<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS 4.1 to External AD for authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030245#M407079</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if I understand you last issue. Are your talking about password expiry ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rephrase it ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to know things are moving &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 May 2008 14:50:37 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2008-05-13T14:50:37Z</dc:date>
    <item>
      <title>Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030238#M407068</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have just configured Cisco ACS solution engine 4.1 and using a Windows Domain Controller 2003 as a remote agent.we are using tacacs as protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The users which are created in ACS itself are able to login to various network devices. but domain (active directory) users are unable to login. we get access denial message. same time we get External DB is not operational message in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active directory server where agent running, in CSWINAgentlog we get the follwoing error " NDLIB..FOUND 0 TRUSTED DOMAIN" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please help us to isolate the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;amp;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030238#M407068</guid>
      <dc:creator>parthibanp</dc:creator>
      <dc:date>2019-03-10T22:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030239#M407069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure the software ver of acs and remote agent is same. And also account running remote agent should have special domain admin rights, like act as part of operating system and login as service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 May 2008 12:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030239#M407069</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-12T12:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030240#M407072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear JG ..thanks for the great input.as per your response we had found out the software version which was running in Remote Agent was wrong. we have now installed the correct version corresponding to the ACS software version.but now we are still facing problem in active directory user login network devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the error we are receiving the error we are getting in CSWINAgentlog in Active directory server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSWinAgent 05/13/2008 11:47:18 A 0386 3068 RPC: NT_MSCHAPAuthenticateUser received&lt;/P&gt;&lt;P&gt;CSWinAgent 05/13/2008 11:47:18 A 0063 3068 NTLIB: Attempting Windows authentication for user test&lt;/P&gt;&lt;P&gt;CSWinAgent 05/13/2008 11:47:18 A 0063 3068 NTLIB: Windows authentication FAILED (error 6L)&lt;/P&gt;&lt;P&gt;CSWinAgent 05/13/2008 11:47:18 A 0451 3068 RPC: NT_MSCHAPAuthenticateUser reply sent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that we have only one Domain Controller where we have installed Remote Agent.there is no trusted or child domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 07:09:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030240#M407072</guid>
      <dc:creator>parthibanp</dc:creator>
      <dc:date>2008-05-13T07:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030241#M407074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure remote agent service is running using local admin account , since RA is running on DC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check how many processor do we have on that RA system and what is the operating system with SP we have on RA system?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 12:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030241#M407074</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-13T12:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030242#M407075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear JG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your input. it is now resolved the issue.thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following are the main steps we carried out to make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Added ACS hostname in Active Directory server computer field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Enable Netbios in ADS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Made remote agent service is running  using local admin account &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the following issue once we login with Active directoy users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) ADS user when login through SSH after giving the username and password it directly goes to enable mode(not asking the enable password at all)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) ADS user when login through console its not taking the enable password.do we need to modify the aaa configuration in router and ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 12:31:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030242#M407075</guid>
      <dc:creator>parthibanp</dc:creator>
      <dc:date>2008-05-13T12:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030243#M407076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a)The reason it goes directly to enable mode is because we have priv 15 defined for that user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't user to log directly to enable mode then lower the priv lvl for that user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) There must be some misconfiguration. It should also not work via SSH but since we have exec authorization configured it bypassed enable password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On acs in user setup --&amp;gt;Enable Tacacs+  options----&amp;gt; Choose any one ---&amp;gt;Use Cisco PAP pwd, or Use windows pass or use separate pwd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should fix it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark it resolved so other can benefit for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 12:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030243#M407076</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-13T12:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030244#M407077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear DJ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the great help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything is fixed and working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On acs in user setup --&amp;gt;Enable Tacacs+ options----&amp;gt; Choose any one ---&amp;gt;Use Cisco PAP pwd, or Use windows pass or use separate pwd . here if put windows pass  should it be changing the users each login or it would be permanent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;amp;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 14:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030244#M407077</guid>
      <dc:creator>parthibanp</dc:creator>
      <dc:date>2008-05-13T14:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030245#M407079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if I understand you last issue. Are your talking about password expiry ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rephrase it ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to know things are moving &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 14:50:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030245#M407079</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-13T14:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.1 to External AD for authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030246#M407080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear DJ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was talking about the Dynamic users enable password.can we set dynamic users password permanently so that each time when they login we dont need to set password? How long dynamic users login details will be available in the users list in ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We find there is no option in the group belongs to those users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;amp;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2008 04:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-1-to-external-ad-for-authentication/m-p/1030246#M407080</guid>
      <dc:creator>parthibanp</dc:creator>
      <dc:date>2008-05-14T04:16:19Z</dc:date>
    </item>
  </channel>
</rss>

