<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank for you reply, and I in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728817#M394102</link>
    <description>&lt;P&gt;Thank for you reply, and I wonder that the ISE you use now is use chap or EAP-TLS?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jun 2016 07:58:56 GMT</pubDate>
    <dc:creator>xiaodong liao</dc:creator>
    <dc:date>2016-06-29T07:58:56Z</dc:date>
    <item>
      <title>ACS 5.1 CHAP authentication internal user</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728809#M393830</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to authenticate some android smartphones with CHAP to ACS internal user database. The problem is the password. We had try some combinations but always some result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="S2"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15004&amp;nbsp; Matched rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15013&amp;nbsp; Selected Identity Store - Internal Users&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24210&amp;nbsp; Looking up User in Internal Users IDStore - Testuser&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24212&amp;nbsp; Found User in Internal Users IDStore&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22063&amp;nbsp; Wrong password&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #ff0000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22057&amp;nbsp; The advanced option that is configured for a failed authentication request is used.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #ff0000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22061&amp;nbsp; The 'Reject' advanced option is configured in case of a failed authentication request.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #ff0000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11003&amp;nbsp; Returned RADIUS Access-Reject&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password is same on phone and acs internal user. I don't kown what is wrong.&lt;/P&gt;&lt;P&gt;If there a option for CHAP with password ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;Lars&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728809#M393830</guid>
      <dc:creator>Lars Reidelbach</dc:creator>
      <dc:date>2019-03-11T01:10:11Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 CHAP authentication internal user</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728810#M393835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The shared secret between the AAA client on the ACS and the phone has to be the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS Network Resources &amp;gt; network Devices and AAA client &amp;gt; Radius/TACACS &amp;gt; Shared secret value has to be the same on the Phone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ensure both of these are same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 04:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728810#M393835</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-16T04:43:34Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 CHAP authentication internal user</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728811#M393869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the smartphone sends the authentication request to a router in our provider network. This router is the AAA clients which builds the radius request to the acs server. The shared secret between AAA client (router) and acs is same.&lt;/P&gt;&lt;P&gt;So I don't need a aaa client for the smartphone. Or I am wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Lars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 07:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728811#M393869</guid>
      <dc:creator>Lars Reidelbach</dc:creator>
      <dc:date>2011-06-16T07:15:26Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 CHAP authentication internal user</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728812#M393903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try resetting the password of the user in the ACS and try the login again. Please ensure that you do not enter space in the password wghile typing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check if the option of "Allow chap" is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access policies &amp;gt; Network default access &amp;gt; Allowed protocol &amp;gt; Allow CHAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as&amp;nbsp; answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 01:55:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728812#M393903</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-17T01:55:59Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 CHAP authentication internal user</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728813#M393934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I had reset password and the user has defined a new over the option "Change password on next login". All work fine, acs take the new password. After that we test the authentication again -&amp;gt; Failed Wrong Password&lt;/P&gt;&lt;P&gt;Access Service has Allow Chap enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;Lars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 08:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728813#M393934</guid>
      <dc:creator>Lars Reidelbach</dc:creator>
      <dc:date>2011-06-17T08:22:22Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 CHAP authentication internal user</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728814#M393966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lars,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please open a TAC case. The engineer will help you resolve this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jul 2011 03:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728814#M393966</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-07-03T03:41:04Z</dc:date>
    </item>
    <item>
      <title>hello, I've met the same</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728815#M394005</link>
      <description>&lt;P&gt;hello, I've met the same problem, have you solved it now ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 03:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728815#M394005</guid>
      <dc:creator>xiaodong liao</dc:creator>
      <dc:date>2016-06-29T03:51:50Z</dc:date>
    </item>
    <item>
      <title>We had used EAP-TLS with</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728816#M394045</link>
      <description>&lt;P&gt;We had used EAP-TLS with certificates. This has work than. Now we are using ISE so I can't test again. Sorry.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 07:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728816#M394045</guid>
      <dc:creator>Lars Reidelbach</dc:creator>
      <dc:date>2016-06-29T07:23:51Z</dc:date>
    </item>
    <item>
      <title>Thank for you reply, and I</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728817#M394102</link>
      <description>&lt;P&gt;Thank for you reply, and I wonder that the ISE you use now is use chap or EAP-TLS?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 07:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728817#M394102</guid>
      <dc:creator>xiaodong liao</dc:creator>
      <dc:date>2016-06-29T07:58:56Z</dc:date>
    </item>
    <item>
      <title>We are using now EAP-TLS for</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728818#M394137</link>
      <description>&lt;P&gt;We are using now EAP-TLS for all mobile devices.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 08:01:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/1728818#M394137</guid>
      <dc:creator>Lars Reidelbach</dc:creator>
      <dc:date>2016-06-29T08:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Thank for you reply, and I</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/5132628#M590129</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/327891"&gt;@xiaodong liao&lt;/a&gt;&amp;nbsp;I'm pretty desperate because I have the same problem with AnyConnect client authentication. Have you found a solution?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 14:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-chap-authentication-internal-user/m-p/5132628#M590129</guid>
      <dc:creator>MarcoLazzarotto</dc:creator>
      <dc:date>2024-06-17T14:21:53Z</dc:date>
    </item>
  </channel>
</rss>

