<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Directory + ACS Remote Agent in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126132#M436078</link>
    <description>&lt;P&gt;I have an ACS appliance (3.2). I understand that I need to use an ACS remote agent, preferably installed on a Domain controller, to do Windows authentication. My question is: If I'm using Active Directory, can I not just use External User databases and configure Generic LDAP with appropriate settings to access Active Directory?? Then I wouldn't need a remote agent?? Or do I have to use External User databases and configure Windows Databases (which means using an external remote agent?? Or Can I choose either method?? Its confusing as Active Direcory also cann support pre-2000 windows domains, and i don't know which method of external User Databse mapping to use.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:26:06 GMT</pubDate>
    <dc:creator>rcullum</dc:creator>
    <dc:date>2019-03-10T14:26:06Z</dc:date>
    <item>
      <title>Active Directory + ACS Remote Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126132#M436078</link>
      <description>&lt;P&gt;I have an ACS appliance (3.2). I understand that I need to use an ACS remote agent, preferably installed on a Domain controller, to do Windows authentication. My question is: If I'm using Active Directory, can I not just use External User databases and configure Generic LDAP with appropriate settings to access Active Directory?? Then I wouldn't need a remote agent?? Or do I have to use External User databases and configure Windows Databases (which means using an external remote agent?? Or Can I choose either method?? Its confusing as Active Direcory also cann support pre-2000 windows domains, and i don't know which method of external User Databse mapping to use.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126132#M436078</guid>
      <dc:creator>rcullum</dc:creator>
      <dc:date>2019-03-10T14:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory + ACS Remote Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126133#M436079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With 3.2 you can authenticate directly to a Windows AD database (&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs32/win32sdt.htm#95081" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs32/win32sdt.htm#95081&lt;/A&gt;).  Just use External User Databases - Windows Database and you should be good to go.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2003 05:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126133#M436079</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-08-07T05:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory + ACS Remote Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126134#M436080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But I'm using an ACS 3.2 appliance, which cannot authenticate directly to External User Databases -Windows Databases without the use of the ACS remote agent. So my question still stands. Can I use External User Databases -Generic LDAP mappings to authenticate Active Directory users without the use of the remote agent or do I have to use External User Databases - Windows Database method??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2003 06:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126134#M436080</guid>
      <dc:creator>rcullum</dc:creator>
      <dc:date>2003-08-07T06:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory + ACS Remote Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126135#M436081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My apologies, missed the "appliance" word in your original post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could probably use this either way I would imagine, although we'd suggest using a Remote Agent with the Windows DB.  If you do go down this path make sure of your security permissions (&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/raig/rawi.htm#642394" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/raig/rawi.htm#642394&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've had users use the LDAP database with Windows Ad before and it works fine, the only difference (IIRC)is you don't get all the Windows group mappings with this method, but for just user authentication it should work fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2003 23:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126135#M436081</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-08-07T23:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory + ACS Remote Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126136#M436082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use the LDAP database aren't you unable to use LEAP for authentication?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2003 20:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-acs-remote-agent/m-p/126136#M436082</guid>
      <dc:creator>pallette</dc:creator>
      <dc:date>2003-12-10T20:11:24Z</dc:date>
    </item>
  </channel>
</rss>

