<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-0/m-p/559413#M427124</link>
    <description>&lt;P&gt;I try to establish a link to an external database by LDAP SSL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put all information in the common LDAP configuration, I set the port to 636, Checkmark are on LDAPv3 and Use SecureAuthentification&lt;/P&gt;&lt;P&gt;I put the path of my .db file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when I try to map ACS group to LDAP group, I've got an error the LDAP cannot be reach.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I sniff all packet on my ACS 4.0 server and nothing seems to be pass with the port 389 or 636&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I keep the 636 port on and uncheck the Use SecureAuthentification, I sniff my network and now I see all the packet try to contact my LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what I do wrong? Someone try this and work fine?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:36:33 GMT</pubDate>
    <dc:creator>guillaume.chartrand</dc:creator>
    <dc:date>2019-03-10T21:36:33Z</dc:date>
    <item>
      <title>ACS 4.0</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-0/m-p/559413#M427124</link>
      <description>&lt;P&gt;I try to establish a link to an external database by LDAP SSL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put all information in the common LDAP configuration, I set the port to 636, Checkmark are on LDAPv3 and Use SecureAuthentification&lt;/P&gt;&lt;P&gt;I put the path of my .db file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when I try to map ACS group to LDAP group, I've got an error the LDAP cannot be reach.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I sniff all packet on my ACS 4.0 server and nothing seems to be pass with the port 389 or 636&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I keep the 636 port on and uncheck the Use SecureAuthentification, I sniff my network and now I see all the packet try to contact my LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what I do wrong? Someone try this and work fine?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-0/m-p/559413#M427124</guid>
      <dc:creator>guillaume.chartrand</dc:creator>
      <dc:date>2019-03-10T21:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.0</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-0/m-p/559414#M427126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LDAP uses the port 389 and LDAPS uses 636. Make sure your LDAP server is listening to the correct port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you are using SSL, also make sure that the SSL port (TCP/443) is not blocked by any device in between.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jun 2006 15:55:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-0/m-p/559414#M427126</guid>
      <dc:creator>thomas.chen</dc:creator>
      <dc:date>2006-06-05T15:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.0</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-0/m-p/559415#M427130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes my LDAP server listen the port 636 or 443 and also 389.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I try to put any Trusted Root CA, when I capture my packet, I see something on port 636. But if I put a cert7.db on the local Path of my ACS server, it send anything, like if he can't read my cert7.db.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another question, the .db file is it the only extension that the server can read. Because when I export my certificate from Console One in Novell 6.5, I have only two choice, a .per file or .b64&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what can I do to transform this file in a .db file.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jun 2006 18:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-0/m-p/559415#M427130</guid>
      <dc:creator>guillaume.chartrand</dc:creator>
      <dc:date>2006-06-05T18:41:50Z</dc:date>
    </item>
  </channel>
</rss>

