<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;24427 Access to Active Directory failed&amp;quot; error in ACS 5.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608437#M269888</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working on implementing a RADIUS authentication for wireless access with the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- PCs running Windows 7, protocol used is PEAP (without validating the server certificate to make it simple at first),&lt;/P&gt;&lt;P&gt;- AP 1252&amp;nbsp; configured to use a RADIUS server to authenticate (it's working good with an ACS server 4.2),&lt;/P&gt;&lt;P&gt;- ACS Server 5.1.0.44.5 running as VM connected to an AD domain and working good with VPN connections,&lt;/P&gt;&lt;P&gt;- AD domain running on Windows 2003 Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ACS VM is working good since a couple of months for VPN (RADIUS) and administration (TACACS) remote access, both using Active Directory. Now, I'd like to use it to authenticate people connecting to a 1252 Cisco access point but I'm getting this error "&lt;A href="https://acs/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=24427+Access+to+Active+Directory+failed&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: #ff0000; margin-top: 0pt;" target="_self" title="Click for failure reason details"&gt;24427 Access to Active Directory failed&lt;/A&gt;". I switched from PEAP to LEAP but this is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I can get running the expert troubleshoot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" class="cuesTableNonscrollable" id="progressTable.td"&gt;&lt;TBODY&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R0"&gt;&lt;TD&gt;Investigating failure code: 24427 Access to Active Directory failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowEven" id="progressTable.R1"&gt;&lt;TD&gt;Checking if Active Directory is configured&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R2"&gt;&lt;TD&gt;Active Directory is configured&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowEven" id="progressTable.R3"&gt;&lt;TD&gt;Attempting connection to Active Directory&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R4"&gt;&lt;TD&gt;Connection to Active Directory was successful.&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowEven" id="progressTable.R5"&gt;&lt;TD&gt;Troubleshooting completed.&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R6"&gt;&lt;TD&gt;&lt;P&gt;Click on Show Results Summary to view results.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed this guide, at least for the ACS certificate section :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps10315/products_configuration_example09186a0080b4cdb9.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps10315/products_configuration_example09186a0080b4cdb9.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has an idea where the problem may come from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:41:10 GMT</pubDate>
    <dc:creator>Vincent Fortrat</dc:creator>
    <dc:date>2019-03-11T00:41:10Z</dc:date>
    <item>
      <title>"24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608437#M269888</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working on implementing a RADIUS authentication for wireless access with the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- PCs running Windows 7, protocol used is PEAP (without validating the server certificate to make it simple at first),&lt;/P&gt;&lt;P&gt;- AP 1252&amp;nbsp; configured to use a RADIUS server to authenticate (it's working good with an ACS server 4.2),&lt;/P&gt;&lt;P&gt;- ACS Server 5.1.0.44.5 running as VM connected to an AD domain and working good with VPN connections,&lt;/P&gt;&lt;P&gt;- AD domain running on Windows 2003 Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ACS VM is working good since a couple of months for VPN (RADIUS) and administration (TACACS) remote access, both using Active Directory. Now, I'd like to use it to authenticate people connecting to a 1252 Cisco access point but I'm getting this error "&lt;A href="https://acs/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=24427+Access+to+Active+Directory+failed&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: #ff0000; margin-top: 0pt;" target="_self" title="Click for failure reason details"&gt;24427 Access to Active Directory failed&lt;/A&gt;". I switched from PEAP to LEAP but this is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I can get running the expert troubleshoot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" class="cuesTableNonscrollable" id="progressTable.td"&gt;&lt;TBODY&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R0"&gt;&lt;TD&gt;Investigating failure code: 24427 Access to Active Directory failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowEven" id="progressTable.R1"&gt;&lt;TD&gt;Checking if Active Directory is configured&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R2"&gt;&lt;TD&gt;Active Directory is configured&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowEven" id="progressTable.R3"&gt;&lt;TD&gt;Attempting connection to Active Directory&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R4"&gt;&lt;TD&gt;Connection to Active Directory was successful.&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowEven" id="progressTable.R5"&gt;&lt;TD&gt;Troubleshooting completed.&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="cuesTableRowOdd" id="progressTable.R6"&gt;&lt;TD&gt;&lt;P&gt;Click on Show Results Summary to view results.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed this guide, at least for the ACS certificate section :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps10315/products_configuration_example09186a0080b4cdb9.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps10315/products_configuration_example09186a0080b4cdb9.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has an idea where the problem may come from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608437#M269888</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2019-03-11T00:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608438#M269889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the AD user have dialin permissions enabled by any chance?&lt;BR /&gt;This is to confirm whether we may be hitting a known limitation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To further investigate this we could collect some initial logs from ACS 5.1, in order to start isolating the issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Log in to the ACS command line and enable the following debugs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin# acs-config&lt;BR /&gt;Escape character is CNTL/D.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: &lt;ACS 5="" gui="" user="" name=""&gt; &lt;BR /&gt;Password: &lt;ACS 5="" gui="" password=""&gt;&lt;/ACS&gt;&lt;/ACS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acsadmin(config-acs)# debug-adclient enable&lt;BR /&gt;acsadmin(config-acs)# debug-log mgmt level debug&lt;BR /&gt;acsadmin(config-acs)# debug-log runtime level debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Recreate the issue a couple of times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Take note of the time stamp when you recreate the issue and then collect the ACS support bundle from the Monitoring &amp;amp; Report Viewer, under&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troubleshooting &amp;gt; ACS Support Bundle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be sure of collecting the support bundle while checking the following options:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Include full configuration database = Unchecked&lt;BR /&gt;Include debug logs = All&lt;BR /&gt;Include local logs = All&lt;BR /&gt;Include core files = All&lt;BR /&gt;Include monitoring and reporting logs (all categories checked) = Include files from the last 1 day&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please communicate the time stamp when the issue is observed, so that we can track it faster in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 09:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608438#M269889</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-05T09:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608439#M269891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fede,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used the administrator account to join the AD, I checked and it has dial-in permissions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have downloaded the ACS support bundle, I tried to extract it but all I can get is a .gpg file...how can I check the log files?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the max size for uploaded content is 50MB, I joined the entire file which sizes 18MB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, I recreated the issue at 5:04PM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 16:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608439#M269891</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-01-05T16:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608440#M269893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the support bundle was generated with encryption enabled.&lt;/P&gt;&lt;P&gt;Would it be possible to please re-generate it with the following options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encrypt Support Bundle = Unchecked &amp;lt;&amp;lt;&amp;lt; IMPORTANT&lt;/P&gt;&lt;P&gt;Include full configuration database = Unchecked&lt;/P&gt;&lt;P&gt;Include debug logs = All&lt;/P&gt;&lt;P&gt;Include local logs = All&lt;/P&gt;&lt;P&gt;Include core files = All&lt;/P&gt;&lt;P&gt;Include monitoring and reporting logs (all categories checked) = Include files from the last 1 day&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 18:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608440#M269893</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-05T18:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608441#M269896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see any option to enable or not the encryption. It seems that this features is only supported by ACS 5.2 and I'm using 5.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 09:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608441#M269896</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-01-06T09:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608442#M269897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's right Vincent, sorry if I didn't include all the details in my previous message.&lt;/P&gt;&lt;P&gt;I already tried yesterday also to decrypt the bundle with one of our ACS 5.1, but it failed, so that's why I thought of asking anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you could test to decrypt the support bundle from your side directly:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Load the support bundle to an FTP location.&lt;/P&gt;&lt;P&gt;2. Create an FTP repository on ACS to point to this FTP location.&lt;/P&gt;&lt;P&gt;3. SSH to ACS and enter the "acs-config" mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin# acs-config&lt;/P&gt;&lt;P&gt;Escape character is CNTL/D.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: &lt;ACS 5="" gui="" user="" name=""&gt;&lt;/ACS&gt;&lt;/P&gt;&lt;P&gt;Password: &lt;ACS 5="" gui="" password=""&gt;&lt;/ACS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acsadmin(config-acs)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Then please decrypt the bundle with the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;decrypt-support-bundle &lt;FTP repository="" name=""&gt; acs-support-bundle-01-05-2011-17-05.tar.gz&lt;/FTP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 09:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608442#M269897</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-06T09:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608443#M269898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a further option apart from trying to decrypt the support bundle on your side, could you maybe try to collect it one more time? (being sure to include the logs from the last failure)&lt;/P&gt;&lt;P&gt;If the previous one was corrupted, then the failure in decrypting it could be expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 10:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608443#M269898</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-06T10:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608444#M269899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm stuck at step 4, I am not able to decrypt the support bundle :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;acs/ACSAdmin(config-acs)# decrypt-support-bundle pc_vincent_ftp acs_acs_support.tar.gpg&lt;BR /&gt;Decrypting Support Bundle...&lt;BR /&gt;Repository: pc_vincent_ftp&lt;BR /&gt;Support Bundle: acs_acs_support.tar.gpg&lt;BR /&gt;Unable to import file 'acs_acs_support.tar.gpg' from remote repository 'pc_vincent_ftp'&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at my FTP server log file, ACS doesn't even try to access the repository which is working (I used it to load the patch file for ACS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried using FTP but it doesn't work either. Did you manage to get this command working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 11:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608444#M269899</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-01-06T11:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608445#M269900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's exactly the very same error message I am getting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you maybe test by recreating the issue today and re-download the support bundle with the logs just from today?&lt;/P&gt;&lt;P&gt;Then, without trying to uncompress the bundle with other tools, just attach it here (or even try to decrypt it yourself with the procedure I posted before)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am suspecting that something got corrupted in the previous support bundle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 11:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608445#M269900</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-06T11:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608446#M269901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's exactly the very same error message I am getting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you maybe test by recreating the issue today and re-download the &lt;/P&gt;&lt;P&gt;support bundle with the logs just from today?&lt;/P&gt;&lt;P&gt;Then, without trying to uncompress the bundle with other tools, just &lt;/P&gt;&lt;P&gt;attach it here (or even try to decrypt it yourself with the procedure I &lt;/P&gt;&lt;P&gt;posted before)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am suspecting that something got corrupted in the previous support bundle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If  this helps you and/or answers your question please mark the question &lt;/P&gt;&lt;P&gt;as  "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 11:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608446#M269901</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-06T11:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608447#M269902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like you suggest, I re-downloaded the support bundle but I'm still not able to decrypt it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 14:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608447#M269902</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-01-06T14:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608448#M269903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The next best alternative I could think of is to collect the log files through "show" commands on the ACS command line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show acs-logs filename ACSManagement.log&lt;/P&gt;&lt;P&gt;show acs-logs filename acsRuntime.log&lt;/P&gt;&lt;P&gt;show acs-logs filename ACSADAgent.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to please log the full output of these three commands right after having recreated the issue.&lt;/P&gt;&lt;P&gt;In case you'd like to filter even further for a specific month (so not to collect also the logs from December for example), you could also try the following syntax:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show acs-logs filename ACSManagement.log | i Jan&lt;/P&gt;&lt;P&gt;show acs-logs filename acsRuntime.log | i Jan&lt;/P&gt;&lt;P&gt;show acs-logs filename ACSADAgent.log | i Jan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 17:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608448#M269903</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-06T17:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608449#M269904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try to run the commands but the log files are pretty big ! and almost impossible to copy/paste in a text file. Any idea to download the full files from ACS ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 09:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608449#M269904</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-01-07T09:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608450#M269905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know it's a bit of a pain &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You could maybe try to simply keep scrolling and logging the text output in the meantime (so no copy+paste needed).&lt;BR /&gt;In Putty for example, this can be done by right-clicking on the window's bar and selecting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;change settings... &amp;gt; logging &amp;gt; all session output &amp;gt; (browse to where you'd like to save the file) &amp;gt; apply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, the only logs we can transfer through the "copy" command are those for ADE, which are not useful for our issue.&lt;BR /&gt;The debugging logs we are looking for are stored internally and cannot be retrieved via FTP for example with the standard commands. There is a patch that we could install to access the underlying Linux OS, but for us to publish this you would need to go through the official channel of a TAC case:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/ServiceRequestTool/create/launch.do"&gt;http://tools.cisco.com/ServiceRequestTool/create/launch.do&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 11:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608450#M269905</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-07T11:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608451#M269906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently out of office for a couple of days. I'll let you know as soon as I have some more information to investigate our problem, probably on friday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 09:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608451#M269906</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-01-11T09:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608452#M269907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Vincent, looking forward to hearing back from you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 10:04:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608452#M269907</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-11T10:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608453#M269908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you're doing great since our last conversation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since my last post, I upgraded my ACS to 5.2 version. I did exactly the same thing as previously with 5.1 release and I'm getting the exact same error...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now, I'm able to generate a support bundle without encryption so you will be able to take a look at the log files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I experienced my authentication failure around 17:15PM today.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thans again for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Feb 2011 17:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608453#M269908</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-02-22T17:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608454#M269909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not giving up so I did some additionnal tests today. I make it work by changing the protocol and/or the inner method used by the protocol. My conclusion is each time I use MS-CHAP (v1 or v2) as inner method it fails (LEAP, EAP-FAST or MS-PEAP) but each time I use EAP-GTC as inner method it works (EAP-FAST and CISCO-PEAP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked my ACS configuration. In the "allowed protocols" section of my default network access policy, MS-CHAP inner method is allowed for PEAP and EAP-FAST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what could cause the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Feb 2011 16:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608454#M269909</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2011-02-23T16:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608455#M269910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem was gone for some time and since yesterday, I'm having trouble authenticating with any protocol using MSCHAP as inner method. I upgraded my ACS server to 5.3.0.40 (patch 1) but the problem is still there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea or investigation tip to help ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 15:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608455#M269910</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2012-01-04T15:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: "24427 Access to Active Directory failed" error in</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608456#M269911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AD User must have permissions to add and remove users and machines in the field.&lt;/P&gt;&lt;P&gt;&lt;BR style="font-family: arial, sans-serif; font-size: 16px; text-align: -webkit-auto; background-color: #f5f5f5;" /&gt;&lt;/P&gt;&lt;P&gt;And make sure your password is working perfectly, you can test by logging on any machinein the field.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 15:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-24427-access-to-active-directory-failed-quot-error-in-acs-5/m-p/1608456#M269911</guid>
      <dc:creator>jonmarso_07</dc:creator>
      <dc:date>2012-01-04T15:25:56Z</dc:date>
    </item>
  </channel>
</rss>

