<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows authentication  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285069#M348709</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it belongs to multiple groups in AD, but for the moment the whole AD setup is offline, but still users enter via the group 0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Aug 2009 06:15:39 GMT</pubDate>
    <dc:creator>lni1</dc:creator>
    <dc:date>2009-08-26T06:15:39Z</dc:date>
    <item>
      <title>Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285062#M348660</link>
      <description>&lt;P&gt;We are trying to authenticate against a AD group, instead of authenticating with AD it gives the following message and places the users in the default group, any ideas ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RDS 08/10/2009 23:54:03 P 0786 3192 0x0 Found local user MSNET\ibis5471&lt;/P&gt;&lt;P&gt;RDS 08/10/2009 23:54:03 E 5800 3192 0x0 Failed to get group info about user:MSNET\ibis5471 - CSAuth client has passed userID with invalid id info&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:38:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285062#M348660</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2019-03-10T23:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285063#M348663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a known issue that ACS does look ups based on the outer id instead of the inner id when the outer identity is a username.  For whatever reason, when the outer identity is anonymous, ACS correctly does its lookups based on the inner identity.&lt;/P&gt;&lt;P&gt;It is entirely possible this is why fast-reconnect also fails.  I saw the following entries in the RDS.log that correspond to the reported fast-reconnect error in the Failed Attempts log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2009 23:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285063#M348663</guid>
      <dc:creator>mchin345</dc:creator>
      <dc:date>2009-08-17T23:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285064#M348665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is normal ACS behavior for AD users to show up in the local users database once they have authenticated.  This is a caching feature that is enabled by default(and can be disabled).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are users being allowed access, but these messages are showing up in the logs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Aug 2009 15:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285064#M348665</guid>
      <dc:creator>Robert.N.Barrett_2</dc:creator>
      <dc:date>2009-08-19T15:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285065#M348667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I disabled the whole setup to Windows AD, &lt;/P&gt;&lt;P&gt;so the authentication should fail, still the authentication for the devices are valid, they are in the default group (0).&lt;/P&gt;&lt;P&gt;The default group (0) is off limits for everybody, but still these users enter via this group, how is this possible ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 05:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285065#M348667</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2009-08-21T05:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285066#M348668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create a mapping and map default group with no access group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 08:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285066#M348668</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-08-21T08:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285067#M348669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already did that, it still enters the default group (0),could it be a problem with my link to AD ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 08:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285067#M348669</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2009-08-21T08:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285068#M348688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does that user belongs to multiple group in AD?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 12:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285068#M348688</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-08-21T12:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285069#M348709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it belongs to multiple groups in AD, but for the moment the whole AD setup is offline, but still users enter via the group 0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Aug 2009 06:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-authentication/m-p/1285069#M348709</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2009-08-26T06:15:39Z</dc:date>
    </item>
  </channel>
</rss>

