<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.2 does not check Active directory changes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516440#M350790</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you can help me with a similar issue i am facing on migration from Cisco ACS 4.1.24 to Cisco 5.3.0.40&lt;/P&gt;&lt;P&gt;and testing Radius authentication for vpn client users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authentication method used is external Active Directory and for some users authenticating to the external AD via ACS, the following message is obtained:&lt;/P&gt;&lt;P&gt;"15039 Selected Authorization Profile is DenyAcces", which results in Auth failure.&lt;/P&gt;&lt;P&gt;Other users on the same AD group seem to work fine and there are no changes performed on the AD for any of the&amp;nbsp; concerned users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the detail report for the user, confirms&amp;nbsp; that no attributes&amp;nbsp; are returned to the Radius(under the other&amp;nbsp; attributes field) from the&amp;nbsp; external server. The Radius also returns the&amp;nbsp; following messages:&lt;/P&gt;&lt;P&gt;"24412 User not&amp;nbsp; found in Active Directory"&lt;/P&gt;&lt;P&gt;"22056 Subject not found in the applicable&amp;nbsp; identity store(s)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Within the ACS Identity sequence in the ID store, the&amp;nbsp; sequence is set to match on AD first and then Internal user.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The&amp;nbsp; Identity for the default network profile(for Radius users) is&amp;nbsp; configured to General sequence. The same user/s seem to work fine when&amp;nbsp; swithced to ACS4.&lt;/P&gt;&lt;P&gt;We are also looking at possible NTP sync issue with the ACS/AD or&amp;nbsp; any NTLM/Kerberos auth issues or any issues related to applying the&amp;nbsp; latest ACS patch to the box.Please let me know if there is any AD related configs to be modified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Sep 2012 09:20:38 GMT</pubDate>
    <dc:creator>mohankumarm</dc:creator>
    <dc:date>2012-09-03T09:20:38Z</dc:date>
    <item>
      <title>ACS 5.2 does not check Active directory changes</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516436#M350329</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working with ACS 5.2 and using Radius authentication for vpn client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authentication method used is Active Directory in an Windows enviroment with multiple domains in the same forest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem occurs when i change a user from one group to another in Active Directory. After that i receive the following message when try to connect:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;15039 Selected Authorization Profile is DenyAccess&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message is because match the default policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another user in the same AD group works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All domain in the forest have trust relation each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using universal groups to include users from all domain belongs this forest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516436#M350329</guid>
      <dc:creator>cpfl_vzuben</dc:creator>
      <dc:date>2019-03-11T00:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 does not check Active directory changes</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516437#M350405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is your authentication rule matching against a single AD group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check which groups were retrieved for the user as follows:&lt;/P&gt;&lt;P&gt;- goto "Monitoring and Troublshooting"&lt;/P&gt;&lt;P&gt;- select &lt;A href="https://community.cisco.com/" title="Click to run"&gt;Authentications - RADIUS - Today&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- Find the entry that did not match and click on the details icon&lt;/P&gt;&lt;P&gt;- Expand "Authentication Details" section. Look under "Other Attributes" the groups retrieved from AD for the user will be listed there&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Oct 2010 22:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516437#M350405</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2010-10-14T22:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 does not check Active directory changes</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516438#M350589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jrabinow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked wich groups the user belongs and i didn't find the group that match the policy. But&amp;nbsp; it's a problem, because i checked in active directory wich group the user belongs and there are 2 groups that ACS does not find.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Properties from this user was changed in Active Directory some days ago and does not appear in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible ACS keep a cache about this attributes and does'nt check AD to uptade this settings?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another ACS vs 4.1 here and the same problem occurs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Evandro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Oct 2010 13:57:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516438#M350589</guid>
      <dc:creator>cpfl_vzuben</dc:creator>
      <dc:date>2010-10-15T13:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 does not check Active directory changes</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516439#M350688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jrabinow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you help me with same instructions, i could see the Global Catalog server was not updated in the ACS log. Then i change DNS Server address in the ACS Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After change the DNS Server, the ACS starts to check another Global Catalog Server in AD forest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Until now the problem was resolved. I believe this problem was in AD not in ACS Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Evandro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 15:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516439#M350688</guid>
      <dc:creator>cpfl_vzuben</dc:creator>
      <dc:date>2010-10-19T15:36:06Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 does not check Active directory changes</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516440#M350790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you can help me with a similar issue i am facing on migration from Cisco ACS 4.1.24 to Cisco 5.3.0.40&lt;/P&gt;&lt;P&gt;and testing Radius authentication for vpn client users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authentication method used is external Active Directory and for some users authenticating to the external AD via ACS, the following message is obtained:&lt;/P&gt;&lt;P&gt;"15039 Selected Authorization Profile is DenyAcces", which results in Auth failure.&lt;/P&gt;&lt;P&gt;Other users on the same AD group seem to work fine and there are no changes performed on the AD for any of the&amp;nbsp; concerned users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the detail report for the user, confirms&amp;nbsp; that no attributes&amp;nbsp; are returned to the Radius(under the other&amp;nbsp; attributes field) from the&amp;nbsp; external server. The Radius also returns the&amp;nbsp; following messages:&lt;/P&gt;&lt;P&gt;"24412 User not&amp;nbsp; found in Active Directory"&lt;/P&gt;&lt;P&gt;"22056 Subject not found in the applicable&amp;nbsp; identity store(s)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Within the ACS Identity sequence in the ID store, the&amp;nbsp; sequence is set to match on AD first and then Internal user.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The&amp;nbsp; Identity for the default network profile(for Radius users) is&amp;nbsp; configured to General sequence. The same user/s seem to work fine when&amp;nbsp; swithced to ACS4.&lt;/P&gt;&lt;P&gt;We are also looking at possible NTP sync issue with the ACS/AD or&amp;nbsp; any NTLM/Kerberos auth issues or any issues related to applying the&amp;nbsp; latest ACS patch to the box.Please let me know if there is any AD related configs to be modified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2012 09:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516440#M350790</guid>
      <dc:creator>mohankumarm</dc:creator>
      <dc:date>2012-09-03T09:20:38Z</dc:date>
    </item>
    <item>
      <title>We had an issue where ACS was</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516441#M350877</link>
      <description>&lt;P&gt;We had an issue where ACS was doing Active Directory authentication lookup to Global Catalog Server.&amp;nbsp; We were seeing user not found in Active Directory.&amp;nbsp; The issue was that the user had the same account login in two different domains.&amp;nbsp; The Windows administrator removed one of the accounts and authentication started working immediately after replication.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;24412 User not found in Active Directory&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 18:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-does-not-check-active-directory-changes/m-p/1516441#M350877</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2016-11-02T18:38:47Z</dc:date>
    </item>
  </channel>
</rss>

