<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: authentication between the ACS and AD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588215#M305860</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Jatin.... &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Jan 2011 13:06:17 GMT</pubDate>
    <dc:creator>sidcracker</dc:creator>
    <dc:date>2011-01-31T13:06:17Z</dc:date>
    <item>
      <title>authentication between the ACS and AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588213#M305832</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know the kind of authentication mechanism ACS 5.1 uses to talk with the Active Directory. Does it use MSCHAP or MSCHAPv2 or just plain PAP. By default it uses PAP to speak between the Cisco IOS and the ACS on the 5.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you llook at the default device admin tab and click on allowed protocols ---&amp;gt; it mentions PAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DOes it use a secure means of transport between the ACS and AD. Idf so can anyone tell the authentication mechanism?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588213#M305832</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2019-03-11T00:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: authentication between the ACS and AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588214#M305843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Any administration session like telnet, ssh and console they always use PAP as an authentication method.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Though pap communication can be captured and read as it happens in clear text. However, since we have tacacs in use, it always encrypt the whole packet with shared secret defined on the IOS and ACS/TACACS so if you capture the traffic between the tacacs and device you won't be able to decrypt it without the key. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;In case you have radius then use SSH (Putty) so that it can help you for secure communication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;ACS and AD do support CHAP, MSCHAPv1 and MSCHAPv2 and PAP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;However, these administration doesn't work on other authentication method except PAP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts~&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 13:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588214#M305843</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-31T13:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: authentication between the ACS and AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588215#M305860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Jatin.... &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 13:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588215#M305860</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2011-01-31T13:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: authentication between the ACS and AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588216#M305893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your welcome &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 15:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-between-the-acs-and-ad/m-p/1588216#M305893</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-31T15:34:13Z</dc:date>
    </item>
  </channel>
</rss>

