<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS stripping UPN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726543#M419942</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wanted to let you know that your suggestion was spot on and has resolved my issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Elliott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Jul 2007 12:38:23 GMT</pubDate>
    <dc:creator>elliott.fougman</dc:creator>
    <dc:date>2007-07-26T12:38:23Z</dc:date>
    <item>
      <title>ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726536#M419928</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm hoping that someone has come accross a workaround to an age old issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently using ACS 3.3 (Windows Edition) which passes off password authentication to an Active Directory Domain controller.  This all works as it should do but my Client wants to use the UPN Name to log onto the Network.  The problem is that ACS strips everything after the "@" symbol&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:joe.bloggs@xxx.com" target="_blank"&gt;joe.bloggs@xxx.com&lt;/A&gt; gets passed onto AD as joe.bloggs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any known solution to this issue either from a Cisco or Microsoft perspective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already tried using Microsoft IAS which works perfectly but you lose the logging / security aspects provided by ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Elliott&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726536#M419928</guid>
      <dc:creator>elliott.fougman</dc:creator>
      <dc:date>2019-03-10T22:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726537#M419929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Elliot,&lt;/P&gt;&lt;P&gt;Please check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acs---&amp;gt;External user db---&amp;gt; Database configuration----&amp;gt;Windows---&amp;gt; choose domain ---&amp;gt;configure----&amp;gt;Configure Domain Lists---&amp;gt;Make sure that you domain name is under available domain box&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how that goes !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2007 14:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726537#M419929</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-07-20T14:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726538#M419930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Windows Domains are listed and selected, the problem I am suffering is that the username does is not a direct match for the UPN &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UPN = &lt;A href="mailto:joe.bloggs@mycompany.com"&gt;joe.bloggs@mycompany.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;username = Joeb01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I try logging onto our VPN conecentrator with the User ID Joeb01 then I have no problems.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2007 14:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726538#M419930</guid>
      <dc:creator>elliott.fougman</dc:creator>
      <dc:date>2007-07-20T14:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726539#M419933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Elliott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using peap or TLS ? PEAP does not support domain stripping. The client is the one sending the information to ACS. It really doesn't have anything to do with ACS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2007 15:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726539#M419933</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-07-20T15:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726540#M419934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope, not using any forms of EAP. This is purely PAP / CHAP stuff.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is a section of an ACS manual which explains how ACS deals with certain usernames&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Full URL : &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00802335f3.html#wp353993" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00802335f3.html#wp353993&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UPN Usernames &lt;/P&gt;&lt;P&gt;ACS supports authentication of usernames in UPN format, such as &lt;A href="mailto:cyril.yang@example.com"&gt;cyril.yang@example.com&lt;/A&gt; or cyril.yang@&lt;A href="mailto:central-office@example.com"&gt;central-office@example.com&lt;/A&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the authentication protocol is EAP-TLS, by default, ACS submits the username to Windows in UPN format; however, you can configure ACS to strip from the username all characters after and including the last at symbol (@). For more information, see EAP-TLS Domain Stripping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For all other authentication protocols that it can support with Windows databases, ACS submits the username to Windows that is stripped of all characters after and including the last at symbol (@). This behavior allows for usernames that contain an at symbol (@). For example: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?If the username received is &lt;A href="mailto:cyril.yang@example.com"&gt;cyril.yang@example.com&lt;/A&gt;, ACS submits to Windows an authentication request containing the username cyril.yang. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?If the username received is cyril.yang@&lt;A href="mailto:central-office@example.com"&gt;central-office@example.com&lt;/A&gt;, ACS submits to Windows an authentication request containing the username cyril.yang@central-office. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2007 15:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726540#M419934</guid>
      <dc:creator>elliott.fougman</dc:creator>
      <dc:date>2007-07-20T15:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726541#M419937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How users are connecting ? CHAP is not supported with AD. Please provide your network scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2007 15:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726541#M419937</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-07-20T15:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726542#M419939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you are trying to do would be little difficult, as your SAM and UPN username are different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I would suggest you to give this a try,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From External User Databases &amp;gt; Database Configuration ?.&lt;/P&gt;&lt;P&gt;Create a Generic LDAP instance, with following information,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Directory Subtree : DC=mycompany,DC=com&lt;/P&gt;&lt;P&gt;Group Directory Subtree : DC=mycompany,DC=com&lt;/P&gt;&lt;P&gt;UserObjectType : userPrincipalName&lt;/P&gt;&lt;P&gt;UserObjectClass : person&lt;/P&gt;&lt;P&gt;GroupObjectType : cn&lt;/P&gt;&lt;P&gt;GroupObjectClass : group&lt;/P&gt;&lt;P&gt;Group Attribute Name : member&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hostname : &lt;IP-ADDRESS-DC&gt;&lt;/IP-ADDRESS-DC&gt;&lt;/P&gt;&lt;P&gt;Port : 389&lt;/P&gt;&lt;P&gt;Admin DN : &lt;A href="mailto:Administrator@mycompany.com"&gt;Administrator@mycompany.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Password : &lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leave rest of the information as default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And from External User Database &amp;gt; Unknown User Policy &amp;gt; make sure that your newly created Generic LDAP is at top of windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE : I have taken User Directory Subtree and Group Directory Subtree from the root of the tree, if you have a large tree, then i would prefer to be specific where the users are and where the groups are, rather then searching the whole tree.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Give this a try, it should let users using username as UPN format, to be able to authenticate, and if they use SAM account name, then ACS will look for next database after Generic LDAP, i.e. Windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Jul 2007 18:35:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726542#M419939</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-07-21T18:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS stripping UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726543#M419942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wanted to let you know that your suggestion was spot on and has resolved my issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Elliott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2007 12:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-stripping-upn/m-p/726543#M419942</guid>
      <dc:creator>elliott.fougman</dc:creator>
      <dc:date>2007-07-26T12:38:23Z</dc:date>
    </item>
  </channel>
</rss>

