<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External Identity Source - LDAP Admin DN account in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575632#M524331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a doubt about what information to put in the Admin DN filed when we are defining a LDAP external identity store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example: the objects in the identity store are in the route: CN=NAC,DC=ds,DC=corp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Admin DN account that I should put to configure and bind the connection has to be mandatorily an admin accont of that domain, or I could put another account from another domain, but where the user defined on the server has read privileges at least to get the groups and subjects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/108255_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this configuration, the bind is successful. The question&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and kind regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Jun 2017 11:28:51 GMT</pubDate>
    <dc:creator>palonso_3</dc:creator>
    <dc:date>2017-06-13T11:28:51Z</dc:date>
    <item>
      <title>External Identity Source - LDAP Admin DN account</title>
      <link>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575632#M524331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a doubt about what information to put in the Admin DN filed when we are defining a LDAP external identity store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example: the objects in the identity store are in the route: CN=NAC,DC=ds,DC=corp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Admin DN account that I should put to configure and bind the connection has to be mandatorily an admin accont of that domain, or I could put another account from another domain, but where the user defined on the server has read privileges at least to get the groups and subjects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/108255_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this configuration, the bind is successful. The question&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and kind regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jun 2017 11:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575632#M524331</guid>
      <dc:creator>palonso_3</dc:creator>
      <dc:date>2017-06-13T11:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: External Identity Source - LDAP Admin DN account</title>
      <link>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575633#M524332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does not need to be an admin account. Since you're going against Active Directory, you don't need to spell out the full DN. You can specify domain\username as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jun 2017 13:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575633#M524332</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2017-06-13T13:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: External Identity Source - LDAP Admin DN account</title>
      <link>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575634#M524335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Viktor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. So as far if I understand you, I could put a username from another domain (different from ds.corp), in the form DOMAIN\username, if this username is allowed to ask the LDAP server and get the information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jun 2017 14:03:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575634#M524335</guid>
      <dc:creator>palonso_3</dc:creator>
      <dc:date>2017-06-13T14:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: External Identity Source - LDAP Admin DN account</title>
      <link>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575635#M524337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that's correct. I've seen some instances when you need to specify the domain even when you're querying the domain controller from that domain, so it's safest to specify the domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jun 2017 14:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-identity-source-ldap-admin-dn-account/m-p/3575635#M524337</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2017-06-13T14:22:35Z</dc:date>
    </item>
  </channel>
</rss>

