<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP import to ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398015#M432537</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, ok. But not if I read table 1-3 on this page:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/sw/secursw/ps2086/products_user_guide_chapter09186a00802335f9.html" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/sw/secursw/ps2086/products_user_guide_chapter09186a00802335f9.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you mean that it is only to set it up and then the ACS handle the PAP/CHAP-job?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Mar 2005 06:55:56 GMT</pubDate>
    <dc:creator>walruspro</dc:creator>
    <dc:date>2005-03-11T06:55:56Z</dc:date>
    <item>
      <title>LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398010#M432531</link>
      <description>&lt;P&gt;We use 802.1x with PEAP for all our students and personell over WLAN and wire and it works excellent. However - our central catalouge will be an LDAP-server and since LDAP can't process chap we must get accounts into the ACS 3.3 another way. One way would be to use CSUtils with some pearlscripts but we can't decrypt the passwords that are stored in LDAP... So, anyone have some good ideas about what to do? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;&lt;P&gt;Karlstad Univerity&lt;/P&gt;&lt;P&gt;Sweden&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398010#M432531</guid>
      <dc:creator>walruspro</dc:creator>
      <dc:date>2019-03-10T21:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398011#M432533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One thing that you could do is setup ACS so that all unknown users within ACS get authenticated against the LDAP server.  This process is setup with the "Unknown User" policy within ACS and also telling ACS about the LDAP server.  Here is a link with some more information about setting up ACS in this fashion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/user/d.htm#wp354503" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/user/d.htm#wp354503&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2005 15:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398011#M432533</guid>
      <dc:creator>sstudsdahl</dc:creator>
      <dc:date>2005-03-09T15:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398012#M432534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That would be nice but since we use MS-CHAP, LDAP can't handle that. This is the dilemma... LDAP only supports PAP as far as I understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 07:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398012#M432534</guid>
      <dc:creator>walruspro</dc:creator>
      <dc:date>2005-03-10T07:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398013#M432535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That would be nice but since we use MS-CHAP, LDAP can't handle that. This is the dilemma... LDAP only supports PAP as far as I understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 07:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398013#M432535</guid>
      <dc:creator>walruspro</dc:creator>
      <dc:date>2005-03-10T07:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398014#M432536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS will handle the authentication protocol differences for you.  MS-CHAP authentication will occur to the ACS server and it will use PAP authentication against the LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 16:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398014#M432536</guid>
      <dc:creator>sstudsdahl</dc:creator>
      <dc:date>2005-03-10T16:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398015#M432537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, ok. But not if I read table 1-3 on this page:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/sw/secursw/ps2086/products_user_guide_chapter09186a00802335f9.html" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/sw/secursw/ps2086/products_user_guide_chapter09186a00802335f9.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you mean that it is only to set it up and then the ACS handle the PAP/CHAP-job?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2005 06:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398015#M432537</guid>
      <dc:creator>walruspro</dc:creator>
      <dc:date>2005-03-11T06:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398016#M432538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fredrik,&lt;/P&gt;&lt;P&gt;I stand corrected.  Your interpretation is correct.  Thank you for teaching me something!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now that I have a better understanding of ACS, it looks as if your options are going to be limited.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only option that is coming to mind would be to use a third party supplicant for your authentication.  One that comes to mind is made is Aegis client by Meetinghouse.  Here is a link to the site for more info on it.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.mtghouse.com/products/aegisclient/index.shtml" target="_blank"&gt;http://www.mtghouse.com/products/aegisclient/index.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another one that you might look at is SecureW2.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.securew2.com/uk/" target="_blank"&gt;http://www.securew2.com/uk/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll keep thinking on this one and see what else I can come up with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2005 17:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398016#M432538</guid>
      <dc:creator>sstudsdahl</dc:creator>
      <dc:date>2005-03-11T17:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398017#M432539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are in the same boat here.  Sure would be nice if Cisco came up with a way to make these two work together.  We don't want to have a separate client on our student PCs.   I've talked with Funk as well, same issue Chap vs. PAP.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For copying the LDAP user database over to ACS have you looked at the RDBMS synchronization section?  That may be the direction we go but haven't tested it yet. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2005 22:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398017#M432539</guid>
      <dc:creator>dopenfield</dc:creator>
      <dc:date>2005-03-29T22:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398018#M432540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, the procedure that we have implemented now, until we find something better, is an automated perl-job to import the ldap accounts via CSutils. Not good but it works. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/fred&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Mar 2005 06:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398018#M432540</guid>
      <dc:creator>walruspro</dc:creator>
      <dc:date>2005-03-30T06:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP import to ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398019#M432541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as my knowledge goes the securew2 solution uses EAP-TTLS which isn't supported by ACS.&lt;/P&gt;&lt;P&gt;I'm I right or have I overlooked something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also in freeradius you are able to use PEAP-MSCHAPv2 using LDAP-stored NT-hashes. Anyone tried this on an ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that you really need an MS AD to make this to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anders Nilsson&lt;/P&gt;&lt;P&gt;UMDAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Jun 2005 10:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-import-to-acs/m-p/398019#M432541</guid>
      <dc:creator>anders.nilsson@umu.se</dc:creator>
      <dc:date>2005-06-26T10:52:01Z</dc:date>
    </item>
  </channel>
</rss>

