<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Michael, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877345#M40107</link>
    <description>&lt;P&gt;Hello Michael,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes, there is a way to change the password, you will need to define "password-management" under the tunnel group that you created for this connection with the AAA server that will authenticate users, please take into account the following information:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;ACS can be configured to check the users in an AD database&lt;/EM&gt;. Password expiry and change is supported when &lt;STRONG&gt;Microsoft Challenge Handshake Authentication Protocol version 2 (MSCHAPv2)&lt;/STRONG&gt; is used;&lt;/P&gt;
&lt;P&gt;On an ASA, you can use the &lt;STRONG&gt;password management feature&lt;/STRONG&gt;, as described in the next section, in order to force the &lt;STRONG&gt;ASA&lt;/STRONG&gt; to use &lt;STRONG&gt;MSCHAPv2&lt;/STRONG&gt;. ACS uses the Common Internet File System &lt;STRONG&gt;(CIFS)&lt;/STRONG&gt; Distributed Computing Environment/Remote Procedure Call (DCE/RPC) call when it contacts the Domain Controller (DC) directory in order to change the password.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA can use both the &lt;STRONG&gt;RADIUS&lt;/STRONG&gt; and &lt;STRONG&gt;TACACS+&lt;/STRONG&gt; protocols in order to contact with the ACS for an AD password change, the command:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA(config)# tunnel-group general-attributes&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;&lt;STRONG&gt;ASA(config-tunnel-general)# password-management&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For further information, on PAP and MSCHAP along with radius, you may find it here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;http://www.cisco.com/c/en/us/support/docs/network-management/remote-access/116757-config-asa-remote-00.pdf&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please proceed to rate this post and the previous one and mark it as correct, keep me posted if something comes up!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;David Castro,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2016 18:10:36 GMT</pubDate>
    <dc:creator>David Castro F.</dc:creator>
    <dc:date>2016-03-07T18:10:36Z</dc:date>
    <item>
      <title>ACS Password Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877342#M40104</link>
      <description>&lt;P&gt;My company would like to replace the existing LDAP servers with Cisco ACS. &amp;nbsp;One requirement of our VPN security policy is that the user must change their VPN account password prior to their first log in. &amp;nbsp;If the user tries to connect to the VPN without changing their password, then they are denied access.&lt;/P&gt;
&lt;P&gt;Is there a rule in ACS that&amp;nbsp;can achieve this goal?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877342#M40104</guid>
      <dc:creator>michaelhorv11</dc:creator>
      <dc:date>2019-03-11T06:32:44Z</dc:date>
    </item>
    <item>
      <title>Hi Michael,</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877343#M40105</link>
      <description>&lt;P&gt;Hi Michael,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can&amp;nbsp;reset the password this way:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;H3 class="p_H_Head2"&gt;Resetting Another Administrator’s Password&lt;/H3&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1075966"&gt;&lt;/A&gt;To reset another administrator’s password:&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;*Step 1&lt;/B&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="5" height="2" border="0" /&gt; Choose System Administration &amp;gt; Administrators &amp;gt; Accounts.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;The Accounts page appears with a list of administrator accounts.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;*Step 2&lt;/B&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="5" height="2" border="0" /&gt; Check the check box next to the administrator account for which you want to change the password and click &lt;B class="cBold"&gt;Change Password&lt;/B&gt;.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;The Authentication Information page appears, listing the date when the administrator’s password was last changed.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;*Step 3&lt;/B&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="5" height="2" border="0" /&gt; In the Password field, enter a new administrator password.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;*Step 4&lt;/B&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="5" height="2" border="0" /&gt; In the Confirm Password field, re-enter the new administrator password.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;*Step 5&lt;/B&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="5" height="2" border="0" /&gt; Check the &lt;B class="cBold"&gt;Change password on next login&lt;/B&gt; check box for the other administrator to change password at first login.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;*Step 6&lt;/B&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="5" height="2" border="0" /&gt; Click Submit.&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;The administrator password is reset.&amp;nbsp;&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;¿Which Type of Remote Access VPN are you using Anyconnect or VPN client IPsec?&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;Please rate and mark as correct the this post if it helped you! Keep me posted&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;&lt;/P&gt;
&lt;P class="pSF_StepFirst"&gt;David Castro,&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 23:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877343#M40105</guid>
      <dc:creator>David Castro F.</dc:creator>
      <dc:date>2016-03-04T23:31:42Z</dc:date>
    </item>
    <item>
      <title>I appreciate your response.</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877344#M40106</link>
      <description>&lt;P&gt;I appreciate your response. &amp;nbsp;The users will be connecting to the VPN via AnyConnect. For the AnyConnect users, is there an option to force them to change their password upon first login? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 15:41:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877344#M40106</guid>
      <dc:creator>michaelhorv11</dc:creator>
      <dc:date>2016-03-07T15:41:47Z</dc:date>
    </item>
    <item>
      <title>Hello Michael,</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877345#M40107</link>
      <description>&lt;P&gt;Hello Michael,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes, there is a way to change the password, you will need to define "password-management" under the tunnel group that you created for this connection with the AAA server that will authenticate users, please take into account the following information:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;ACS can be configured to check the users in an AD database&lt;/EM&gt;. Password expiry and change is supported when &lt;STRONG&gt;Microsoft Challenge Handshake Authentication Protocol version 2 (MSCHAPv2)&lt;/STRONG&gt; is used;&lt;/P&gt;
&lt;P&gt;On an ASA, you can use the &lt;STRONG&gt;password management feature&lt;/STRONG&gt;, as described in the next section, in order to force the &lt;STRONG&gt;ASA&lt;/STRONG&gt; to use &lt;STRONG&gt;MSCHAPv2&lt;/STRONG&gt;. ACS uses the Common Internet File System &lt;STRONG&gt;(CIFS)&lt;/STRONG&gt; Distributed Computing Environment/Remote Procedure Call (DCE/RPC) call when it contacts the Domain Controller (DC) directory in order to change the password.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA can use both the &lt;STRONG&gt;RADIUS&lt;/STRONG&gt; and &lt;STRONG&gt;TACACS+&lt;/STRONG&gt; protocols in order to contact with the ACS for an AD password change, the command:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA(config)# tunnel-group general-attributes&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;&lt;STRONG&gt;ASA(config-tunnel-general)# password-management&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For further information, on PAP and MSCHAP along with radius, you may find it here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;http://www.cisco.com/c/en/us/support/docs/network-management/remote-access/116757-config-asa-remote-00.pdf&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please proceed to rate this post and the previous one and mark it as correct, keep me posted if something comes up!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;David Castro,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 18:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-password-policy/m-p/2877345#M40107</guid>
      <dc:creator>David Castro F.</dc:creator>
      <dc:date>2016-03-07T18:10:36Z</dc:date>
    </item>
  </channel>
</rss>

