<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.3 join to domain issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206742#M116362</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the AD setup? Can you please describe how is the AD setup? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is your domain name? Are you able to execute nslookup for the same from ACS CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see all services running : show application status acs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Please provide me the following debugs from acs-config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(a)acsadmin(config-acs)# debug-adclient enable&lt;/P&gt;&lt;P&gt;(b) acsadmin(config-acs)# debug-log runtime-idstores level debug&lt;/P&gt;&lt;P&gt;(c) acsadmin(config-acs)# debug-log mgmt-bl level debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 May 2013 00:03:15 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-05-22T00:03:15Z</dc:date>
    <item>
      <title>ACS 5.3 join to domain issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206741#M116361</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I facing a strange problem with ACS 5.3.0.40.9.&lt;/P&gt;&lt;P&gt;I'm trying to join the ACS to domain without success.The test connection works properly "Connection test to &amp;lt;domain&amp;gt; succeeded" but when i'm trying to save the config i get the error "wrong domain".&lt;/P&gt;&lt;P&gt;These machine was previous in a lab environment and the connection to AD was working fine.Now i'm trying to install it in production environment.&lt;/P&gt;&lt;P&gt;Maybe ACS has cashed information about AD,i cleared "ad-agent-clear-cache" but I'm not able to clear the AD config through CLI,&lt;/P&gt;&lt;P&gt;ACS5(config-acs)# ad-agent-reset-configuration&lt;/P&gt;&lt;P&gt;Performing reset of AD agent configuration , AD agent will be restarted. continue (y/n)?&amp;nbsp; &lt;/P&gt;&lt;P&gt;Unable to restart AD agent. Define AD configuration or check current AD configuration settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206741#M116361</guid>
      <dc:creator>Christos Stefaneskou</dc:creator>
      <dc:date>2019-03-11T03:27:06Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 join to domain issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206742#M116362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the AD setup? Can you please describe how is the AD setup? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is your domain name? Are you able to execute nslookup for the same from ACS CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see all services running : show application status acs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Please provide me the following debugs from acs-config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(a)acsadmin(config-acs)# debug-adclient enable&lt;/P&gt;&lt;P&gt;(b) acsadmin(config-acs)# debug-log runtime-idstores level debug&lt;/P&gt;&lt;P&gt;(c) acsadmin(config-acs)# debug-log mgmt-bl level debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 00:03:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206742#M116362</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T00:03:15Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 join to domain issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206743#M116363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem solved,i created a new AD user for ACS with administrator rights.&lt;/P&gt;&lt;P&gt;This is strange because it isn't necessary to be administrator.&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 07:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206743#M116363</guid>
      <dc:creator>Christos Stefaneskou</dc:creator>
      <dc:date>2013-05-22T07:34:07Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 join to domain issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206744#M116364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to know. However we don't need admin rights.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the user guide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/users_id_stores.html#wp1171071"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/users_id_stores.html#wp1171071&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Predefined user in AD. AD account required for domain access in ACS should have either of the following:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;•Add workstations to domain user right in corresponding domain.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;•Create Computer Objects or Delete Computer Objects permission on corresponding computers container where ACS machine's account is precreated (created before joining ACS machine to the domain).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recommend that you disable the lockout policy for the ACS account and configure the AD infrastructure to send alerts to the admin if a wrong password is used for that account. This is because if you enter a wrong password, ACS will not create or modify its machine account when it is necessary and therefore possibly deny all authentications. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 08:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-join-to-domain-issue/m-p/2206744#M116364</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T08:33:01Z</dc:date>
    </item>
  </channel>
</rss>

