<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic From the ACS perspective this in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-1-ad-authentication/m-p/2452774#M86492</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;From the ACS perspective this can't be done because this is not under the control of the ACS to choose the DC. ACS forwards user credentials to a Windows database by passing the user credentials to the Windows operating system of the computer that is running ACS for Windows or the Solution Engine remote agent. The Windows database passes or fails the authentication request from ACS.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;You can refer to below listed link:&lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4." target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.&lt;/A&gt;&lt;BR /&gt;2/user/guide/UsrDb.html#wp353547&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;If you are running ACS on windows than you've a liberty to use windows lmhost file.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;As a final means of ensuring communication with specific domain controllers, on the member server that is running ACS, configure a LMHOSTS file to include entries for each domain controller that ACS must authenticate.The format of an LMHOSTS file is very particular. Ensure that you understand the requirements of configuring the LMHOSTS file. For more information, see:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;- Microsoft.com: LMHOSTS File&lt;BR /&gt;- The example LMHOSTS file is included with the Windows operating system.&amp;nbsp;&lt;BR /&gt;The default location and filename for the sample file is&amp;nbsp;&lt;BR /&gt;systemroot&amp;gt;\system32\drivers\etc\lmhosts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;For more information, please refer the below listed doc&lt;BR /&gt;http://www.scribd.com/doc/50262863/345/Using-the-Lmhosts-File&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;NOTE:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-family: verdana, geneva, sans-serif; font-size: 11px;"&gt;In order to check what domain and DC ACS is trying to connect, check auth.log when set to full logging.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Apr 2014 19:04:02 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2014-04-24T19:04:02Z</dc:date>
    <item>
      <title>ACS 4.1 AD Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-ad-authentication/m-p/2452773#M86491</link>
      <description>&lt;P&gt;We have an existing HA deployment of Cisco ACS 4.1 servers authenticating wireless users with 802.1X against AD. We are looking to retire a number of older DCs in the near future. Prior to retiring the DCs, I want to make sure no authentication requests are being sent to them. From the ACS GUI, I cannot determine what DC IP / hostnames the ACS is pointing to. Within Exernal Users&amp;nbsp;Databases -&amp;gt; Database Configuration -&amp;gt; Windows Database, I don't see any mention of server ip / hostname. I've ran throught he configuration guide, but didn't see any place where you enter the information either.&amp;nbsp;Is it possible the DC server IP addresses are also&amp;nbsp;stored within some&amp;nbsp;configuration file on the server itself? Does anyone have any suggestions short of running wireshark captures to/from each of the DCs to see if authentication requests are coming from the ACS servers? Any advice or suggestions would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-ad-authentication/m-p/2452773#M86491</guid>
      <dc:creator>psullivan1984</dc:creator>
      <dc:date>2019-03-11T04:39:45Z</dc:date>
    </item>
    <item>
      <title>From the ACS perspective this</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-ad-authentication/m-p/2452774#M86492</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;From the ACS perspective this can't be done because this is not under the control of the ACS to choose the DC. ACS forwards user credentials to a Windows database by passing the user credentials to the Windows operating system of the computer that is running ACS for Windows or the Solution Engine remote agent. The Windows database passes or fails the authentication request from ACS.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;You can refer to below listed link:&lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4." target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.&lt;/A&gt;&lt;BR /&gt;2/user/guide/UsrDb.html#wp353547&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;If you are running ACS on windows than you've a liberty to use windows lmhost file.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;As a final means of ensuring communication with specific domain controllers, on the member server that is running ACS, configure a LMHOSTS file to include entries for each domain controller that ACS must authenticate.The format of an LMHOSTS file is very particular. Ensure that you understand the requirements of configuring the LMHOSTS file. For more information, see:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;- Microsoft.com: LMHOSTS File&lt;BR /&gt;- The example LMHOSTS file is included with the Windows operating system.&amp;nbsp;&lt;BR /&gt;The default location and filename for the sample file is&amp;nbsp;&lt;BR /&gt;systemroot&amp;gt;\system32\drivers\etc\lmhosts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;For more information, please refer the below listed doc&lt;BR /&gt;http://www.scribd.com/doc/50262863/345/Using-the-Lmhosts-File&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;NOTE:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-family: verdana, geneva, sans-serif; font-size: 11px;"&gt;In order to check what domain and DC ACS is trying to connect, check auth.log when set to full logging.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 19:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-ad-authentication/m-p/2452774#M86492</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-04-24T19:04:02Z</dc:date>
    </item>
  </channel>
</rss>

