<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: authenticate ACS 5.0 with controller 4400 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580166#M258298</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ibrahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to perform only user authentication through user accounts that are in AD, this should definitely be possible without having the PC joined to the AD domain (this would be used for machine authentication, so not your case).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Jan 2011 09:46:11 GMT</pubDate>
    <dc:creator>Federico Ziliotto</dc:creator>
    <dc:date>2011-01-10T09:46:11Z</dc:date>
    <item>
      <title>authenticate ACS 5.0 with controller 4400</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580165#M258296</link>
      <description>&lt;P&gt;i want to authenticate WALN user from the acs 5.0 , and the acs integrated with AD but these users&amp;nbsp; have account on the AD but there some PC.labtop not joined on the domian so can they authenticate without joine the PC or labtop to the domain using the user account that configured on AD which is integtated with ACS .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i have tow AD one master the othere is backup , can i configure backup AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pleas advise ASAP&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580165#M258296</guid>
      <dc:creator>khdouradtech</dc:creator>
      <dc:date>2019-03-11T00:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate ACS 5.0 with controller 4400</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580166#M258298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ibrahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to perform only user authentication through user accounts that are in AD, this should definitely be possible without having the PC joined to the AD domain (this would be used for machine authentication, so not your case).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 09:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580166#M258298</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-10T09:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate ACS 5.0 with controller 4400</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580167#M258300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, They can autheticate unless you don't have MAR enabled on the ACS 5.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may check this under Managing user and indentity store &amp;gt;&amp;gt;&amp;nbsp; Microosft active directory &amp;gt;&amp;gt; MAR (This option shouldn't be checked).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1&gt;&lt;/H1&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;Machine access restriction (MAR&lt;/STRONG&gt;)&lt;/SPAN&gt; &amp;gt;&amp;gt; ACS machine access restriction (MAR) features use AD to map machine authentication to user authentication and authorization, and sets a the maximal time allowed between machine authentication and an authentication of a user from the same machine. Most commonly, MAR fails authentication of users whose host machine does not successfully authenticate or if the time between machine and user authentication is greater than the specified aging time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest you to upgrade ACS to atleast 5.1 because......&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3 class="p_H_Head2"&gt;The below listed Features are Not Supported IN ACS 5.0&lt;BR /&gt;&lt;/H3&gt;&lt;A name="wp74958"&gt;&lt;/A&gt;&lt;P class="pB1_Body1"&gt;The following features are not supported in ACS 5.0:&lt;/P&gt;&lt;A name="wp74915"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Integration with RSA server or RADIUS Token One Time Password (OTP) servers.&lt;/P&gt;&lt;A name="wp74975"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Integration with SQL DB via ODBC, for external authentication and identity information.&lt;/P&gt;&lt;A name="wp74919"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;The following Extensible Authentication Protocol (EAP) methods are not supported: &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;&lt;A name="wp81051"&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;P class="pBu2_Bullet2"&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;LEAP &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;&lt;A name="wp81055"&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;P class="pBu2_Bullet2"&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;EAP-FAST/GTC &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;&lt;A name="wp81061"&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;P class="pBu2_Bullet2"&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;EAP-FAST/TLS &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;&lt;A name="wp81063"&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;P class="pBu2_Bullet2"&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;PEAP/GTC &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;&lt;A name="wp81065"&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;P class="pBu2_Bullet2"&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;PEAP/TLS &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;A name="wp74985"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Support for locally significant external resources (ID stores, and so on) in a distributed deployment.&lt;/P&gt;&lt;A name="wp74990"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;RADIUS and TACACS+ Proxy.&lt;/P&gt;&lt;A name="wp74995"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Terminal server access control (port-based TACACS+ access control).&lt;/P&gt;&lt;A name="wp75000"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Complete TACACS+ support for device administration (password change, and so on).&lt;/P&gt;&lt;A name="wp75005"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;RADIUS Virtual Private Network (VPN) and RADIUS-based device administration (for shell access to CLI for third-party network devices).&lt;/P&gt;&lt;A name="wp75010"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;ACS administrator and internal user password policies.&lt;/P&gt;&lt;A name="wp75021"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Application access control for CiscoWorks applications.&lt;/P&gt;&lt;A name="wp75022"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;CSUtil features.&lt;/P&gt;&lt;A name="wp113324"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Network access restriction to users whose Windows accounts have Windows dial-in permission.&lt;/P&gt;&lt;A name="wp113325"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;IP Pools Server feature.&lt;/P&gt;&lt;A name="wp113321"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Support for defining the maximum number of simultaneous sessions for a user or user group.&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;Regards&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;Jatin&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;~Do rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 10:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580167#M258300</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-10T10:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate ACS 5.0 with controller 4400</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580168#M258301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for support.&lt;/P&gt;&lt;P&gt;how we can upgrade to 5.1 and how we can install the OS .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and for the Wlan soulation anyone provide us document explain how we can configure with acs 5.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 13:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580168#M258301</guid>
      <dc:creator>khdouradtech</dc:creator>
      <dc:date>2011-01-10T13:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate ACS 5.0 with controller 4400</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580169#M258302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ibrahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the procedure to upgrade from ACS 5.0 to 5.1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/installation/guide/csacs_upg.html#wp1167547"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/installation/guide/csacs_upg.html#wp1167547&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For configuring the authentication of wireless users on ACS 5.1, here are the main concepts explaining the ACS policy model:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/policy_mod.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/policy_mod.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 13:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-acs-5-0-with-controller-4400/m-p/1580169#M258302</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-10T13:53:31Z</dc:date>
    </item>
  </channel>
</rss>

