<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.1 - Dynamic User automatic purging? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257859#M149880</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's good to know that NAR settings doesn't affect the user type. As far as I know the above could be a possible causes of deletion of dynamic user. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's see if someone else has some more inputs on this thread/discussion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 May 2013 23:42:47 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-05-08T23:42:47Z</dc:date>
    <item>
      <title>ACS 4.1 - Dynamic User automatic purging?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257853#M149874</link>
      <description>&lt;P&gt;How often does ACS 4.1 purge dynamic users from it's user group after inactivity?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're trying to disable access to certain resources via a NAR, and finding that some users are not in the ACS dynamic user database, despite that, at one point in the past, they have used it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I correct in assuming that a user that has never authenticated via an ACS-controlled resource would not be in the database?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257853#M149874</guid>
      <dc:creator>brian.emil.harris</dc:creator>
      <dc:date>2019-03-11T03:24:33Z</dc:date>
    </item>
    <item>
      <title>ACS 4.1 - Dynamic User automatic purging?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257854#M149875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS doesn't purge dynamic users automatically. Most of the times when you make changes in the "external database" section, below the &lt;STRONG&gt;submit &lt;/STRONG&gt;tab, it says&lt;STRONG&gt; Submitting the configuration changes removes the dynamic users linked to the&amp;nbsp; database.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can go to user setup and manualy delete the dynamic users using "&lt;STRONG&gt;Remove Dynamic Users&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 16:46:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257854#M149875</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T16:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 - Dynamic User automatic purging?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257855#M149876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the user does not exist in the CS ACS local database, CSACS marks that user as unknown and checks for an unknown user policy.&amp;nbsp; If the unknown user policy is to fail the user, CS ACS fails the user. Otherwise, if external database is configured, CS ACS forwards that information to the configured external user database. CS ACS tries each external user database until the user succeeds or fails. If the authentication is successful, the user information goes into the cache of CSACS, which has a pointer for using the external user database. This user is known as a&lt;STRONG&gt; dynamic user.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The next time the dynamic user tries to authenticate, Cisco Secure ACS authenticates the user against the database that was successful the first time. These cached user entries are used to speed up the authentication process. Dynamic users are treated in the same way as known users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the unknown user fails authentication with all configured external databases, the user is not added to the Cisco Secure user database and the authentication fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: In ACS 4.2 we have a controlled on this feature &lt;/P&gt;&lt;P&gt;Under External user database &amp;gt; unknown user policy.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Use this option to disable the creation of dynamic users while using an external&amp;nbsp; database for authentication &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; Disable dynamic user&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 17:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257855#M149876</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T17:02:36Z</dc:date>
    </item>
    <item>
      <title>ACS 4.1 - Dynamic User automatic purging?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257856#M149877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, then, how would a user be automatically removed from the Dynamic Users group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can pretty much ensure that nobody has manually removed this particular dynamic user, and based on the "Passed Authentications" logs, I know that the user has authenticated at some point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, this user is no longer part of any group of users, no account on ACS, so I'm not able to utilize the NAR to block auth attempts from a particular source for this user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 17:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257856#M149877</guid>
      <dc:creator>brian.emil.harris</dc:creator>
      <dc:date>2013-05-08T17:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 - Dynamic User automatic purging?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257857#M149878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so if you go to user setup and type the name of the user, do you even see user exist on ACS?&lt;/P&gt;&lt;P&gt;In few cases if you make changes to a dynamic user parameters /settings, it start appearing as a static users.&lt;/P&gt;&lt;P&gt;It is recommended to configure everything on a group to which they belong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 17:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257857#M149878</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T17:48:30Z</dc:date>
    </item>
    <item>
      <title>ACS 4.1 - Dynamic User automatic purging?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257858#M149879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, as an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to enable and configure a "Per User Defined Network Access Restriction" for a "Denied Calling/Point of Access Locations" to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA Client - server1&lt;/P&gt;&lt;P&gt;Port - *&lt;/P&gt;&lt;P&gt;Address - *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for username1, I have configured this, and it has not changed the user from dynamic to static:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group:&amp;nbsp; Dynamic mapping [Currently: Default Group (5201 users)].&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for username2, I want to configure this, but when I try to find this user, I get "No users matching:&amp;nbsp; username2"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username2 has successfully authenticated via this ACS system several months ago.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't wish to create any groups at this time, as my method of disabling their authentication access to this single AAA client is working how I wish it to, and it's not making these users static, so I think we're clear there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 18:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257858#M149879</guid>
      <dc:creator>brian.emil.harris</dc:creator>
      <dc:date>2013-05-08T18:52:28Z</dc:date>
    </item>
    <item>
      <title>ACS 4.1 - Dynamic User automatic purging?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257859#M149880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's good to know that NAR settings doesn't affect the user type. As far as I know the above could be a possible causes of deletion of dynamic user. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's see if someone else has some more inputs on this thread/discussion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 23:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-dynamic-user-automatic-purging/m-p/2257859#M149880</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T23:42:47Z</dc:date>
    </item>
  </channel>
</rss>

