<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS5: rules - continue on FAIL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862619#M212886</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately the Treat Rejects as 'authentication failed' and Treat Rejects as 'user not found' options only apply when configuring RSA (Native SDI). Those would not apply for any other External Database like AD or LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clarifies it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jan 2012 15:11:23 GMT</pubDate>
    <dc:creator>camejia</dc:creator>
    <dc:date>2012-01-17T15:11:23Z</dc:date>
    <item>
      <title>ACS5: rules - continue on FAIL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862616#M212883</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to create on ACS5 rule which will:&lt;/P&gt;&lt;P&gt;1. Try to authenticate user in external database1 (radius) &lt;/P&gt;&lt;P&gt;2. When external database1 returns FAIL (because of bad password) ACS5 should try to authenticate user in another external database2 (radius)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to have such scenario ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862616#M212883</guid>
      <dc:creator>mlopacinski</dc:creator>
      <dc:date>2019-03-11T01:43:29Z</dc:date>
    </item>
    <item>
      <title>ACS5: rules - continue on FAIL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862617#M212884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only database that will allow that behavior when configured first on an Identity Store Sequence would be RSA when configured to use Native SDI. It has a setting that reads as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"This Identity Store does not differentiate between&amp;nbsp; 'authentication failed' and 'user not found' when an authentication&amp;nbsp; attempt is rejected. From the options below, select how such an&amp;nbsp; authentication reject from the Identity Store should be interpreted by&amp;nbsp; ACS for Identity Policy processing and reporting . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Treat Rejects as 'authentication failed' &lt;/P&gt;&lt;P&gt; Treat Rejects as 'user not found'"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can select either of the above two options in order to determine how will the ACS interpret the failure returned from the RSA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For LDAP, AD or any other external database, if the ACS does the query to the external database, finds the username but the failure is caused due to a "Bad Password" the ACS will exit the Identity Store Sequence and will deny access to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way for the ACS to keep querying databases in an ID Store Sequence is that the user account is not found on the current database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 22:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862617#M212884</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-16T22:40:52Z</dc:date>
    </item>
    <item>
      <title>ACS5: rules - continue on FAIL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862618#M212885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanx for detailed description for Treat Rejects as 'authentication failed'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one more question for Treat Rejects as 'user not found'"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So - if my first external database: LDAP or AD return Treat Rejects as 'user not found'"&lt;/P&gt;&lt;P&gt;next external database can be queried ? (or this functionality is also only for RSA SDI) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2012 08:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862618#M212885</guid>
      <dc:creator>mlopacinski</dc:creator>
      <dc:date>2012-01-17T08:02:18Z</dc:date>
    </item>
    <item>
      <title>ACS5: rules - continue on FAIL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862619#M212886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately the Treat Rejects as 'authentication failed' and Treat Rejects as 'user not found' options only apply when configuring RSA (Native SDI). Those would not apply for any other External Database like AD or LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clarifies it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2012 15:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862619#M212886</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-17T15:11:23Z</dc:date>
    </item>
    <item>
      <title>ACS5: rules - continue on FAIL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862620#M212888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so - there is no way i could do a migration from one external database to another external database ?&lt;/P&gt;&lt;P&gt;(creating gradually new users in new database and deleting them from old database) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jan 2012 07:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862620#M212888</guid>
      <dc:creator>mlopacinski</dc:creator>
      <dc:date>2012-01-18T07:08:17Z</dc:date>
    </item>
    <item>
      <title>ACS5: rules - continue on FAIL</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862621#M212890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to delete the user from the Old Database as soon as you create it on the New Database for the ACS to receive an "Unknown User" error and move to the next available database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that if the ACS finds the user on the Old Database it will not move to the New Database and the failure would be reported as "Bad Password" as you stated on the beginning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jan 2012 17:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-rules-continue-on-fail/m-p/1862621#M212890</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-18T17:37:02Z</dc:date>
    </item>
  </channel>
</rss>

