<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure ACS 5.1 with RSA Authentication Manager 7.1 and in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525947#M297039</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;I think what you need to do is create an identity sequence with RSA as the selection in &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Authentication and Attribute Retrieval Search List &lt;SPAN style="background-color: #f8fafd;"&gt;and AD in &lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;Additional Attribute Retrieval Search List. Then select this sequence as the result in the identity policy for the service&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Oct 2010 17:30:21 GMT</pubDate>
    <dc:creator>jrabinow</dc:creator>
    <dc:date>2010-10-06T17:30:21Z</dc:date>
    <item>
      <title>Cisco Secure ACS 5.1 with RSA Authentication Manager 7.1 and Active Directory groups for profiles</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525946#M297037</link>
      <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Tableau Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;I'm deploying an ACS connected to a RSA AuthManager (which is connected to an Active Directory domain)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;I'm creating multiple groups inside the Active Directory server, I'm looking to give different access rights to users regarding to their groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;I tried to define an access policy "NetOp/NetAdm policy" and two authorization rules :&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;Rule-1 AD-AD1:ExternalGroups contains any DIR.INTRA/Groups/NETOP "Auth for net operators" 0 &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;Rule-2 AD-AD1:ExternalGroups contains any DIR.INTRA/Groups/NETADM "Auth for net admin" 0 &lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;Default : Deny&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;In the Identity I configured the RSA identity source, so that users get authenticated by the RSA Authentication Manager.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;But I always get an access deny, the RSA authentication succeeds but the active directory group belonging does not work, even with unix attributes or main group defined for the user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;My question, is this configuration scenario valid ? Is there another way to define multiple profiles depending on the user group from external source ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;The steps from the monitoring :&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;Steps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;11001&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Received RADIUS Access-Request &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;11017&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;RADIUS created a new session &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;Evaluating Service Selection Policy &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15004&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Matched rule &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15012&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Selected Access Service - NetOp/NetAdm policy &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;Evaluating Identity Policy &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15004&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Matched rule &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15013&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Selected Identity Store - RSA Server &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;24500&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Authenticating user against the RSA SecurID Server. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;24501&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;A session is established with the RSA SecurID Server. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;24506&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Check passcode operation succeeded &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;24505&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;User authentication has succeeded. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;24553&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;User record was cached &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;24502&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The session with RSA SecurID Server is closed &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;22037&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Authentication Passed &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;22023&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Proceed to attribute retrieval &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;24628&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;User cache not enabled in the RADIUS token identity store configuration. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;22016&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Identity sequence completed iterating the IDStores &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;Evaluating Group Mapping Policy &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15006&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Matched Default Rule &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;Evaluating Exception Authorization Policy &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15042&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;No rule was matched &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;Evaluating Authorization Policy &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15006&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Matched Default Rule &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15016&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Selected Authorization Profile - DenyAccess &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN lang="EN-US"&gt;15039&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Selected Authorization Profile is DenyAccess &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt; "&gt;11003&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Returned RADIUS Access-Reject &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;Christophe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525946#M297037</guid>
      <dc:creator>ChristopheBerger</dc:creator>
      <dc:date>2019-03-11T00:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure ACS 5.1 with RSA Authentication Manager 7.1 and</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525947#M297039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;I think what you need to do is create an identity sequence with RSA as the selection in &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Authentication and Attribute Retrieval Search List &lt;SPAN style="background-color: #f8fafd;"&gt;and AD in &lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;Additional Attribute Retrieval Search List. Then select this sequence as the result in the identity policy for the service&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 17:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525947#M297039</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2010-10-06T17:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure ACS 5.1 with RSA Authentication Manager 7.1 and</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525948#M297042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the advice, I'll try this solution next week and let you know the result&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Oct 2010 09:44:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525948#M297042</guid>
      <dc:creator>ChristopheBerger</dc:creator>
      <dc:date>2010-10-07T09:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure ACS 5.1 with RSA Authentication Manager 7.1 and</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525949#M297046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help, I missed this detail.&lt;/P&gt;&lt;P&gt;So I added Active Directory as an additionnal attribute search list and the group mapping is now working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Christophe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Oct 2010 08:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-5-1-with-rsa-authentication-manager-7-1-and/m-p/1525949#M297046</guid>
      <dc:creator>ChristopheBerger</dc:creator>
      <dc:date>2010-10-12T08:05:24Z</dc:date>
    </item>
  </channel>
</rss>

