<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting up ACS 5.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/setting-up-acs-5-3/m-p/1945040#M245840</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just been tasked with setting up the ACS 5.3&amp;nbsp; and am having&lt;/P&gt;&lt;P&gt;a few problems getting things started.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is&amp;nbsp; a question from my server team -&lt;/P&gt;&lt;P&gt;ACS specifies an account to join the machine to the domain. Will this account then be the account that it communicates to AD on once it has joined the domain or is there somewhere we need to put AD credentials for LDAP lookup? Our AD administrator is happy to join it the domain but does not want ACS then running under his account” &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words we dont want to use an admin account but surely&lt;/P&gt;&lt;P&gt;we only need an ordinary account that reads ad for authentication ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone clear this one up ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2019 00:40:40 GMT</pubDate>
    <dc:creator>steve switzer</dc:creator>
    <dc:date>2019-03-13T00:40:40Z</dc:date>
    <item>
      <title>Setting up ACS 5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-acs-5-3/m-p/1945040#M245840</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just been tasked with setting up the ACS 5.3&amp;nbsp; and am having&lt;/P&gt;&lt;P&gt;a few problems getting things started.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is&amp;nbsp; a question from my server team -&lt;/P&gt;&lt;P&gt;ACS specifies an account to join the machine to the domain. Will this account then be the account that it communicates to AD on once it has joined the domain or is there somewhere we need to put AD credentials for LDAP lookup? Our AD administrator is happy to join it the domain but does not want ACS then running under his account” &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words we dont want to use an admin account but surely&lt;/P&gt;&lt;P&gt;we only need an ordinary account that reads ad for authentication ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone clear this one up ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-acs-5-3/m-p/1945040#M245840</guid>
      <dc:creator>steve switzer</dc:creator>
      <dc:date>2019-03-13T00:40:40Z</dc:date>
    </item>
    <item>
      <title>Setting up ACS 5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-acs-5-3/m-p/1945041#M245874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the account guidelines for joining ACS to AD, Once ACS joins to AD it will authenticate users through the workstation account that is created when its joined. The only time the ACS needs the credentials of the account is when the box joins to AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1140928table1140922" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P&gt; Username &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1254730"&gt;&lt;/A&gt;&lt;P&gt; Predefined user in AD. AD account required for domain access in ACS should have either of the following: &lt;/P&gt;&lt;A name="wp1254731"&gt;&lt;/A&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Add workstations to domain user right in corresponding domain. &lt;/P&gt;&lt;A name="wp1291226"&gt;&lt;/A&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Create&amp;nbsp; Computer Objects or Delete Computer Objects permission on corresponding&amp;nbsp; computers container where ACS machine's account is precreated (created&amp;nbsp; before joining ACS machine to the domain). &lt;/P&gt;&lt;A name="wp1291062"&gt;&lt;/A&gt;&lt;P&gt; We&amp;nbsp; recommend that you disable the lockout policy for the ACS account and&amp;nbsp; configure the AD infrastructure to send alerts to the admin if a wrong&amp;nbsp; password is used for that account. This is because if you enter a wrong&amp;nbsp; password, ACS will not create or modify its machine account when it is&amp;nbsp; necessary and therefore possibly deny all authentications. &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/users_id_stores.html#wp1140906&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 07:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-acs-5-3/m-p/1945041#M245874</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-05-02T07:50:10Z</dc:date>
    </item>
    <item>
      <title>Setting up ACS 5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-acs-5-3/m-p/1945042#M245905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 15:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-acs-5-3/m-p/1945042#M245905</guid>
      <dc:creator>steve switzer</dc:creator>
      <dc:date>2012-05-02T15:13:57Z</dc:date>
    </item>
  </channel>
</rss>

