<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius and AD issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740336#M420551</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You only need to configure following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Make sure that you have a Remote Agent installed so that your ACS appliance can talk to AD. Beware, Remote Agent version should be exactly the same, as the version of ACS software that you have on your appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Then you need to configure Group mapping, if you need users discovered from AD to map to a particular group on ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Else, if you don't, all the AD users will be mapped to Default Group on ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Configure the group the way you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Useful links:&lt;/P&gt;&lt;P&gt;Installation/configuration instructions for Remote Agent(they come in 2 flavors, Solaris, Windows):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/csapp41/rase41/index.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/csapp41/rase41/index.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows Database:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/usrdb.htm#wp353636" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/usrdb.htm#wp353636&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group Mapping:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/grpmap.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/grpmap.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Jun 2007 11:53:42 GMT</pubDate>
    <dc:creator>Premdeep Banga</dc:creator>
    <dc:date>2007-06-04T11:53:42Z</dc:date>
    <item>
      <title>Radius and AD issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740334#M420549</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The scenario as following, I have ASA, ACS appliance v4.1 and Active directory, all the users credentials located on AD and I?m willing to configure the ACS (radius) to manage and restrict the access to internet, I did it successfully in case the credentials created on the ACS's local database but practically all my users accounts created on the AD and I need to find away to group the users on ACS and keep the accounts on AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740334#M420549</guid>
      <dc:creator>balsheikh</dc:creator>
      <dc:date>2019-03-10T22:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Radius and AD issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740335#M420550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes is possible. You have your active directory groups map to ACS groups. You'll need to migrate all of your permissions to the group level since user permissions override group settings. You'll also need to (IMHO) migrate your local users from static on the server to dynamic populated from Active Directory.  Be aware that the order in which your groups are listed in ACS matters in AAA, the first match a rule hits is the one it uses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2007 10:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740335#M420550</guid>
      <dc:creator>akemp</dc:creator>
      <dc:date>2007-06-04T10:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Radius and AD issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740336#M420551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You only need to configure following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Make sure that you have a Remote Agent installed so that your ACS appliance can talk to AD. Beware, Remote Agent version should be exactly the same, as the version of ACS software that you have on your appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Then you need to configure Group mapping, if you need users discovered from AD to map to a particular group on ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Else, if you don't, all the AD users will be mapped to Default Group on ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Configure the group the way you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Useful links:&lt;/P&gt;&lt;P&gt;Installation/configuration instructions for Remote Agent(they come in 2 flavors, Solaris, Windows):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/csapp41/rase41/index.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/csapp41/rase41/index.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows Database:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/usrdb.htm#wp353636" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/usrdb.htm#wp353636&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group Mapping:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/grpmap.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/grpmap.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2007 11:53:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740336#M420551</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-04T11:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Radius and AD issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740337#M420552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Prem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thx for your support, I wasted time trying to configure group mapping using LDAP but I found it wasn't supported. I used the windows DB with remote agent and task acomplished successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Belal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jun 2007 13:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-and-ad-issue/m-p/740337#M420552</guid>
      <dc:creator>balsheikh</dc:creator>
      <dc:date>2007-06-09T13:58:08Z</dc:date>
    </item>
  </channel>
</rss>

