<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.1 &amp; Tons of Domain Controllers Behind Firewalls in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tons-of-domain-controllers-behind-firewalls/m-p/1648844#M249368</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had the same issue in our environment, where we have over 100 DC's located across the US and each behind series of firewalls. We ended up going to LDAP and eventually LDAP-S as we were able to point the ACS machines to a specific set of servers. With AD, we would constantly see our ACS boxes trying to contact every GC server and if it failed to reach a few it would time out and disconnect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 13 Mar 2011 18:56:52 GMT</pubDate>
    <dc:creator>dchamorro</dc:creator>
    <dc:date>2011-03-13T18:56:52Z</dc:date>
    <item>
      <title>ACS 5.1 &amp; Tons of Domain Controllers Behind Firewalls</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tons-of-domain-controllers-behind-firewalls/m-p/1648843#M249357</link>
      <description>&lt;P&gt;We have ACS 5.1 deployed in a large environment where we have two local domain controllers and boat loads of other domain controllers outside of our administrative domain behind multiple firewalls. When joining ACS to the domain we had troubles. Debugs were showing the system attempting connection to a bunch of DCs outside of us before eventually timing out. I decided to click the "Test Connectivity" button and let it sit. About 20 minutes later the page finally popped up the box that said the connection was successful. At that point I was able to save the config, the status showed connected, and I was even able to enumerate the directory groups.&lt;/P&gt;&lt;P&gt;However, when I go to do actual testing I keep getting EAP-TLS timeouts that I suspect are due to the million other DCs its trying to talk to. Additionally, now when I go back to the "directory groups" tab it no longer pulls groups even though the status still shows "connected."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to limit which domain controllers we talk to? Or should I just switch to a generic LDAP store? If I switch to LDAP, do I lose any functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tons-of-domain-controllers-behind-firewalls/m-p/1648843#M249357</guid>
      <dc:creator>AJ Cruz</dc:creator>
      <dc:date>2019-03-11T00:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 &amp; Tons of Domain Controllers Behind Firewalls</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tons-of-domain-controllers-behind-firewalls/m-p/1648844#M249368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had the same issue in our environment, where we have over 100 DC's located across the US and each behind series of firewalls. We ended up going to LDAP and eventually LDAP-S as we were able to point the ACS machines to a specific set of servers. With AD, we would constantly see our ACS boxes trying to contact every GC server and if it failed to reach a few it would time out and disconnect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Mar 2011 18:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tons-of-domain-controllers-behind-firewalls/m-p/1648844#M249368</guid>
      <dc:creator>dchamorro</dc:creator>
      <dc:date>2011-03-13T18:56:52Z</dc:date>
    </item>
  </channel>
</rss>

