<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS Wireless Authentication Failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601836#M283035</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Looks like you have machine authentication enabled. In case of wireless ACS can get the machine names from the authentication request. With this restriction/policy set in the Active Directory to apply the user login restriction then ACS will have to provide a machine/host name for every request that it send to Active Directory. As already established its not possible for ACS to know the real machine name of the user authentication, ACS sends a default machine name its own name with each request to AD. On the AD we create a machine account by ACS name and then allow all the users to be able to log in to this machine. This way ACS is allowed to authenticate every one.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;So please see add the ACS as a computer account on the AD with same hostname and see if thats help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jan 2011 15:48:53 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2011-01-21T15:48:53Z</dc:date>
    <item>
      <title>ACS Wireless Authentication Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601835#M282981</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently migrated from Windows IAS to Cisco ACS 5.2.0.26 for our wireless authentication and use PEAP MSCHAPv2 hitting AD. Everything seems to be working correctly except when a user account has a restriction on which machines they are allowed to log into, at which time an ACS log entry shows as follows,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;24441 Account not permitted to log on using the current workstation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This had been functioning correctly when we were using the IAS server and I'm thinking that ACS just isn't passing the necessary attributes at this time. Does any know how what additional configuration may be needed in ACS to support this configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601835#M282981</guid>
      <dc:creator>robertlwalk</dc:creator>
      <dc:date>2019-03-11T00:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Wireless Authentication Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601836#M283035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Looks like you have machine authentication enabled. In case of wireless ACS can get the machine names from the authentication request. With this restriction/policy set in the Active Directory to apply the user login restriction then ACS will have to provide a machine/host name for every request that it send to Active Directory. As already established its not possible for ACS to know the real machine name of the user authentication, ACS sends a default machine name its own name with each request to AD. On the AD we create a machine account by ACS name and then allow all the users to be able to log in to this machine. This way ACS is allowed to authenticate every one.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;So please see add the ACS as a computer account on the AD with same hostname and see if thats help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2011 15:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601836#M283035</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-21T15:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Wireless Authentication Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601837#M283073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That was the issue and adding the ACS computer account worked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you Jatin!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jan 2011 17:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601837#M283073</guid>
      <dc:creator>robertlwalk</dc:creator>
      <dc:date>2011-01-26T17:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Wireless Authentication Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601838#M283143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad, I could help you&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rgds&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jan 2011 17:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-wireless-authentication-failure/m-p/1601838#M283143</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-26T17:09:12Z</dc:date>
    </item>
  </channel>
</rss>

