<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS appliance setup help in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-appliance-setup-help/m-p/908042#M386354</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS Agent is installed on two DC's as well and they are detected by ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 24 Feb 2008 17:42:12 GMT</pubDate>
    <dc:creator>m_popovic</dc:creator>
    <dc:date>2008-02-24T17:42:12Z</dc:date>
    <item>
      <title>ACS appliance setup help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-appliance-setup-help/m-p/908041#M386353</link>
      <description>&lt;P&gt;Network environment:&lt;/P&gt;&lt;P&gt;-	Windows 2003 with enterprise CA&lt;/P&gt;&lt;P&gt;-	Cisco ACS appliance 4.1.1.23&lt;/P&gt;&lt;P&gt;-	Cisco 1240 AG series APs&lt;/P&gt;&lt;P&gt;Wireless clients:&lt;/P&gt;&lt;P&gt;-	Windows XP SP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brief steps taken:&lt;/P&gt;&lt;P&gt;-	Installed Enterprise CA&lt;/P&gt;&lt;P&gt;-	Created copy of web server certificate with option â&amp;#128;&amp;#156;Mark keys as exportableâ&amp;#128;&amp;#157; enabled. Certificate published.&lt;/P&gt;&lt;P&gt;-	Created global group in AD that contains test user and a single laptop that is a member of domain - for auto enrolment.&lt;/P&gt;&lt;P&gt;-	Generated certificate request from ACS (1024 key length).&lt;/P&gt;&lt;P&gt;-	Submitted server request from ftp server - Submit a certificate request using base 64â&amp;#128;¦&lt;/P&gt;&lt;P&gt;-	Submitted CA certificate request from ftp server - Retrieve CA certificate or revocation list /base 64 encoded.&lt;/P&gt;&lt;P&gt;-	CA &amp;amp; server certificates installed in to ACS appliance (Domain certificate authority approved within ACS)&lt;/P&gt;&lt;P&gt;-	&lt;/P&gt;&lt;P&gt;Brief cofig of ACS appliance&lt;/P&gt;&lt;P&gt;Global config&lt;/P&gt;&lt;P&gt;-	PEAP -Selected â&amp;#128;&amp;#156;Allow EAP-MSCHAPv2â&amp;#128;&amp;#157;.&lt;/P&gt;&lt;P&gt;-	LEAP - Allow LEAP (For Aironet only)&lt;/P&gt;&lt;P&gt;-	Selected  â&amp;#128;&amp;#156;Allow MS-CHAP Version 1 &amp;amp; 2 authentication&lt;/P&gt;&lt;P&gt;-	Added AAA client (AP) with shared secret with authentication using â&amp;#128;&amp;#156;Radius (Cisco Aironet)&lt;/P&gt;&lt;P&gt;-	Under External user DB//DB config/windows database, â&amp;#128;&amp;#156;Enable PEAP machine authenticationâ&amp;#128;&amp;#157; selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1240 series AP config&lt;/P&gt;&lt;P&gt;-	Under Server Manager, ACS IP with shared secret entered as a Radius server.&lt;/P&gt;&lt;P&gt;-	Selected EAP authentication.&lt;/P&gt;&lt;P&gt;-	Under SSID Manager selected open Authentication with EAP &amp;amp; selected network EAP.&lt;/P&gt;&lt;P&gt;-	Under Encryption Manager selected WEP Encryption &amp;amp; mandatory.&lt;/P&gt;&lt;P&gt;-	Selected key 1 and entered 128 bit key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client (windows XP SP2 domain member) config&lt;/P&gt;&lt;P&gt;-	Connected to Enterprise CA web site, base64 encoding/download CA certificate 	&lt;/P&gt;&lt;P&gt;and installed it in local computer store.&lt;/P&gt;&lt;P&gt;-	Under  Network authentication selected open with WEP EAP type â&amp;#128;&amp;#156;protected EAP (PEAP)&lt;/P&gt;&lt;P&gt;-	Authenticate as a computer selected&lt;/P&gt;&lt;P&gt;-	Selected my CA under â&amp;#128;&amp;#156;Trusted Certification Authorities &lt;/P&gt;&lt;P&gt;-	Authentication method (EAP-MSCHAP V2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Errors: &lt;/P&gt;&lt;P&gt;Automatic certificate enrollment to local system failed to contact the AD. The specified domain does not exist or cannot be contacted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Computer doesn't have correct certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Used 43486, 64067, 71929&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions very much apretiated.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-appliance-setup-help/m-p/908041#M386353</guid>
      <dc:creator>m_popovic</dc:creator>
      <dc:date>2019-03-10T22:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: ACS appliance setup help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-appliance-setup-help/m-p/908042#M386354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS Agent is installed on two DC's as well and they are detected by ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2008 17:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-appliance-setup-help/m-p/908042#M386354</guid>
      <dc:creator>m_popovic</dc:creator>
      <dc:date>2008-02-24T17:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: ACS appliance setup help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-appliance-setup-help/m-p/908043#M386355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've got it running. Most of the answers were in the doc # 43486.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 16:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-appliance-setup-help/m-p/908043#M386355</guid>
      <dc:creator>m_popovic</dc:creator>
      <dc:date>2008-02-26T16:45:02Z</dc:date>
    </item>
  </channel>
</rss>

