<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Password Aging &amp; Account Lockout in ACS 4.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644180#M330719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yusuf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password Aging on ACS will just prompt to change the password. it will not disable the account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Account is present on the AD. So the Disabling and lockout features for an account will come from the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think a change in password for a guest account is what you would want to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also according to me disabling the account should be a feature only for the AD admin and not open. A lockout can definately happen but that also has to be defined on the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link to password Aging on ACS is as follows:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp525115"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp525115&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this string as answered if you feel the query is answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Jan 2011 07:10:11 GMT</pubDate>
    <dc:creator>andamani</dc:creator>
    <dc:date>2011-01-08T07:10:11Z</dc:date>
    <item>
      <title>Password Aging &amp; Account Lockout in ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644179#M330718</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;I have a requirement that in ACS the&amp;nbsp; user accounts should get disabled after 1 day , so in the group setting under the Password Aging Field I configured the same as 1 day , the Grace &amp;amp; Warning Period is 0 days&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;I want that all these user accounts would be active for 30 days , and the moment the account is used (i.e the Start Message appears in the Radius Accounting ) then after 1 day&amp;nbsp; from the usage then as per the Password Aging Rule the account should get expired.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Now my query is this password aging rule will start from the day I create the account in the ACS or from the day the user logs in.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;I don’t want to use the Account Lockout Tab as I don’t know when the guest account would be used.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Request someone to help pls clarify my doubt.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644179#M330718</guid>
      <dc:creator>yusuf.ujjainwala</dc:creator>
      <dc:date>2019-03-11T00:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Password Aging &amp; Account Lockout in ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644180#M330719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yusuf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password Aging on ACS will just prompt to change the password. it will not disable the account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Account is present on the AD. So the Disabling and lockout features for an account will come from the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think a change in password for a guest account is what you would want to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also according to me disabling the account should be a feature only for the AD admin and not open. A lockout can definately happen but that also has to be defined on the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link to password Aging on ACS is as follows:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp525115"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp525115&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this string as answered if you feel the query is answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Jan 2011 07:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644180#M330719</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-01-08T07:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Password Aging &amp; Account Lockout in ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644181#M330720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct that we dont want the guest to change the password. Our idea is that we will create generic accounts whose account validity would be say for 30 days.&amp;nbsp; Now within the 30 days whenever the account is used then if the Password Aging Parameter is set as 1 day then after 1 day of usage the password would get expired and&amp;nbsp; we know for sure that the guest would not be able to use the account even though it is active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are not creating any accounts on the AD , all the accounts are on the local ACS internal database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not clear if the requirement can be met through the Password Aging Parameter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Jan 2011 07:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644181#M330720</guid>
      <dc:creator>yusuf.ujjainwala</dc:creator>
      <dc:date>2011-01-08T07:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Password Aging &amp; Account Lockout in ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644182#M330721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yusuf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password aging is used when the users are present in AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i guess to restrict the access of the account on the local database of the ACS, one can try the combinations of set max sessions, user usage quotas and user account disablement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never tried it. I am not sure if that will work, but i guess it is worth a try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link which explains the following is as following:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrMgt.html#wp273024"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrMgt.html#wp273024&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you think your query is answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Jan 2011 07:44:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644182#M330721</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-01-08T07:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Password Aging &amp; Account Lockout in ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644183#M330722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will go with your suggestion of the Usage Policy etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Jan 2011 08:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-aging-account-lockout-in-acs-4-2/m-p/1644183#M330722</guid>
      <dc:creator>yusuf.ujjainwala</dc:creator>
      <dc:date>2011-01-08T08:24:56Z</dc:date>
    </item>
  </channel>
</rss>

