<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.2 Edit Hosts File in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726961#M238841</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACS server is on our management vlan and for security reasons can't have a DC on it. The child domain I don't think would work because we have a primary server with multiple secondary ACS servers that will be going to different sites. So all the secondary servers at the different sites would try to point to our DC at the main site which we want them going to their sites DC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Apr 2011 17:20:06 GMT</pubDate>
    <dc:creator>dsmc</dc:creator>
    <dc:date>2011-04-14T17:20:06Z</dc:date>
    <item>
      <title>ACS 5.2 Edit Hosts File</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726959#M238839</link>
      <description>&lt;P&gt;Is it possible to edit the hosts file on an ACS 1121 server running ACS 5.2? Our problem is we have a single domain with multiple domain controllers at different sites. So when the ACS server tries connecting to the domain it randomly picks a domain controller which it can't connect to thus causing it to fail. I found an other thread &lt;A href="https://community.cisco.com/thread/2024431" target="_blank"&gt;https://supportforums.cisco.com/thread/2024431&lt;/A&gt; that has the same problem and was identified as an issue, but no more information on if it was resolved.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726959#M238839</guid>
      <dc:creator>dsmc</dc:creator>
      <dc:date>2019-03-11T00:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 Edit Hosts File</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726960#M238840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about setting up a small DNS server on a PC in the ACS subnet that would return only the right SRV records of DCs that are available ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about creating a child domain to your domain with only accessible DCs ? If ACS joins that child domain it can authenticate anyone in the domain since there are trust relationships.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those are workaround ideas.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 17:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726960#M238840</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-04-14T17:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 Edit Hosts File</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726961#M238841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACS server is on our management vlan and for security reasons can't have a DC on it. The child domain I don't think would work because we have a primary server with multiple secondary ACS servers that will be going to different sites. So all the secondary servers at the different sites would try to point to our DC at the main site which we want them going to their sites DC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 17:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726961#M238841</guid>
      <dc:creator>dsmc</dc:creator>
      <dc:date>2011-04-14T17:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 Edit Hosts File</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726962#M238842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't say you needed a DC on your management vlan.&lt;/P&gt;&lt;P&gt;Just turn on a PC with a DNS application on it. Configure the ACS to use that as DNS server. Voila !&lt;/P&gt;&lt;P&gt;The PC-DNS will give the ip addresses of the DCs you want in the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's be clear, I never tried this but it sounds feasible to me no ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 17:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726962#M238842</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-04-14T17:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 Edit Hosts File</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726963#M238845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think that would work, but I just checked and was told we can't have a PC on the management vlan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 17:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726963#M238845</guid>
      <dc:creator>dsmc</dc:creator>
      <dc:date>2011-04-14T17:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 Edit Hosts File</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726964#M238846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My suggestion would be to use the internal router as an dns forwarder.. One problem is it violates the regulations to enable that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 17:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-edit-hosts-file/m-p/1726964#M238846</guid>
      <dc:creator>cmarsteller</dc:creator>
      <dc:date>2011-04-14T17:32:04Z</dc:date>
    </item>
  </channel>
</rss>

