<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.3 using Windows AD Database in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-3-using-windows-ad-database/m-p/416097#M428343</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just a quick check. Have you point the AD into your 'unknown user policy'? You need to do this in your ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assumed you have already done this:&lt;/P&gt;&lt;P&gt;- set user database in ACS to external database&lt;/P&gt;&lt;P&gt;- join your ACS server to your domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Oct 2005 12:22:07 GMT</pubDate>
    <dc:creator>a.kiprawih</dc:creator>
    <dc:date>2005-10-21T12:22:07Z</dc:date>
    <item>
      <title>ACS 3.3 using Windows AD Database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-using-windows-ad-database/m-p/416095#M428333</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I installed ACS3.3 on windows 2003 standard server and it joins Windows 2000 Active Directory. It works normally when it is using Cisco Secure Database. However, it can't authenticate users located in windows 2000 AD. Is my combination supported by Cisco ACS ? Any additional function I need to configure?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides, I checked with Document that NTLMv2 is not supported in Domain Authentication. NTLM version is determined by the Domain Controller or the Member Server (i.e. The ACS server)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quote:&lt;/P&gt;&lt;P&gt;Verify that the NT LAN Manager (NTLM) version used is version 1. In the applicable Windows security policy editor, access Local Policies &amp;gt; Security Options, and locate the LAN Manager Authentication Level policy and set the policy to Send LM &amp;amp; NTLM responses. Other settings involve the use of NTLM v2, which Cisco Secure ACS does not support. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-using-windows-ad-database/m-p/416095#M428333</guid>
      <dc:creator>rman</dc:creator>
      <dc:date>2019-03-10T21:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 using Windows AD Database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-using-windows-ad-database/m-p/416096#M428338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sup dude,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did you want to authenticate users from AD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it is possible to authenticate users from Active Directory. It just depends on how. You set the Active Directory as a external database. I currently use mine for 802.1x authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding NTLM authentication, the domain controller should dumb down to at least NTLM v1. This depends on the Group Policies defined for your domain. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2005 00:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-using-windows-ad-database/m-p/416096#M428338</guid>
      <dc:creator>Darthkim_2</dc:creator>
      <dc:date>2005-10-19T00:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 using Windows AD Database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-using-windows-ad-database/m-p/416097#M428343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just a quick check. Have you point the AD into your 'unknown user policy'? You need to do this in your ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assumed you have already done this:&lt;/P&gt;&lt;P&gt;- set user database in ACS to external database&lt;/P&gt;&lt;P&gt;- join your ACS server to your domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Oct 2005 12:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-using-windows-ad-database/m-p/416097#M428343</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2005-10-21T12:22:07Z</dc:date>
    </item>
  </channel>
</rss>

