<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.2 authenticating to AD fails 'LookupAccountSidA Failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125910#M439564</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;both the ACS and AD are running SP3. I installed all the latest critical updates before starting my testing do you have any idea what fix in sp4 causes the problems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Sep 2003 13:24:14 GMT</pubDate>
    <dc:creator />
    <dc:date>2003-09-10T13:24:14Z</dc:date>
    <item>
      <title>ACS 3.2 authenticating to AD fails 'LookupAccountSidA Failed'</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125908#M439543</link>
      <description>&lt;P&gt;The failed log has the error 'External DB Account Restriction'. I have the Permit dial in permsion enabled which was the only thing i could find on that one. In the auth.log i get the following (see below) there is a line that states 'Windows Authentication Succesful' followed by a line 'LookupAccountSidA failed' followed by 'User 'TESTAD\testguy1' was not authenticated'. I have not been able to figure out what the second call is that failed. LookupAccountSidA and why it says succesful then failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 0425 1180 AuthenProcessResponse: process response for 'TESTAD\testguy1' against Windows NT/2000&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 0360 1180 External DB [NTAuthenDLL.dll]: Starting MSCHAP authentication for user [TESTAD\testguy1]&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 0360 1180 External DB [NTAuthenDLL.dll]: Attempting Windows authentication for user testguy1&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 0360 1180 External DB [NTAuthenDLL.dll]: Windows authentication SUCCESSFUL (by PDC)&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 E 0360 1180 External DB [NTAuthenDLL.dll]: LookupAccountSidA failed&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 1591 1180 Unknown User 'TESTAD\testguy1' was not authenticated&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 5081 1180 Done RQ1027, client 6, status -2046&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 5094 1180     Worker 6 processing message 43.&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 5081 1180 Start RQ1027, client 6 (127.0.0.1)&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 0425 1180 AuthenProcessResponse: process response for 'TESTAD\testguy1' against Windows NT/2000&lt;/P&gt;&lt;P&gt;AUTH 09/09/2003 12:07:31 I 5081 1180 Done RQ1027, client 6, status -1058&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125908#M439543</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2019-03-10T14:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.2 authenticating to AD fails 'LookupAccountSidA Failed</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125909#M439556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My guess is you're running SP4 on this machine, which is not supported by ACS (only up to SP3) and will give you this error.  Downgrade to SP3 and it should work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you're not running SP4 as we'll have to look elsewhere, but I've seen this a couple of times already and it was due to SP4 and downgrading resolved the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Sep 2003 03:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125909#M439556</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-09-10T03:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.2 authenticating to AD fails 'LookupAccountSidA Failed</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125910#M439564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;both the ACS and AD are running SP3. I installed all the latest critical updates before starting my testing do you have any idea what fix in sp4 causes the problems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Sep 2003 13:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125910#M439564</guid>
      <dc:creator />
      <dc:date>2003-09-10T13:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.2 authenticating to AD fails 'LookupAccountSidA Failed</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125911#M439577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem was an permissions issue with the ACS servcie account, I didn't troubleshoot it completly. Makeing the ACS server a DC (it was a domain member server) solved the problem. I assume the issue has to do with the permissions given in the 'Local Security Policy', 'Domain COntroler Security Policy', or 'Domain Security Policy'.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2003 15:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-authenticating-to-ad-fails-lookupaccountsida-failed/m-p/125911#M439577</guid>
      <dc:creator />
      <dc:date>2003-09-12T15:10:37Z</dc:date>
    </item>
  </channel>
</rss>

