<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.2 to use local database when LDAP fails in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655052#M371564</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tiago,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; That does not work when access to the LDAP fails. I get the below error but does not move the authentication to the next identity store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://192.168.23.250/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=24019+Connection+error+was+encountered&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="display: block; color: red;" target="_self"&gt;24019 Connection error was encountered&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Mar 2011 11:29:10 GMT</pubDate>
    <dc:creator>adrian_teo</dc:creator>
    <dc:date>2011-03-24T11:29:10Z</dc:date>
    <item>
      <title>ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655050#M371478</link>
      <description>&lt;P&gt;Hi all, i'm trying to configure acs 5.2 to LDAP external idenity store, when LDAP failes ACS 5.2 should use internal indenity store. I configured A sequence to use LDAP 1st then Internal and i shut off the link to the LDAP but ACS will not use internal,&amp;nbsp; AAA Diagnostics keeps telling me that Cannot establish connection with LDAP server and will not use the internal store.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655050#M371478</guid>
      <dc:creator>adrian_teo</dc:creator>
      <dc:date>2019-03-11T00:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655051#M371509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most likely you are missing the "Continue" option on the Authentication policy.&lt;/P&gt;&lt;P&gt;Please take a look at the screenshot:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/8/3/17389-AdvOptions.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Here i configured the Identity Sequence "Magic Happens" and select "Continue" "If Process Fails" so it moves sequencially along the Identity Sources configured inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 07:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655051#M371509</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2011-03-24T07:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655052#M371564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tiago,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; That does not work when access to the LDAP fails. I get the below error but does not move the authentication to the next identity store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://192.168.23.250/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=24019+Connection+error+was+encountered&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="display: block; color: red;" target="_self"&gt;24019 Connection error was encountered&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 11:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655052#M371564</guid>
      <dc:creator>adrian_teo</dc:creator>
      <dc:date>2011-03-24T11:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655053#M371646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Current functionality is that in case access to database in the sequence (in this case LDAP) fails no further access to databases in the sequence is attempted and may proceed to authorization based on options specified to be performed in case of failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a feature defined to make this behavio configurable and will be in ACS 5.3&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 11:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655053#M371646</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-03-24T11:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655054#M371700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jrabinow,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for the reply, so just let me get this right. As of the current available software 5.2.0.26.3 if the indenity store sequence is configured and if the 1st identity store fails (in this case LDAP) the authentication stopped and theres no way to configure it to move on to the next store. Is there a official statement on this on any of the release notes? I need a official reply from cisco, is the next move to log a tac case to get the official reply that the feature will be available in the ACS 5.3 release???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 11:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655054#M371700</guid>
      <dc:creator>adrian_teo</dc:creator>
      <dc:date>2011-03-24T11:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655055#M371747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To work failover to ldap,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;first you configure sequence for authentication database like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Local database&lt;/P&gt;&lt;P&gt;2.Ldap or AD (if you have)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it works i have tested this.. you just need to reverse.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 15:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655055#M371747</guid>
      <dc:creator>muhammad feroz</dc:creator>
      <dc:date>2011-03-24T15:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655056#M371809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am aware of the following CDETS:&lt;/P&gt;&lt;P&gt;&lt;SPAN id="s_2_2_91_0"&gt;CSCtl05416: &lt;SPAN id="s_2_2_88_0"&gt;Identity sequence ignored if AD fails&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Would apply equally to LDAP failures&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Note the LDAP can have a primary and secondary defined. In such a case a failure would only occur if both failed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 23:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655056#M371809</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-03-24T23:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 to use local database when LDAP fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655057#M371866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi to all, &lt;/P&gt;&lt;P&gt;I have same issue with AD and Internal database.&lt;/P&gt;&lt;P&gt;About CSCtl05416 at that link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtl05416"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtl05416&lt;/A&gt;&lt;SPAN&gt; you can see " Fixed-In 5.3(0.40)"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I upgraded to that version and configured a sequence to use LDAP first then Internal. In version 5.3(0.40) we have a new check box in the Identity Store Sequence configuration: "Continue to next identity store in the sequence" but it don't works, I have same problem as 5.2, when I shut the link to the LDAP, ACS will not use Internal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Maddalena&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 16:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-to-use-local-database-when-ldap-fails/m-p/1655057#M371866</guid>
      <dc:creator>maddalena.selis</dc:creator>
      <dc:date>2012-02-03T16:08:21Z</dc:date>
    </item>
  </channel>
</rss>

