<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot retrieve AD groups in ACS 5.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-retrieve-ad-groups-in-acs-5-1/m-p/1501162#M316606</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;If you have applied patch 3 and still it didn't work then could you please check if there is any firewall between the domain abd ACS and if you have then please make sure that all ports in FW are opened according to table below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;LDAP 389/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;LDAP 389/udp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;SMB&amp;nbsp;&amp;nbsp; 445/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;KDC 88/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Global catalog&amp;nbsp; 3268/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;KPASS 464/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;NTP 123/udp&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Also, can you, please, take a sniffer capture between ACS and DC at the time you trying to retrieve groups and attach it with&amp;nbsp; ADAgent logs ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Regds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Jun 2010 01:33:29 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2010-06-16T01:33:29Z</dc:date>
    <item>
      <title>Cannot retrieve AD groups in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-retrieve-ad-groups-in-acs-5-1/m-p/1501160#M316528</link>
      <description>&lt;P&gt;Hi, I'm evaluating ACS 5.1 with latest patch before a rollout but I'm having problems trying to retrieve groups from the AD. The ACS status is CONNECTED to the AD, and ACS appears as a computer in the AD, but if I try doing a search for groups I get following error message in logs:&lt;/P&gt;&lt;P&gt;Jun 11 2010 17:35:20 CisACS_33206 39 1 1 BL AD Operation information , ADOperati&lt;BR /&gt;onResult=Encountered Centrify warning while getting groups for domain:DC=prebuil&lt;BR /&gt;d,DC=local Warning: SASL/GSSAPI authentication started&lt;BR /&gt;ldap_sasl_interactive_bind_s: unknown LDAP result code (-50)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; additional info: SASL(-1): generic failure:&lt;BR /&gt;, DomainName=DC=prebuild,DC=local, AdminName=acsadmin, AdminSession=0156D4002CE8&lt;BR /&gt;61075181D7C036B20F0B, AdminInterface=GUI, AdminIPAddress=192.168.1.74&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-retrieve-ad-groups-in-acs-5-1/m-p/1501160#M316528</guid>
      <dc:creator>rcullum</dc:creator>
      <dc:date>2019-03-11T00:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot retrieve AD groups in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-retrieve-ad-groups-in-acs-5-1/m-p/1501161#M316570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By the way, I have installed patch 3 and rebooted so dont think I'm hitting bug&amp;nbsp; CSCtf39158. Anyway this is a single AD environment for eval purposes. AD is win2003 server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jun 2010 07:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-retrieve-ad-groups-in-acs-5-1/m-p/1501161#M316570</guid>
      <dc:creator>rcullum</dc:creator>
      <dc:date>2010-06-15T07:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot retrieve AD groups in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-retrieve-ad-groups-in-acs-5-1/m-p/1501162#M316606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;If you have applied patch 3 and still it didn't work then could you please check if there is any firewall between the domain abd ACS and if you have then please make sure that all ports in FW are opened according to table below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;LDAP 389/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;LDAP 389/udp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;SMB&amp;nbsp;&amp;nbsp; 445/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;KDC 88/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Global catalog&amp;nbsp; 3268/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;KPASS 464/tcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;NTP 123/udp&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Also, can you, please, take a sniffer capture between ACS and DC at the time you trying to retrieve groups and attach it with&amp;nbsp; ADAgent logs ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Regds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 01:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-retrieve-ad-groups-in-acs-5-1/m-p/1501162#M316606</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-06-16T01:33:29Z</dc:date>
    </item>
  </channel>
</rss>

