 version installed on Appliance 1113.We are getting error code as "Internal error" and also "Enabling Tacacs+ is not allowed for this Access Server" while client authentication.

View 5 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Not Accessing Internal DB

Jul 2, 2012

i have configured my ACS 5.3 server to access AD for user authentication but i would as well like to use the internal store for some users.The problem is that when i test with an internal user account, i can see in the logs that it still tries to access the AD for this user and i receive a message in the logs. " 22056 subject not found in the applicable data store".i have already defined the identity sequence to first use the AD, then if user not found, use the internal database.

View 2 Replies View Related

AAA/Identity/Nac :: ACS 5.2 Import Internal Hosts?

May 17, 2011

Trying to use the "File Operations" option to import hosts into ACS.  I go through the wizard and click "Finish", the pop up goes blank and just hangs there.  No errors are generated. 

View 2 Replies View Related

Cisco AAA/Identity/Nac :: How Many Local Accounts Can Be Created On ACS 4.2 Internal

Jan 29, 2013

I intend to create ACS local account from file. What is maximum of accounts can be in ACS 4.2?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Maximum Internal Hosts Accounts On ACS 5.2?

Aug 27, 2011

Is there a maximum number of "Internal Hosts account" IDs that the local database in a ACS 5.2 can handle?

View 5 Replies View Related

Cisco Wireless :: AP 1524 Not Getting Joined With 2504 WLC

Jul 3, 2012

I've got a 1524 ap and it wont join my 2540 WLC. The messages I see in the WLC is RADIUS authorization is pending for the AP. I've added the MAC address of the ap under AP Policies using MIC. I dont have a radius server either so not sure how to tackle this one.When I run debug capwap events enale under the wlc I see the following messages:Discarding discovery request in LWAPP from AP supporting CAPWAP.

View 35 Replies View Related

Cisco :: Newly Joined Computer To Request IP Address From MAC?

Mar 13, 2012

RARP (Reverse Address Resolution Protocol) is a protocol by which a physical machine in a local area network can request to learn its IP address from a gateway server's Address Resolution Protocol (ARP) table or cache. A network administrator creates a table in a local area network's gateway router that maps the physical machine (or Media Access Control - MAC address) addresses to corresponding Internet Protocol addresses.When a new machine is set up, its RARP client program requests from the RARP server on the router to be sent its IP address. Assuming that an entry has been set up in the router table, the RARP server will return the IP address to the machine which can store it for future use.Among the passage of words i read, there was this sentence i were not sure, "A network administrator creates a table in a local area network's gateway router that maps the physical machine (or Media Access Control - MAC address) addresses to corresponding Internet Protocol addresses." Does it means each time a host computer joins in the ethernet LAN, the network administrator would manually add in it's MAC address in the router table, so it would allow the newly joined computer to request IP address from it's MAC address?

View 1 Replies View Related

Cisco Wireless :: 1230AG Not Able To Stay Joined To Controller

Feb 21, 2012

I have multiple 1230AG wireless access point in autonomous mode that I am migrating to lightweight mode so that a 4402 controller can manage them. I already migrated 4 of those APs with no problems using the Upgrade Tool version 3.4 and now I have one that just refused to upgrade version.
 
I ran the upgrade tool for this AP alone with the same parameters as others. It is now on lightweight version 12.3.7-JX9 The upgrade procedure went smoothly, the SSC was created on the AP and added to the authorised list on the controller. The AP boots up, gets an IP by DHCP, tries the controller via DNS, gets to it. It joins it then disconnects. Its FastEthernet interface keeps doing down/up every 90 seconds or so.
 
In my controller logs I see:
*SNMPTask: Feb 22 19:39:17.135: %LWAPP-3-INVALID_SLOT: spam_api.c:711 Invalid slot identifier (0) - ; AP 00:13:.........
*spamReceiveTask: Feb 22 19:39:13.150: %LWAPP-3-PAYLOAD_MISSING:

[Code].....

View 5 Replies View Related

Windows Xp Internet Lost When Domain Joined?

Feb 10, 2012

I have a domain network , when i log on domain the internet is lost , and still did work until i to return this pc to workgroup without change any ip configuration , i try to resolve this and i found that when I rejoined to domain , it's work but not for long time only work until the pc rebooting ?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Add A User Into Several Groups?

Apr 5, 2011

We are running two ACS appliances but we cannot figure out how we can add a user into 2 differents groups.Here's the context :We have a company A which is having devices, this company uses Group A.then we have a company B which is having devices, this company uses Group B.But the admin has to manage the devices for both companies A & B.We don't want to mix devices from company A with company B.Is there a way to add the user into both groups A & B.

View 5 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Maximum User ID

Jan 5, 2013

what is the maximum user IDs that I can create to the ACS server? The client have an ACS appliance with version 5.2.

View 2 Replies View Related

Cisco Wireless :: Bridge Joined By WAP 4410n For Access Point

Oct 21, 2012

I wonder if I can join via the WAP 4410n Bridge and also work as Access-point at a time. The idea is that you can connect to a router that provides Internet service that makes access-point bridge and connect to another WAP 4410n which would be another single access point for wireless bridge.

View 1 Replies View Related

Servers :: Your Computer Could Not Be Joined To The Domain - Access Denied

Apr 2, 2012

your computer could not be joined to the domain because the following error has occured,access denied,this error is happening when i create users for active directory users and computers in windows server 2003,i have 11 computers ,,1 server and 10 clients,,i created 10 users in active directory users and computers ,,until here i have no problem,,but when i want join client computers with server it is happening this error(your computer could not be joined to the domain because the following error has occurred,access denied)i can join 3 client computer with the server in fourth computer it happening that error,what can i do?

View 9 Replies View Related

Cisco AAA/Identity/Nac :: Restricting User Sessions In ACS 5.1?

Jul 26, 2011

We are using ACS 5.1 in our network. We have created users and grouped them as per the requirements. We want to restrict the user sessions in the network. A user should authenticate and able to access a network resource. But when he is active with that session, we need to block him from another successful authentication. We want to avoid multiple users using same user credentials for logging into the devices. whether this can be achieved by making configuration changes in ACS.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 How To Deny Access To User

Jun 12, 2011

I have ACS 5.1.I have created the Identity Group 'Admin' and added 2 users in that, say User1 and User2.How do I permit only User1 to get authenticated when he logins in to the device?There is option to select 'UserName' while creating Service Access Policy , but I have observed that though I have mentioned only User1 in the rule, User2 is also getting permitted

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Limited User Account?

Mar 29, 2013

i have cisco ACS 5.2 and want to create user account for technician, with only certain commands.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: User Change Password On ACS 5.3

Mar 7, 2012

On the ACS ver5, there is a "User Change Password" feature. When i click the UCP WSDL, it gives me a page with WSDL language. how is it supposed to be installed? does it copy or install to any web server

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Can Add / Modify ACS 5.2 CLI User Roles

Apr 28, 2011

My company's security group uses Tripwire to monitor for changes in start-config and running-config on network devices in PCI scope.  We are migrating from ACS v4.2 to v5.2.  I need to create the account for Tripwire on the ACS Appliance but did not want to assign the admin role which would give access to configure terminal.  The user role does not have privileges for show start-config or show running-config.  Am I missing something or are these the only 2 roles available at the CLI?  Can another rolle be added?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Local User Authentication

Nov 12, 2012

I want to have a local user in ACS that is permitted to login to routers. I have TACACS with AD already working but cannot get a local user to work. I used to do this in ACS 4.x.I created a user in the internal identity store.I tried configuring a policy to allow this users TACACS authentication multiple ways to no avail. I cannot find a config example doc and cannot figure it out from the user guide as the documention is sorely lacking.

View 5 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Delete Specific Log For User X

Jun 25, 2012

on the acs 5.2 , how to delete specific log for user X, ?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Connected To AD Locking Out User?

Feb 18, 2013

  So we have this problem that just started, I can replicate the issue as well, if a user makes a mistake on typing there password after 1 attempt ACS sends 3 to AD locking out the user.
 
  In a putty or secureCRT session after 1 password failed attempt, I am unable to retry with that same session.

  The issue seems to be that after 1 bad password attempt, from the client side I am unable to get another try.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 User Group Mapping?

Sep 12, 2012

We are using ACS 4.2.1.15 with patch 8 on ACS 1113 SE box.
 
Our requirement is to assign ACS loal group to user on basis of windows Nt group. Which means I dont wants to create individual users in ACS rather when user will login, the auth request will be forwarded to AD(remote database). Depeneding on the remote database group the user should be mapped to local database.
 
For this I have configured "database group mapping" according to following cisco guide. [URL] 
 
However when ever my AD users are authenticating they are getting the membership of default group as configured in "Default" profile. I am using TACACS+ protocol in my routers and switches for authentication.
 
whether "Group mapping by External user database"  works with TACACS+ or only with RADIUS protocol. If it works with TACACS+ what else configuration need to be done so that my ACS can map users to proper groups instead of default group.

View 4 Replies View Related

AAA/Identity/Nac :: ACS 5.2 Machine Authentication And AD User?

Sep 1, 2011

I am trying to setup up a rule to allow wireless access only to users in my AD when they use computers from my AD.I have Machine authentication working on it's own (computer boots up and connects to wireless - confrimed by ACS logs) I have User authentication working But when I try to creat the floowing rule:it does not work.
 
Access Policy
Access Service:
Default Network Access Identity Store:
AD1
Authorization Profiles:
DenyAccess
Exception Authorization Profiles:
Active Directory Domain:

[code]....
 
Everything seem to fine until it gets to the last rule.

View 1 Replies View Related

AAA/Identity/Nac :: AD User Password Changing With ACS 5.0?

Oct 11, 2011

I use ACS appliance 1120 for cisco devices administration. The identity store is  external. I use Active directory. Actually, Authentication, authorization and accounting work well but users can not change theirs Active directory password when they have expired. Do you now how to configure ACS to permit password changing?

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved