<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CAA Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217454#M435194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAA is just a method to transfer the messaging (about password aging) from ACS to the client (not related to NAS).&lt;/P&gt;&lt;P&gt;It uses udp port 7500 and it's important the NAS doesn't have any ACLs blocking it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to install CAA on the client , configure password aging rules on the user/group in ACS DB and then when the user reaches the specific rule , a message should pop up on the client alerting the user that its password expires in X days etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Radius is the method ACS talks to the NAS and doesn't have anything to do with CAA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAA is working when NAS is talking Radius to ACS , ofcourse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Nov 2003 20:06:44 GMT</pubDate>
    <dc:creator>aschiebe</dc:creator>
    <dc:date>2003-11-14T20:06:44Z</dc:date>
    <item>
      <title>CAA Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217451#M435191</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to get CiscoSecure Authentication Agent working: Does anyone know whether it can work in my configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 3.2 using Radius&lt;/P&gt;&lt;P&gt;The NAS is a 2611 router (home gateway) running IOS 12.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main reason for CAA is to get ACS's Password Ageing functionality.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;P&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217451#M435191</guid>
      <dc:creator>pvanvuuren</dc:creator>
      <dc:date>2019-03-10T14:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: CAA Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217452#M435192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on the location of your users you may choose CAA/UCP or MSCHAPv2 for Password Aging functionality.&lt;/P&gt;&lt;P&gt;If ACS is authenticating to Active Directory - you need to choose MSCHAPv2.&lt;/P&gt;&lt;P&gt;If ACS is using its internal DB - UCP (User Changeable Password) or CAA (CiscoSecure Authentication Agent) are your choices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAA is described thoroughly in &lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/secureaa/csaa3b.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/secureaa/csaa3b.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Nov 2003 21:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217452#M435192</guid>
      <dc:creator>aschiebe</dc:creator>
      <dc:date>2003-11-12T21:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: CAA Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217453#M435193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, its starting to become a bit clearer to me now. &lt;/P&gt;&lt;P&gt;ACS will not be authenticatin towards AD. We're using the internel ACS user databse. I have tested UCP and it works very well. Even the reporting side of it too. I want to use CAA , but the online documentation is a bit vague. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I use RADIUS with CAA? &lt;/P&gt;&lt;P&gt;And are there anything in regards to config that are important to have.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2003 10:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217453#M435193</guid>
      <dc:creator>pvanvuuren</dc:creator>
      <dc:date>2003-11-14T10:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: CAA Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217454#M435194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAA is just a method to transfer the messaging (about password aging) from ACS to the client (not related to NAS).&lt;/P&gt;&lt;P&gt;It uses udp port 7500 and it's important the NAS doesn't have any ACLs blocking it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to install CAA on the client , configure password aging rules on the user/group in ACS DB and then when the user reaches the specific rule , a message should pop up on the client alerting the user that its password expires in X days etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Radius is the method ACS talks to the NAS and doesn't have anything to do with CAA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAA is working when NAS is talking Radius to ACS , ofcourse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2003 20:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/caa-problem/m-p/217454#M435194</guid>
      <dc:creator>aschiebe</dc:creator>
      <dc:date>2003-11-14T20:06:44Z</dc:date>
    </item>
  </channel>
</rss>

