<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS authentication to Win2K in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17013#M438639</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a similar issue with 3.0 and 3.1.  I resolved this by disabling the "require kerberos pre-authentication" option under the user setup. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Jan 2003 14:54:18 GMT</pubDate>
    <dc:creator>grshaw</dc:creator>
    <dc:date>2003-01-24T14:54:18Z</dc:date>
    <item>
      <title>ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17001#M438627</link>
      <description>&lt;P&gt;Does the ACS services actually need to use the domain administrator account or an account with admin privliges?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can get ACS to authenticate with the local user database on the member server but can't seem to get it to authenticate to the domain.  Using a user form the ACS database works fine as well.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:03:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17001#M438627</guid>
      <dc:creator>anthony.cogswell</dc:creator>
      <dc:date>2019-03-10T14:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17002#M438628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anthony&lt;/P&gt;&lt;P&gt;It seems that we have the same problem. I don't have a solution till now. But please have a look at the csauth log file. You find the csauth log file under x:\Program Files\CiscoSecure ACS v3.0\CSAuth\Logs. I have there some logs like:&lt;/P&gt;&lt;P&gt;*******************************************************************************&lt;/P&gt;&lt;P&gt;AUTH 06/04/2002 11:08:12 E 0266 1688 External DB [NTAuthenDLL.dll]: RasAdminUserGetInfo returned error 0x5&lt;/P&gt;&lt;P&gt;AUTH 06/04/2002 11:08:12 E 0266 1688 External DB [NTAuthenDLL.dll]: Failed to get RAS information for user giadmu&lt;/P&gt;&lt;P&gt;*******************************************************************************&lt;/P&gt;&lt;P&gt;Do you have this logs also?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2002 10:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17002#M438628</guid>
      <dc:creator>giadmu</dc:creator>
      <dc:date>2002-06-04T10:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17003#M438629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually I went through my logs and found this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*****************************************************************************&lt;/P&gt;&lt;P&gt;AUTH 06/03/2002 13:11:51 I 0266 2012 External DB [NTAuthenDLL.dll]: Starting authentication for user [anthonyc]&lt;/P&gt;&lt;P&gt;AUTH 06/03/2002 13:11:51 I 0266 2012 External DB [NTAuthenDLL.dll]: Attempting NT/2000 authentication&lt;/P&gt;&lt;P&gt;AUTH 06/03/2002 13:11:51 I 0266 2012 External DB [NTAuthenDLL.dll]: NT/2000 authentication SUCCESSFUL (by GNBDC02)&lt;/P&gt;&lt;P&gt;AUTH 06/03/2002 13:11:51 I 0266 2012 External DB [NTAuthenDLL.dll]: Obtaining RAS information for user anthonyc from GNBDC02&lt;/P&gt;&lt;P&gt;AUTH 06/03/2002 13:11:51 E 0266 2012 External DB [NTAuthenDLL.dll]: RasAdminUserGetInfo returned error 0x5&lt;/P&gt;&lt;P&gt;AUTH 06/03/2002 13:11:51 E 0266 2012 External DB [NTAuthenDLL.dll]: Failed to get RAS information for user anthonyc from GNBDC02&lt;/P&gt;&lt;P&gt;AUTH 06/03/2002 13:11:51 I 1311 2012 Unknown User 'anthonyc' was not authenticated&lt;/P&gt;&lt;P&gt;*******************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my userid is getting authenticated but can't get the RAS info.  My account is setup for dial-in.  Not sure what is going on but at least this helps.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2002 10:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17003#M438629</guid>
      <dc:creator>anthony.cogswell</dc:creator>
      <dc:date>2002-06-04T10:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17004#M438630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So - We have the same error. I have still open a TAC Case (C730737) about this problem. I will send you the whole Case content. Perhaps it will help you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem Description: Situation:&lt;/P&gt;&lt;P&gt;We have a ACS Server to authenticate the RAS Users.&lt;/P&gt;&lt;P&gt;I configured the ACS to authenticate unknown users by the 'Windows NT/2000' Database (Unknown User Policy). The ACS is a member server in a Windows 2000 Domain called 'giaintra.net'. The Users are in a Windows NT Domain called 'MM'. There is a two way trust between this domains.&lt;/P&gt;&lt;P&gt;I configured the 'Windows NT/2000 User Database' in the ACS to verify the 'Grant dialin permission' setting and also configure the Domain List with all needed domains (MM, giaintra.net).&lt;/P&gt;&lt;P&gt;Problem:&lt;/P&gt;&lt;P&gt;The authentication allways fails for user that are not in the ACS database. In the 'Failed Attempts' Log the Authentication Failure Code is 'Unknown'&lt;/P&gt;&lt;P&gt;investigations:&lt;/P&gt;&lt;P&gt;I capture the network traffic from and to the ACS Server and see, that there is no traffic to any Domaincontroller. So I turn the ACS logging to the maximum and check the csauth service log file for any debug messages beginning with [External DB]. The following messages were logged:&lt;/P&gt;&lt;P&gt;****************************************************************&lt;/P&gt;&lt;P&gt;AUTH 05/23/2002 15:56:30 I 4562 1676 Attempting authentication for Unknown User 'MM\giadmu'&lt;/P&gt;&lt;P&gt;AUTH 05/23/2002 15:56:30 I 0266 1676 External DB [NTAuthenDLL.dll]: Starting authentication for user [MM\giadmu]&lt;/P&gt;&lt;P&gt;AUTH 05/23/2002 15:56:30 I 0266 1676 External DB [NTAuthenDLL.dll]: Attempting NT/2000 authentication&lt;/P&gt;&lt;P&gt;AUTH 05/23/2002 15:56:30 E 0266 1676 External DB [NTAuthenDLL.dll]: NT/2000 authentication FAILED (error 1300L)&lt;/P&gt;&lt;P&gt;AUTH 05/23/2002 15:56:30 I 1311 1676 Unknown User 'MM\giadmu' was not authenticated&lt;/P&gt;&lt;P&gt;****************************************************************&lt;/P&gt;&lt;P&gt;Please contact customer via email: &lt;A href="mailto:daniel.mueller@gia.ch"&gt;daniel.mueller@gia.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Email: &lt;A href="mailto:daniel.mueller@gia.ch"&gt;daniel.mueller@gia.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Phone: 41-62-789-71-71&lt;/P&gt;&lt;P&gt;Urls shown to the user :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/cc/pd/sqsw/sq/prodlit/exatu_wp.htm" target="_blank"&gt;http://www.cisco.com/warp/public/cc/pd/sqsw/sq/prodlit/exatu_wp.htm&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt26/usergd26/userdb.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt26/usergd26/userdb.htm&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt26/usergd26/unknown.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt26/usergd26/unknown.htm&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/cc/pd/sqsw/sq/prodlit/ldcsa_wp.htm" target="_blank"&gt;http://www.cisco.com/warp/public/cc/pd/sqsw/sq/prodlit/ldcsa_wp.htm&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/customer/480/csntsdi.html" target="_blank"&gt;http://www.cisco.com/warp/customer/480/csntsdi.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** NOTES LOG 23-MAY-2002 07:58:54 PST, ciscodotcom, Action Type: Action *** &lt;/P&gt;&lt;P&gt;Notes logged DANIEL MUELLER (giadmu) &lt;A href="mailto:daniel.mueller@gia.ch"&gt;daniel.mueller@gia.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;CC list updated by DANIEL MUELLER (giadmu) &lt;A href="mailto:daniel.mueller@gia.ch"&gt;daniel.mueller@gia.ch&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;OLD: &lt;/P&gt;&lt;P&gt;NEW: &lt;A href="mailto:giaaaj@gia.ch"&gt;giaaaj@gia.ch&lt;/A&gt;, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** EMAIL OUT 23-MAY-2002 08:25:03 PST, kpintus, Action Type: Email Out *** &lt;/P&gt;&lt;P&gt;Send to: [&lt;A href="mailto:daniel.mueller@gia.ch"&gt;daniel.mueller@gia.ch&lt;/A&gt;]&lt;/P&gt;&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;Good afternoon. My name is Kirk with Cisco Systems and I will be assisting you with this case.&lt;/P&gt;&lt;P&gt;It sounds to me like the problem is that ACS is installed on a Member Server. If this was installed on a Domain Controller you probably wouldnt have this issue. If you follow the instructions below, it should fix the problem. The 1300L error you are getting is defined here:&lt;/P&gt;&lt;P&gt;Code Name Description -------1300L ERROR_NOT_ALL_ASSIGNED&lt;/P&gt;&lt;P&gt;Indicates not all privileges referenced are assigned to the caller. This allows, for example, all privileges to be disabled without having to know exactly which privileges are assigned. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://support.microsoft.com/default.aspx?scid=kb;en-us;Q155012" target="_blank"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;Q155012&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Try these instructions below and let me know how that goes and if I can be of further assistance.&lt;/P&gt;&lt;P&gt;*****************************************************************************&lt;/P&gt;&lt;P&gt;First ensure that any trusts that will be followed are 2-way.&lt;/P&gt;&lt;P&gt;One-way trusts are problematic for ACS.&lt;/P&gt;&lt;P&gt;- On the domain controller serving the ACS server:&lt;/P&gt;&lt;P&gt;-- Create a user&lt;/P&gt;&lt;P&gt;-- Make the user a member of Domain Admins group.&lt;/P&gt;&lt;P&gt;-- Make the user a member of Administrators group.&lt;/P&gt;&lt;P&gt;- Log onto ACS server.&lt;/P&gt;&lt;P&gt;-- Add the domain user to the local Administrators group.&lt;/P&gt;&lt;P&gt;-- Assign special rights with following instructions:&lt;/P&gt;&lt;P&gt;-- If ACS server is NT:&lt;/P&gt;&lt;P&gt;--- Run the User Manager program.&lt;/P&gt;&lt;P&gt;--- Choose "User Rights" from the "Policies" menu.&lt;/P&gt;&lt;P&gt;--- Check "Show Advanced User Rights."&lt;/P&gt;&lt;P&gt;--- Find "Act as part of the operating system" in the list.&lt;/P&gt;&lt;P&gt;--- Click "Add."&lt;/P&gt;&lt;P&gt;--- Choose the domain from the "List Names From" box.&lt;/P&gt;&lt;P&gt;--- Click "Show Users."&lt;/P&gt;&lt;P&gt;--- Double-click the user created earlier to add it.&lt;/P&gt;&lt;P&gt;--- Click OK.&lt;/P&gt;&lt;P&gt;--- Find "Log on as a Service" in the list.&lt;/P&gt;&lt;P&gt;--- Click "Add."&lt;/P&gt;&lt;P&gt;--- Choose the domain from the "List Names From" box.&lt;/P&gt;&lt;P&gt;--- Click "Show Users."&lt;/P&gt;&lt;P&gt;--- Double-click the user created earlier to add it.&lt;/P&gt;&lt;P&gt;--- Click OK.&lt;/P&gt;&lt;P&gt;-- If ACS server is Windows 2000:&lt;/P&gt;&lt;P&gt;--- Open "Administrative Tools" from the control panel.&lt;/P&gt;&lt;P&gt;--- Open "Local Security Policy."&lt;/P&gt;&lt;P&gt;--- Open "Local Policies."&lt;/P&gt;&lt;P&gt;--- Open "User Rights Assignment."&lt;/P&gt;&lt;P&gt;--- Double-click on "Act as part of the operating system."&lt;/P&gt;&lt;P&gt;--- Click "Add."&lt;/P&gt;&lt;P&gt;--- Choose the domain from the "Look in" box.&lt;/P&gt;&lt;P&gt;--- Double-click the user created earlier to add it.&lt;/P&gt;&lt;P&gt;--- Click OK.&lt;/P&gt;&lt;P&gt;--- Double-click on "Log on as a service."&lt;/P&gt;&lt;P&gt;--- Click "Add."&lt;/P&gt;&lt;P&gt;--- Choose the domain from the "Look in" box.&lt;/P&gt;&lt;P&gt;--- Double-click the user created earlier to add it.&lt;/P&gt;&lt;P&gt;--- Click OK.&lt;/P&gt;&lt;P&gt;- Set the ACS services to run as the created user.&lt;/P&gt;&lt;P&gt;-- If ACS server is NT:&lt;/P&gt;&lt;P&gt;--- Open "Services" from the control panel.&lt;/P&gt;&lt;P&gt;--- Click the CSADMIN entry once.&lt;/P&gt;&lt;P&gt;--- Click "Startup."&lt;/P&gt;&lt;P&gt;--- Click "This Account" and then the "..." button.&lt;/P&gt;&lt;P&gt;--- Choose the domain, double-click the user created earlier.&lt;/P&gt;&lt;P&gt;--- Click "Add," then "OK," then "OK" again.&lt;/P&gt;&lt;P&gt;--- Repeat for the rest of the CS services.&lt;/P&gt;&lt;P&gt;--- Stop and then start CSADMIN.&lt;/P&gt;&lt;P&gt;-- If ACS server is Windows 2000:&lt;/P&gt;&lt;P&gt;--- Open "Services" from "Administrative Tools."&lt;/P&gt;&lt;P&gt;--- Double-click the CSADMIN entry.&lt;/P&gt;&lt;P&gt;--- Click the "Log On" tab.&lt;/P&gt;&lt;P&gt;--- Click "This Account" and then the "Browse" button.&lt;/P&gt;&lt;P&gt;--- Choose the domain, double-click the user created earlier.&lt;/P&gt;&lt;P&gt;--- Click "OK."&lt;/P&gt;&lt;P&gt;--- Repeat for the rest of the CS services.&lt;/P&gt;&lt;P&gt;--- Stop and then start CSADMIN.&lt;/P&gt;&lt;P&gt;- Open the ACS GUI.&lt;/P&gt;&lt;P&gt;- Click on System Config.&lt;/P&gt;&lt;P&gt;- Click on Service Control.&lt;/P&gt;&lt;P&gt;- Click "Restart."&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kirk Pintus&lt;/P&gt;&lt;P&gt;Tech Support&lt;/P&gt;&lt;P&gt;SLC TAC-Security&lt;/P&gt;&lt;P&gt;Cisco Systems Inc. &lt;/P&gt;&lt;P&gt;M-F 7-3:00pm MST&lt;/P&gt;&lt;P&gt;801-736-3939 x55455&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:kpintus@cisco.com"&gt;kpintus@cisco.com&lt;/A&gt; &lt;&gt;&lt;A href="mailto:kpintus@cisco.com"&gt;kpintus@cisco.com&lt;/A&gt;&amp;gt;&lt;/&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** STATUS CHANGE 23-MAY-2002 08:25:03 PST, kpintus, Action Type: *** &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** NOTES LOG 24-MAY-2002 10:09:18 PST, kpintus, Action Type: Action *** &lt;/P&gt;&lt;P&gt;email from customer:&lt;/P&gt;&lt;P&gt;Hi Kirk&lt;/P&gt;&lt;P&gt;I implemented the task you described below and now I can logon with the&lt;/P&gt;&lt;P&gt;accounts from the Domain 'MM'. But I still can't logon with a account in the&lt;/P&gt;&lt;P&gt;Domain 'giaintra.net'. The debug messages in the csauth Logfile is:&lt;/P&gt;&lt;P&gt;**************************************&lt;/P&gt;&lt;P&gt;AUTH 05/24/2002 09:19:59 I 4562 1684 Attempting authentication for Unknown&lt;/P&gt;&lt;P&gt;User 'GIAINTRA.NET\giadmu'&lt;/P&gt;&lt;P&gt;AUTH 05/24/2002 09:19:59 I 0266 1684 External DB [NTAuthenDLL.dll]: Starting&lt;/P&gt;&lt;P&gt;authentication for user [GIAINTRA.NET\giadmu]&lt;/P&gt;&lt;P&gt;AUTH 05/24/2002 09:19:59 I 0266 1684 External DB [NTAuthenDLL.dll]:&lt;/P&gt;&lt;P&gt;Attempting NT/2000 authentication&lt;/P&gt;&lt;P&gt;AUTH 05/24/2002 09:19:59 I 0266 1684 External DB [NTAuthenDLL.dll]: NT/2000&lt;/P&gt;&lt;P&gt;authentication SUCCESSFUL (by GIAT056)&lt;/P&gt;&lt;P&gt;AUTH 05/24/2002 09:19:59 E 0266 1684 External DB [NTAuthenDLL.dll]: Local&lt;/P&gt;&lt;P&gt;account domain fallback not permitted&lt;/P&gt;&lt;P&gt;AUTH 05/24/2002 09:19:59 I 1311 1684 Unknown User 'GIAINTRA.NET\giadmu' was&lt;/P&gt;&lt;P&gt;not authenticated&lt;/P&gt;&lt;P&gt;**************************************&lt;/P&gt;&lt;P&gt;Do you have any idea about that?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** STATUS CHANGE 24-MAY-2002 10:09:19 PST, kpintus, Action Type: *** &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** EMAIL OUT 24-MAY-2002 10:35:19 PST, kpintus, Action Type: Email Out *** &lt;/P&gt;&lt;P&gt;Send to: [&lt;A href="mailto:daniel.mueller@gia.ch"&gt;daniel.mueller@gia.ch&lt;/A&gt;]&lt;/P&gt;&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;From the debugs it looks possibily like a permission issue. Which domain did you create the user on from the instructions before? You will need to create the user on the domain the ACS box is in. If that does not work for you, maybe try turning on security auditing/failure auditing for everything on the domain controller and send me the results from that.&lt;/P&gt;&lt;P&gt;Lets try that and see what happens. I will go over this with the team lead as well, and see what he thinks about this issue.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Kirk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** NOTES LOG 28-MAY-2002 08:46:30 PST, kpintus, Action Type: Action *** &lt;/P&gt;&lt;P&gt;Hi Kirk&lt;/P&gt;&lt;P&gt;The user accounts were migrated from the 'MM' domain (Win NT) to the&lt;/P&gt;&lt;P&gt;'giaintra.net' domain (Win2000). To test the functionality of the acs I have&lt;/P&gt;&lt;P&gt;two user accounts:&lt;/P&gt;&lt;P&gt;- 'giadmu' in the Win NT domain MM&lt;/P&gt;&lt;P&gt;- 'giadmu' in the new Win2000 Domain ' giaintra.net' (this is the migrated&lt;/P&gt;&lt;P&gt;user from the MM Domain)&lt;/P&gt;&lt;P&gt;The acs is a windows 2000 member server in the 'giaintra.net' domain. I can&lt;/P&gt;&lt;P&gt;not install the acs on a domaincontroller, because of our internal security&lt;/P&gt;&lt;P&gt;regulations.&lt;/P&gt;&lt;P&gt;For the user account in the MM Domain all works properly after I implemented&lt;/P&gt;&lt;P&gt;your instructions. But for the user account in the 'giaintra.net' domain the&lt;/P&gt;&lt;P&gt;authentication still fails. First I try to logon with 'giaintra.net\giadmu'&lt;/P&gt;&lt;P&gt;(dot net extension for the domain). In this case the csauth services logs&lt;/P&gt;&lt;P&gt;the following:&lt;/P&gt;&lt;P&gt;****************************************************************************&lt;/P&gt;&lt;P&gt;*************************&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:22:04 I 4562 1752 Attempting authentication for Unknown&lt;/P&gt;&lt;P&gt;User 'GIAINTRA.NET\giadmu'&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:22:04 I 0266 1752 External DB [NTAuthenDLL.dll]: Starting&lt;/P&gt;&lt;P&gt;authentication for user [GIAINTRA.NET\giadmu]&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:22:04 I 0266 1752 External DB [NTAuthenDLL.dll]:&lt;/P&gt;&lt;P&gt;Attempting NT/2000 authentication&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:22:04 I 0266 1752 External DB [NTAuthenDLL.dll]: NT/2000&lt;/P&gt;&lt;P&gt;authentication SUCCESSFUL (by GIAT057)&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:22:04 E 0266 1752 External DB [NTAuthenDLL.dll]: Local&lt;/P&gt;&lt;P&gt;account domain fallback not permitted&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:22:04 I 1311 1752 Unknown User 'GIAINTRA.NET\giadmu' was&lt;/P&gt;&lt;P&gt;not authenticated&lt;/P&gt;&lt;P&gt;****************************************************************************&lt;/P&gt;&lt;P&gt;*************************&lt;/P&gt;&lt;P&gt;Then I try to logon with giaintra\giadmu and the csauth service logs this:&lt;/P&gt;&lt;P&gt;****************************************************************************&lt;/P&gt;&lt;P&gt;*************************&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 I 4562 1776 Attempting authentication for Unknown&lt;/P&gt;&lt;P&gt;User 'GIAINTRA\giadmu'&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 I 1172 1776 ReadSupplierRegistry: Windows NT/2000&lt;/P&gt;&lt;P&gt;loaded&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 I 0266 1776 External DB [NTAuthenDLL.dll]: Starting&lt;/P&gt;&lt;P&gt;authentication for user [GIAINTRA\giadmu]&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 I 0266 1776 External DB [NTAuthenDLL.dll]:&lt;/P&gt;&lt;P&gt;Attempting NT/2000 authentication&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 I 0266 1776 External DB [NTAuthenDLL.dll]: NT/2000&lt;/P&gt;&lt;P&gt;authentication SUCCESSFUL (by GIAT057)&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 I 0266 1776 External DB [NTAuthenDLL.dll]:&lt;/P&gt;&lt;P&gt;Obtaining RAS information for user giadmu from GIAT057&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 E 0266 1776 External DB [NTAuthenDLL.dll]:&lt;/P&gt;&lt;P&gt;RasAdminUserGetInfo returned error 0x5&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 E 0266 1776 External DB [NTAuthenDLL.dll]: Failed&lt;/P&gt;&lt;P&gt;to get RAS information for user giadmu from GIAT057&lt;/P&gt;&lt;P&gt;AUTH 05/27/2002 10:19:07 I 1311 1776 Unknown User 'GIAINTRA\giadmu' was not&lt;/P&gt;&lt;P&gt;authenticated&lt;/P&gt;&lt;P&gt;****************************************************************************&lt;/P&gt;&lt;P&gt;*************************&lt;/P&gt;&lt;P&gt;I also turn on auditing for&lt;/P&gt;&lt;P&gt;- account logon events&lt;/P&gt;&lt;P&gt;- account management&lt;/P&gt;&lt;P&gt;- object access&lt;/P&gt;&lt;P&gt;on the domaincontroller of the 'giaintra.net' domain. But in the event&lt;/P&gt;&lt;P&gt;viewer I just see, that the account logon from the acs server was&lt;/P&gt;&lt;P&gt;succesfully. The following message appears in the event viewer:&lt;/P&gt;&lt;P&gt;****************************************************************************&lt;/P&gt;&lt;P&gt;*************************&lt;/P&gt;&lt;P&gt;Account Used for Logon by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0&lt;/P&gt;&lt;P&gt;Account Name:&lt;/P&gt;&lt;P&gt;giadmu&lt;/P&gt;&lt;P&gt;Workstation: &lt;/P&gt;&lt;P&gt;CISCO&lt;/P&gt;&lt;P&gt;****************************************************************************&lt;/P&gt;&lt;P&gt;*************************&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** NOTES LOG 03-JUN-2002 10:04:22 PST, kpintus, Action Type: Action *** &lt;/P&gt;&lt;P&gt;Hi Kirk&lt;/P&gt;&lt;P&gt;As I told you in a mail before the csauth log file log the following&lt;/P&gt;&lt;P&gt;message:&lt;/P&gt;&lt;P&gt;RasAdminUserGetInfo returned error 0x5&lt;/P&gt;&lt;P&gt;The error code 0x5 is the code for a 'permission denied' error.&lt;/P&gt;&lt;P&gt;See the ErrorText.exe in the LS-Tool Collection on &amp;lt;&lt;A class="jive-link-custom" href="http://www.losoft.de/" target="_blank"&gt;http://www.losoft.de/&lt;/A&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;I also search for the API Call 'RasAdminUserGetInfo' and found the following&lt;/P&gt;&lt;P&gt;article.&lt;/P&gt;&lt;P&gt;&amp;lt;&lt;A class="jive-link-custom" href="http://msdn.microsoft.com/library/en-us/rras/rasadm_5e9b.asp" target="_blank"&gt;http://msdn.microsoft.com/library/en-us/rras/rasadm_5e9b.asp&lt;/A&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;There is a remark, that the 'RasAdminUserGetInfo' function is replaced by&lt;/P&gt;&lt;P&gt;the 'MprAdminUserGetInfo' function in Windows 2000. Is it possible, that the&lt;/P&gt;&lt;P&gt;'Grant Dialin setting' can't work because the acs server call a old API&lt;/P&gt;&lt;P&gt;function? In this case the acs 3.0 can't work in a Windows 2000 environment&lt;/P&gt;&lt;P&gt;(puh - big bug).&lt;/P&gt;&lt;P&gt;In further I make some tests with different combinations of Registry Key and&lt;/P&gt;&lt;P&gt;the 'Grant Dialin Perm' setting:&lt;/P&gt;&lt;P&gt;RegKey dialinPerm MM\giadmu (Win NT) GIAINTRA\giadmu&lt;/P&gt;&lt;P&gt;(W2K)&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;1 not set ok nok&lt;/P&gt;&lt;P&gt;1 set ok nok&lt;/P&gt;&lt;P&gt;0 not set ok ok&lt;/P&gt;&lt;P&gt;0 set ok nok&lt;/P&gt;&lt;P&gt;For the 'GIAINTRA\giadmu' account the last case is against your statement in&lt;/P&gt;&lt;P&gt;the mail before (If you set it to 0 then you can check Grant dial in perms).&lt;/P&gt;&lt;P&gt;I set the registry key to 0 and check the 'Grant Dialin Permission' but&lt;/P&gt;&lt;P&gt;can't logon with the Win2000 account GIAINTRA\giadmu.&lt;/P&gt;&lt;P&gt;On the W2K Domaincontroller (GIAT057) I audit 'logon events'. Allways when I&lt;/P&gt;&lt;P&gt;would logon with the GIAINTRA\giadmu account the Domaincontroller log the&lt;/P&gt;&lt;P&gt;following three events:&lt;/P&gt;&lt;P&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;Event Type: Success Audit&lt;/P&gt;&lt;P&gt;Event Source: Security&lt;/P&gt;&lt;P&gt;Event Category: Account Logon &lt;/P&gt;&lt;P&gt;Event ID: 680&lt;/P&gt;&lt;P&gt;Date: 31.05.2002&lt;/P&gt;&lt;P&gt;Time: 18:11:33&lt;/P&gt;&lt;P&gt;User: NT AUTHORITY\SYSTEM&lt;/P&gt;&lt;P&gt;Computer: GIAT057&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;Account Used for Logon by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0&lt;/P&gt;&lt;P&gt;Account Name:&lt;/P&gt;&lt;P&gt;giadmu&lt;/P&gt;&lt;P&gt;Workstation: &lt;/P&gt;&lt;P&gt;CISCO&lt;/P&gt;&lt;P&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;Event Type: Failure Audit&lt;/P&gt;&lt;P&gt;Event Source: Security&lt;/P&gt;&lt;P&gt;Event Category: Directory Service Access &lt;/P&gt;&lt;P&gt;Event ID: 565&lt;/P&gt;&lt;P&gt;Date: 31.05.2002&lt;/P&gt;&lt;P&gt;Time: 18:11:33&lt;/P&gt;&lt;P&gt;User: NT AUTHORITY\ANONYMOUS LOGON&lt;/P&gt;&lt;P&gt;Computer: GIAT057&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;Object Open:&lt;/P&gt;&lt;P&gt;Object Server: Security Account Manager&lt;/P&gt;&lt;P&gt;Object Type: SAM_SERVER&lt;/P&gt;&lt;P&gt;Object Name: CN=Server,CN=System&lt;/P&gt;&lt;P&gt;New Handle ID: -&lt;/P&gt;&lt;P&gt;Operation ID: {0,125580714}&lt;/P&gt;&lt;P&gt;Process ID: 304&lt;/P&gt;&lt;P&gt;Primary User Name: GIAT057$&lt;/P&gt;&lt;P&gt;Primary Domain: GIAINTRA&lt;/P&gt;&lt;P&gt;Primary Logon ID: (0x0,0x3E7)&lt;/P&gt;&lt;P&gt;Client User Name: ANONYMOUS LOGON&lt;/P&gt;&lt;P&gt;Client Domain: NT AUTHORITY&lt;/P&gt;&lt;P&gt;Client Logon ID: (0x0,0x77C35A2)&lt;/P&gt;&lt;P&gt;Accesses MAX_ALLOWED &lt;/P&gt;&lt;P&gt;Privileges -&lt;/P&gt;&lt;P&gt;Properties:&lt;/P&gt;&lt;P&gt;**********************************************************************&lt;/P&gt;&lt;P&gt;Event Type: Failure Audit&lt;/P&gt;&lt;P&gt;Event Source: Security&lt;/P&gt;&lt;P&gt;Event Category: Directory Service Access &lt;/P&gt;&lt;P&gt;Event ID: 565&lt;/P&gt;&lt;P&gt;Date: 31.05.2002&lt;/P&gt;&lt;P&gt;Time: 18:11:33&lt;/P&gt;&lt;P&gt;User: NT AUTHORITY\ANONYMOUS LOGON&lt;/P&gt;&lt;P&gt;Computer: GIAT057&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;Object Open:&lt;/P&gt;&lt;P&gt;Object Server: Security Account Manager&lt;/P&gt;&lt;P&gt;Object Type: SAM_SERVER&lt;/P&gt;&lt;P&gt;Object Name: CN=Server,CN=System&lt;/P&gt;&lt;P&gt;New Handle ID: -&lt;/P&gt;&lt;P&gt;Operation ID: {0,125580717}&lt;/P&gt;&lt;P&gt;Process ID: 304&lt;/P&gt;&lt;P&gt;Primary User Name: GIAT057$&lt;/P&gt;&lt;P&gt;Primary Domain: GIAINTRA&lt;/P&gt;&lt;P&gt;Primary Logon ID: (0x0,0x3E7)&lt;/P&gt;&lt;P&gt;Client User Name: ANONYMOUS LOGON&lt;/P&gt;&lt;P&gt;Client Domain: NT AUTHORITY&lt;/P&gt;&lt;P&gt;Client Logon ID: (0x0,0x77C35A2)&lt;/P&gt;&lt;P&gt;Accesses MAX_ALLOWED &lt;/P&gt;&lt;P&gt;Privileges -&lt;/P&gt;&lt;P&gt;Properties:&lt;/P&gt;&lt;P&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;The first event is a successfull message, but the following two events are&lt;/P&gt;&lt;P&gt;failure messages (anonymous logon)?! Hope you can help me?&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2002 13:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17004#M438630</guid>
      <dc:creator>giadmu</dc:creator>
      <dc:date>2002-06-04T13:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17005#M438631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anthony&lt;/P&gt;&lt;P&gt;I found a solution for our problem. I take the everyone group to the "Pre-Windows 2000 Compatible Access" group. But I have to do this with a shell command because the everyone group isn't present in the gui:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;net localgroup "Pre-Windows 2000 Compatible Access" everyone /add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that the Everyone group was present in the Builtin group "Pre-Windows 2000 Compatible Access" and the login procedure works well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2002 12:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17005#M438631</guid>
      <dc:creator>giadmu</dc:creator>
      <dc:date>2002-06-05T12:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17006#M438632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may work but opens up some security concerns with granting Everyone into this group.  Please see below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;########################################################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Backwards Compatibility&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;When a Win 2000 machine is promoted to a domain controller, the Active Directory Installation Wizard (dcpromo.exe) asks several questions about the directory configuration. One of those questions is whether security should be relaxed on directory objects to permit access from downlevel systems like NT4 RAS servers and SQL machines. If you choose to relax security, the Everyone identity is added to the Pre-Windows 2000 Compatible Access group. Pre-Windows 2000 Compatible Access has read permissions on many critical directory objects, including the Users and Groups containers. Thus, by selecting legacy security, Everyone has permissions to enumerate user accounts and group names on the domain. You can alleviate this situation by removing Everyone from the Pre-Windows 2000 Compatible Access group like so:&lt;/P&gt;&lt;P&gt;net localgroup "Pre-Windows 2000 Compatible Access" everyone /delete&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that this will affect downlevel client access to certain directory objects. Thus, it's best to try and migrate NT4 RAS and SQL systems to Win 2000 first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;One of the well-known security principals is Pre-Windows 2000 Compatible Access. By default, this group has permissions for most of the objects in a domain.&lt;/P&gt;&lt;P&gt;The member list of Pre-Windows 2000 Compatible Access was determined when you installed Active Directory to create a new domain and chose the option for Permission.&lt;/P&gt;&lt;P&gt;&amp;#149;	If you selected &amp;#147;Permissions compatible with pre-Windows 2000 servers,&amp;#148; Everyone will be a member.&lt;/P&gt;&lt;P&gt;&amp;#149;	If you selected &amp;#147;Permissions compatible with only Windows 2000 servers,&amp;#148; there will be no members.&lt;/P&gt;&lt;P&gt;Remember that Everyone includes all authenticated and anonymous users.&lt;/P&gt;&lt;P&gt;If you want to change the choice you made at the time of installation, you can use one of the following commands (deletion is possible also with the Users and Computers snap-in):&lt;/P&gt;&lt;P&gt;NET LOCALGROUP &amp;#147;Pre-Windows 2000 Compatible Access&amp;#148; Everyone /ADD&lt;/P&gt;&lt;P&gt;NET LOCALGROUP &amp;#147;Pre-Windows 2000 Compatible Access&amp;#148; Everyone /DELETE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Principal	Permissions	Apply To&lt;/P&gt;&lt;P&gt;Administrators	Full Control except Delete All Child Objects and Delete Subtree	&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enterprise Admins	Full Control	&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	List Contents	&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	Read Remote Access Information	User&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	Read General Information	User&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	Read Group Membership	User&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	Read Account Restrictions	User&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	Read Logon Information	User&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	Read, List Object	Group&lt;/P&gt;&lt;P&gt;Pre-Windows 2000 Compatible Access	Read, List Object	User&lt;/P&gt;&lt;P&gt;########################################################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just thinking if you were concerned about putting ACS on a DC that this may also be an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2002 16:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17006#M438632</guid>
      <dc:creator>anthony.cogswell</dc:creator>
      <dc:date>2002-06-05T16:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17007#M438633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was wondering if you were able to resolve this problem?  I am also getting the "RasAdminUserGetInfo returned error 0x5" error.  I am running ACS 3.0 on a win 2K member server.  I have configured an administrative account that the services run as. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to authenticate to a local user on the server, but I am not able to authenticate to an account in the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw the previous post about adding everyone to the Pre-Windows 2000 Compatible Access group, but I don't think our server guys want to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2002 19:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17007#M438633</guid>
      <dc:creator>sconnolly</dc:creator>
      <dc:date>2002-07-08T19:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17008#M438634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still having the same problem.  Since this was and still is only in testing I set up the local ACS database for authentication.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2002 11:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17008#M438634</guid>
      <dc:creator>anthony.cogswell</dc:creator>
      <dc:date>2002-07-09T11:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17009#M438635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I too have the same exact problem when my client migrated to a homogenous Windows 2000 platform.  We were forced to use the Pre-Windows 2000 Compatability work around.  However, the client understands the extreme security risk and is very disappointed that Cisco hasn't released a patch to correct this problem.  It's incorrect to state that the product is completely compatible with win2k domain controllers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jul 2002 22:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17009#M438635</guid>
      <dc:creator>damerino</dc:creator>
      <dc:date>2002-07-30T22:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17010#M438636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did any of you guys find a solution for this problem yet?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2002 06:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17010#M438636</guid>
      <dc:creator>kj</dc:creator>
      <dc:date>2002-09-10T06:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17011#M438637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This problem renders the NT domian functionality unusable. further more? why did this work on ACS 2.6 and most important how? any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2002 11:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17011#M438637</guid>
      <dc:creator>kj</dc:creator>
      <dc:date>2002-09-12T11:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17012#M438638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yesterday I upgrade my ACS to the version 3.1. In this Release you don't have to add the group 'everyone' to the Built-in group "Pre Windows 2000 Compatible Access". It seems that the ACS integration with Windows 2000 AD works fine with Version ACS Release 3.1!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2003 13:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17012#M438638</guid>
      <dc:creator>giadmu</dc:creator>
      <dc:date>2003-01-23T13:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication to Win2K</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17013#M438639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a similar issue with 3.0 and 3.1.  I resolved this by disabling the "require kerberos pre-authentication" option under the user setup. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2003 14:54:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-to-win2k/m-p/17013#M438639</guid>
      <dc:creator>grshaw</dc:creator>
      <dc:date>2003-01-24T14:54:18Z</dc:date>
    </item>
  </channel>
</rss>

