<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco 5.3 Cluster -  Domain Notation only Required when using Secondary ACS Server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-5-3-cluster-domain-notation-only-required-when-using/m-p/1924263#M192462</link>
    <description>&lt;P&gt;Overview:&amp;nbsp; Cisco 5.3 cluster, with primary server and secondary servers at separate datacenters.&amp;nbsp;&amp;nbsp; For remote vpn authentication through Cisco ASA, using radius authentication and Active Directory security groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The primary and secondary ACS servers are members (connected) to the root domain of our AD forest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue:&amp;nbsp; During testing, I am experiencing different results as it relates to the use of the requirement of domain notation during login.&amp;nbsp; When testing against the primary acs server, I am able to pass authentication for users in the root domain and child domains with or without domain notation.&amp;nbsp; When testing against the secondary ACS server, domain notation is required for child domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Since each server is running the same version, 5.3.0.40, and are connected to the same domain, which happens to the be the root domain of the forest, I would expect the same results from testing.&amp;nbsp; I did confirm that they are synchronized properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&amp;nbsp; &lt;/P&gt;&lt;P&gt; - The forest name and root domain is&amp;nbsp; X and the acs servers are members of x.&lt;/P&gt;&lt;P&gt; - Child domains are y and z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I test authentication against the primary, I can login with a user from x,y, or z using domain notation (domain\username)&amp;nbsp; or without domain notation (username)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I test against the secondary ACS server, I can login using domain notation for x,y,z.&amp;nbsp; But when I test with domain notation, it only works when the user is from the root domain X.&amp;nbsp; So users from y and z must use domain notation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs show the error as:&lt;/P&gt;&lt;P&gt;&lt;A href="https://10.12.2.34/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=22056+Subject+not+found+in+the+applicable+identity+store%28s%29.&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: #ff0000; margin-top: 0pt;" target="_self" title="Click for failure reason details"&gt;22056 Subject not found in the applicable identity store(s)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:59:11 GMT</pubDate>
    <dc:creator>tcroziercisco</dc:creator>
    <dc:date>2019-03-11T01:59:11Z</dc:date>
    <item>
      <title>Cisco 5.3 Cluster -  Domain Notation only Required when using Secondary ACS Server</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-5-3-cluster-domain-notation-only-required-when-using/m-p/1924263#M192462</link>
      <description>&lt;P&gt;Overview:&amp;nbsp; Cisco 5.3 cluster, with primary server and secondary servers at separate datacenters.&amp;nbsp;&amp;nbsp; For remote vpn authentication through Cisco ASA, using radius authentication and Active Directory security groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The primary and secondary ACS servers are members (connected) to the root domain of our AD forest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue:&amp;nbsp; During testing, I am experiencing different results as it relates to the use of the requirement of domain notation during login.&amp;nbsp; When testing against the primary acs server, I am able to pass authentication for users in the root domain and child domains with or without domain notation.&amp;nbsp; When testing against the secondary ACS server, domain notation is required for child domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Since each server is running the same version, 5.3.0.40, and are connected to the same domain, which happens to the be the root domain of the forest, I would expect the same results from testing.&amp;nbsp; I did confirm that they are synchronized properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&amp;nbsp; &lt;/P&gt;&lt;P&gt; - The forest name and root domain is&amp;nbsp; X and the acs servers are members of x.&lt;/P&gt;&lt;P&gt; - Child domains are y and z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I test authentication against the primary, I can login with a user from x,y, or z using domain notation (domain\username)&amp;nbsp; or without domain notation (username)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I test against the secondary ACS server, I can login using domain notation for x,y,z.&amp;nbsp; But when I test with domain notation, it only works when the user is from the root domain X.&amp;nbsp; So users from y and z must use domain notation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs show the error as:&lt;/P&gt;&lt;P&gt;&lt;A href="https://10.12.2.34/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=22056+Subject+not+found+in+the+applicable+identity+store%28s%29.&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: #ff0000; margin-top: 0pt;" target="_self" title="Click for failure reason details"&gt;22056 Subject not found in the applicable identity store(s)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-5-3-cluster-domain-notation-only-required-when-using/m-p/1924263#M192462</guid>
      <dc:creator>tcroziercisco</dc:creator>
      <dc:date>2019-03-11T01:59:11Z</dc:date>
    </item>
    <item>
      <title>Cisco 5.3 Cluster -  Domain Notation only Required when using Se</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-5-3-cluster-domain-notation-only-required-when-using/m-p/1924264#M192477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More info:&amp;nbsp; during the installation of the secondary unit, it was renamed and then reconnected to the root domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2012 19:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-5-3-cluster-domain-notation-only-required-when-using/m-p/1924264#M192477</guid>
      <dc:creator>tcroziercisco</dc:creator>
      <dc:date>2012-04-09T19:57:44Z</dc:date>
    </item>
  </channel>
</rss>

