<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External AD authentication fails. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/external-ad-authentication-fails/m-p/1270620#M348124</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up an Active Directory database as an external resource via Generic LDAP option (I didnt set up via windows database option as my infrastructure does not allow me this). &lt;/P&gt;&lt;P&gt;I am trying to authenticate with no luck. The report database contains the following error message:&lt;/P&gt;&lt;P&gt;Message type: Authentication failed&lt;/P&gt;&lt;P&gt;Authentication Failure Code: External DB reports about an error condition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My configuration steps are as follows: &lt;/P&gt;&lt;P&gt;Process all user names&lt;/P&gt;&lt;P&gt;Qualified by suffix (local.com)&lt;/P&gt;&lt;P&gt;Strip domain before submitting username to LDAP server&lt;/P&gt;&lt;P&gt;User Directory Subtree=dc=local,dc=com&lt;/P&gt;&lt;P&gt;Group Directory Subtree=dc=local,dc=com&lt;/P&gt;&lt;P&gt;User Object Type=SamAccountName&lt;/P&gt;&lt;P&gt;User Object Class=person&lt;/P&gt;&lt;P&gt;Group Object Type=cn&lt;/P&gt;&lt;P&gt;The rest is default settings.&lt;/P&gt;&lt;P&gt;Certificate DB path: empty&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also created an unknown user policy and added my external database in the list of databases and moved it up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I doing wrong? Any help is appreciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Firuza&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:46:49 GMT</pubDate>
    <dc:creator>KarimovaFiruza</dc:creator>
    <dc:date>2019-03-10T23:46:49Z</dc:date>
    <item>
      <title>External AD authentication fails.</title>
      <link>https://community.cisco.com/t5/network-access-control/external-ad-authentication-fails/m-p/1270620#M348124</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up an Active Directory database as an external resource via Generic LDAP option (I didnt set up via windows database option as my infrastructure does not allow me this). &lt;/P&gt;&lt;P&gt;I am trying to authenticate with no luck. The report database contains the following error message:&lt;/P&gt;&lt;P&gt;Message type: Authentication failed&lt;/P&gt;&lt;P&gt;Authentication Failure Code: External DB reports about an error condition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My configuration steps are as follows: &lt;/P&gt;&lt;P&gt;Process all user names&lt;/P&gt;&lt;P&gt;Qualified by suffix (local.com)&lt;/P&gt;&lt;P&gt;Strip domain before submitting username to LDAP server&lt;/P&gt;&lt;P&gt;User Directory Subtree=dc=local,dc=com&lt;/P&gt;&lt;P&gt;Group Directory Subtree=dc=local,dc=com&lt;/P&gt;&lt;P&gt;User Object Type=SamAccountName&lt;/P&gt;&lt;P&gt;User Object Class=person&lt;/P&gt;&lt;P&gt;Group Object Type=cn&lt;/P&gt;&lt;P&gt;The rest is default settings.&lt;/P&gt;&lt;P&gt;Certificate DB path: empty&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also created an unknown user policy and added my external database in the list of databases and moved it up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I doing wrong? Any help is appreciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Firuza&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-ad-authentication-fails/m-p/1270620#M348124</guid>
      <dc:creator>KarimovaFiruza</dc:creator>
      <dc:date>2019-03-10T23:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: External AD authentication fails.</title>
      <link>https://community.cisco.com/t5/network-access-control/external-ad-authentication-fails/m-p/1270621#M348204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know ACS does not have the sub tree query mode in which if a user is not found on the same level that was defined acs will look further levels deep, so you might want to put the user DN pointing exactly where the users are, also your user object type is not defined correctly, if it indeed is the value you are defining, then the correct syntax is sAMAccountName. I would advise to download the following trial "softerra ldap browser" and browse to your AD LDAP infrastructure, and check the right values that you are using, it might be that you are using the defaults which would mean that you would need to use in most of the cases cn user object type and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;Ivan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 21:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-ad-authentication-fails/m-p/1270621#M348204</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-12-02T21:33:24Z</dc:date>
    </item>
  </channel>
</rss>

