<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS and two Windows Active Directory Domains in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194004#M364143</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a 2 way trust with the two domains, have you checked that the user that ACS uses to read and query the Domains lies on both domains and has read privileges?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Feb 2009 01:59:20 GMT</pubDate>
    <dc:creator>Ivan Martinon</dc:creator>
    <dc:date>2009-02-03T01:59:20Z</dc:date>
    <item>
      <title>ACS and two Windows Active Directory Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194003#M364142</link>
      <description>&lt;P&gt;Can one ACS server authenticate users against two different AD domains?  The server is a member server of one domain. We are not able to enumerate the groups from the second domain.  There is a two way trust between the domains.  &lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:25:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194003#M364142</guid>
      <dc:creator>ursshared</dc:creator>
      <dc:date>2019-03-26T00:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and two Windows Active Directory Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194004#M364143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a 2 way trust with the two domains, have you checked that the user that ACS uses to read and query the Domains lies on both domains and has read privileges?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 01:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194004#M364143</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-03T01:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and two Windows Active Directory Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194005#M364144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We authenticate multiple domains like this, We have a proxy domain that contains the acs remote agents. The proxy domain trusts the domains to be authenticated against. In ACS you will be able to see all of the domains that the proxy trusts. When you go about mapping domain groups to acs groups you have to manually add the group name. ACS can enumerate the group to authenticate users, but ACS cannot seem to traverse multiple domains during the setup phase. Hope this helps.&lt;/P&gt;&lt;P&gt;Bob &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2009 23:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194005#M364144</guid>
      <dc:creator>frbilbrey</dc:creator>
      <dc:date>2009-03-05T23:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and two Windows Active Directory Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194006#M364145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;are the users in multiple groups in the multiple domains, if so mapping should be done differently than you would if users were in a single group so that users are properly mapped to a group &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2009 23:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-two-windows-active-directory-domains/m-p/1194006#M364145</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2009-03-06T23:12:38Z</dc:date>
    </item>
  </channel>
</rss>

