<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 3.1 Windows 2000 Domain Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-1-windows-2000-domain-problem/m-p/291194#M431766</link>
    <description>&lt;P&gt;Dear &lt;/P&gt;&lt;P&gt;I have ACS 3.1 for W2k. I install the program in W2k Advance Server and config it to get Authentication from Active Directory. The authentications is work in case of exec but in case of remote logging through Cisco Access Server get error (CS user unknown) and cannot log using the W2k AD Users.&lt;/P&gt;&lt;P&gt;What recommendations for this error?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 20:43:41 GMT</pubDate>
    <dc:creator>aymandcp</dc:creator>
    <dc:date>2019-03-10T20:43:41Z</dc:date>
    <item>
      <title>ACS 3.1 Windows 2000 Domain Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-1-windows-2000-domain-problem/m-p/291194#M431766</link>
      <description>&lt;P&gt;Dear &lt;/P&gt;&lt;P&gt;I have ACS 3.1 for W2k. I install the program in W2k Advance Server and config it to get Authentication from Active Directory. The authentications is work in case of exec but in case of remote logging through Cisco Access Server get error (CS user unknown) and cannot log using the W2k AD Users.&lt;/P&gt;&lt;P&gt;What recommendations for this error?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-1-windows-2000-domain-problem/m-p/291194#M431766</guid>
      <dc:creator>aymandcp</dc:creator>
      <dc:date>2019-03-10T20:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.1 Windows 2000 Domain Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-1-windows-2000-domain-problem/m-p/291195#M431767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the debug  ppp authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2d03h: %LINK-3-UPDOWN: Interface Serial0:12, changed state to down&lt;/P&gt;&lt;P&gt;2d03h: %LINK-3-UPDOWN: Interface Async7, changed state to up&lt;/P&gt;&lt;P&gt;2d03h: As7 PPP: Treating connection as a dedicated line&lt;/P&gt;&lt;P&gt;2d03h: As7 PPP: Phase is AUTHENTICATING, by this end&lt;/P&gt;&lt;P&gt;2d03h: As7 CHAP: O CHALLENGE id 3 len 26 from "RAS"&lt;/P&gt;&lt;P&gt;2d03h: As7 CHAP: I RESPONSE id 3 len 30 from "test"&lt;/P&gt;&lt;P&gt;2d03h: As7 CHAP: Unable to validate Response.  Username test: Authenticatio&lt;/P&gt;&lt;P&gt;n failure&lt;/P&gt;&lt;P&gt;2d03h: As7 CHAP: O FAILURE id 3 len 26 msg is "Authentication failure"&lt;/P&gt;&lt;P&gt;2d03h: %LINK-3-UPDOWN: Interface Serial0:10, changed state to down&lt;/P&gt;&lt;P&gt;2d03h: %LINK-5-CHANGED: Interface Async7, changed state to reset&lt;/P&gt;&lt;P&gt;2d03h: %LINK-3-UPDOWN: Interface Async7, changed state to down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the error in ACS log mesg is "CS CHAP password invalid"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Mar 2004 10:58:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-1-windows-2000-domain-problem/m-p/291195#M431767</guid>
      <dc:creator>aymandcp</dc:creator>
      <dc:date>2004-03-20T10:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.1 Windows 2000 Domain Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-1-windows-2000-domain-problem/m-p/291196#M431768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More Info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recently installed ACS v3.1. I can successfully authenticate users using chap, but when I add the aaa authentication ppp default group tacacs+ command to my Cisco (AS5300) (authen'ing using my W2K AD) and debug it says that authentication fails. I am running IOS 12.0(3)T1. It will however, successfully authenticate me when logging into a AAA client using the aaa authentication login default group tacacs+ local command, so it appears that the authentication process is working. Any suggestions on how to authenticate my dialup users(via ACS/AD Database)? Everything appears to be configured right on the router. My guess is something in ACS is not configured properly to pass the the authen. from the ACS to the NT Database(DC) for the dialup users. Any suggestions would be appreciated. &lt;/P&gt;&lt;P&gt;The ACS log error is (CS CHAP password invalid )&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Mar 2004 07:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-1-windows-2000-domain-problem/m-p/291196#M431768</guid>
      <dc:creator>aymandcp</dc:creator>
      <dc:date>2004-03-21T07:52:25Z</dc:date>
    </item>
  </channel>
</rss>

