<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External db account restriction in Cisco ACS v3.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586075#M278318</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the user properties on the Active directory. Maybe the dial-in properties are defined as denied. please change them to "allow access".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Jan 2011 09:46:10 GMT</pubDate>
    <dc:creator>andamani</dc:creator>
    <dc:date>2011-01-31T09:46:10Z</dc:date>
    <item>
      <title>External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586072#M278144</link>
      <description>&lt;P&gt;I'm trying to setup a wireless network using cisco 1240AG access points (for AAA clients) and Cisco ACS 3.3 for the AAA server and Active Directory for authentication. Wireless laptops are able to communicate with the access points and the ACS but I keep getting an authentication error in the ACS server saying "Authentication Failed" and the reason its giving is "External DB account restriction". Any idea what this error is? I think ACS isn't able to communicate with AD or something. Please advice. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586072#M278144</guid>
      <dc:creator>zhinminbuay</dc:creator>
      <dc:date>2019-03-11T00:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586073#M278208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Meaning of the error message&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;External DB account restriction : The Windows User Account is restricted : The windows administrator must reset this option. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;ACS troubleshooting guide&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1.3/troubleshooting/guide/ecodes.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1.3/troubleshooting/guide/ecodes.html&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;When you try to authenticate via ACS and see failed authentication on the ACS,could you please take a look on the group you are dropped in.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;This can occur either due to permission issues or if your user is being mapped to DISABLED or NO-ACCESS group on the ACS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Once you have the group which the failed user belongs to, go to that group and click on edit group. It shouldn't ne disabled or noaccess group (Group 0 is what we called noaccess group).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If you're getting mapped to correct map then this is surely windows permission issue. You have to ensure that ACS software running on windows machine should have domain admin rights.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;There are some permissions those need to be granted on the windows machine it is installed.You may check from below listed link&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;1.Acs is installed on the member server or DC and permissions are configured as per the following doc:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/install/inst02.htm#wp981552"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/install/inst02.htm#wp981552&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If you're running ACS on member server do make sure that you have completed post installation task for local security policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/installation/guide/windows/install.html#wp981858"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/installation/guide/windows/install.html#wp981858&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts~&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 08:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586073#M278208</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-31T08:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586074#M278269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I logged into the ACS v3.3 and selected the "Group setup" the disabled box is uncheck under the Group disabled. Do I need to manually add the user to enable the authentication ?Sorry for any inconvenience as I am still new to ACS. Please advice. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 09:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586074#M278269</guid>
      <dc:creator>zhinminbuay</dc:creator>
      <dc:date>2011-01-31T09:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586075#M278318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the user properties on the Active directory. Maybe the dial-in properties are defined as denied. please change them to "allow access".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 09:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586075#M278318</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-01-31T09:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586076#M278355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;No worries, keep us posted until you get the resolution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Well, if the users resides on the ACS internal database and not in the AD-active directory then you have to placed users manually in their resoective groups. However, if this setup includes active directory then group mapping would do.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Group-mapping&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/user/guide/qg.html#wp940515"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/user/guide/qg.html#wp940515&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts~&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 09:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586076#M278355</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-31T09:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586077#M278374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Previously, all the users are able to authenticate. But unable to authenticate anymore and no configuration changes on the AP, ACS and AD. AD and ACS are in domain A while users laptops are in domain B.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 09:49:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586077#M278374</guid>
      <dc:creator>zhinminbuay</dc:creator>
      <dc:date>2011-01-31T09:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586078#M278392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The authentication is done by the Windows Database &lt;SPAN style="background-color: #f8fafd;"&gt;configured in the Unknown user policy. By right if the user account is not in the ACS, it will automatically authenticate via external windows database. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 09:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586078#M278392</guid>
      <dc:creator>zhinminbuay</dc:creator>
      <dc:date>2011-01-31T09:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586079#M278406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the dial-in under the user account but is for the VPN remote access dial in. But seem no settings can be change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=1&amp;amp;orderType=1&amp;amp;seq=1465"&gt;Date&lt;/A&gt; &lt;IMG src="https://community.cisco.com/images/sortDecending.gif" /&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=2&amp;amp;orderType=1&amp;amp;seq=1466"&gt;Time&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=3&amp;amp;orderType=1&amp;amp;seq=1467"&gt;Message-Type&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=4&amp;amp;orderType=1&amp;amp;seq=1468"&gt;User-Name&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=5&amp;amp;orderType=1&amp;amp;seq=1469"&gt;Group-Name&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=6&amp;amp;orderType=1&amp;amp;seq=1470"&gt;Caller-ID&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=7&amp;amp;orderType=1&amp;amp;seq=1471"&gt;Authen-Failure-Code&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=8&amp;amp;orderType=1&amp;amp;seq=1472"&gt;Author-Failure-Code&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=9&amp;amp;orderType=1&amp;amp;seq=1473"&gt;Author-Data&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=10&amp;amp;orderType=1&amp;amp;seq=1474"&gt;NAS-Port&lt;/A&gt;&lt;/TH&gt;&lt;TH bgcolor="#c0c0c0"&gt;&lt;A href="https://community.cisco.com/setup.exe?action=make_page&amp;amp;page=csv_report_page&amp;amp;line=1&amp;amp;title=&amp;amp;sortColumn=11&amp;amp;orderType=1&amp;amp;seq=1475"&gt;NAS-IP-Address&lt;/A&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;01/31/2011&lt;/TD&gt;&lt;TD align="left"&gt;18:09:38&lt;/TD&gt;&lt;TD align="left"&gt;Authen failed&lt;/TD&gt;&lt;TD align="left"&gt;tester02&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;0012.f08a.36d4&lt;/TD&gt;&lt;TD align="left"&gt;External DB user invalid or bad password&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;663&lt;/TD&gt;&lt;TD align="left"&gt;172.24.11.10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;01/31/2011&lt;/TD&gt;&lt;TD align="left"&gt;18:09:04&lt;/TD&gt;&lt;TD align="left"&gt;Authen failed&lt;/TD&gt;&lt;TD align="left"&gt;Tester02&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;0012.f08a.36d4&lt;/TD&gt;&lt;TD align="left"&gt;External DB user invalid or bad password&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;662&lt;/TD&gt;&lt;TD align="left"&gt;172.24.11.10&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tester02 username is created inside the AD for testing purpose. No account being created inside the ACS. Please advice. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 10:14:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586079#M278406</guid>
      <dc:creator>zhinminbuay</dc:creator>
      <dc:date>2011-01-31T10:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: External db account restriction in Cisco ACS v3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586080#M278421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;This is more of permission issue. looks like you are using ACS windows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;here are the steps to create package.cab file :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Below is the procedure to get the package.cab file from the ACS server.. Set detailed&lt;BR /&gt;logging mode(system config ==&amp;gt;service control ===&amp;gt;Services Log File&lt;BR /&gt;Configuration-full).&amp;nbsp; This will ensure that all the proper service startup information is&lt;BR /&gt;included in the package.cab file. &lt;BR /&gt; &lt;BR /&gt;- Log onto the ACS server itself as the local administrator.&lt;BR /&gt;- Browse to the UTILS directory in the ACS program directory.(C:\program files\ciscosecure&lt;BR /&gt;acs v3.x\utils)&lt;BR /&gt;- Run the program there called CSSupport.&lt;BR /&gt;- Select "Set Log Levels Only" and click Next.&lt;BR /&gt;- Select "Set Diagnostic Log Verbosity to Maximum."&lt;BR /&gt;- Click Next, then click Finish.&lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;At this point, we need to duplicate the issue. Once that's done, we need to gather the verbose logs created.&amp;nbsp; To do so, follow the instructions below AFTER the problem has been recreated and recorded:&lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;- Log onto the ACS server itself as the local administrator.&lt;BR /&gt;- Browse to the UTILS directory in the ACS program directory.&lt;BR /&gt;- Run the program there called CSSupport.&lt;BR /&gt;- Select "Run Wizard" and click Next.&lt;BR /&gt;- Only do these steps if we need more than today's logs:&lt;BR /&gt;- Put a check in both "Previous Logs" checkbox.&lt;BR /&gt;- Select the number of days to go back.&lt;BR /&gt;- Click Next four times. Select the radius/tacacs capture option as applicable&lt;BR /&gt;- When the Finish button appears, click it.&lt;BR /&gt; &lt;BR /&gt;The package.cab will be found in the UTILS\Support directory under the ACS program directory. This file contains all of the log information from ACS &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;~Do rate helpful posts~&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 10:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-db-account-restriction-in-cisco-acs-v3-3/m-p/1586080#M278421</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-31T10:27:46Z</dc:date>
    </item>
  </channel>
</rss>

