<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ask the Expert:  Installing and Configuring Cisco Access Control in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325077#M92234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Javier,&lt;/P&gt;&lt;P&gt;For the purpose of ACS database replication - what ports need to be open on any firewalls between primary and secondary nodes?&amp;nbsp; appreciate your help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Oct 2013 23:33:40 GMT</pubDate>
    <dc:creator>John Ventura</dc:creator>
    <dc:date>2013-10-09T23:33:40Z</dc:date>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control System</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325069#M92226</link>
      <description>&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/4/1/159141-javier-henderson-pic.jpg" align="left" alt="Installing and configuring Cisco Access Control System" border="0" hspace="10" style="padding-right: 10px; padding-bottom: 10px;" width="90" /&gt;&lt;STRONG&gt;With Javier Henderson&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Welcome to the Cisco Support Community Ask the Expert conversation.&amp;nbsp; This&amp;nbsp; is an opportunity to learn and ask questions about how to install and configure the Cisco Secure Access Control System (ACS) with expert Javier Henderson.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The Cisco Secure ACS is a centralized identity and access policy solution that ties together an enterprise's network access policy and identity strategy. Cisco Secure ACS operates as a RADIUS and TACACS+ server, combining user authentication, user and administrator device access control, and policy control in a centralized identity networking solution.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Javier Henderson has been a customer support engineer with the Security Team, specializing in AAA technologies, since 2004. In addition to supporting Cisco customers, he has delivered training to other teams on various AAA products. Javier attended Buenos Aires University and holds CCNA and Checkpoint certifications.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Remember to use the rating system to let Javier know if you've received an adequate response.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Because of the volume expected during this event, Javier might not be able to answer every question. Remember that you can continue the conversation in the Security community, subcommunity, AAA, Identity and NAC, shortly after the event. This event lasts through October 18, 2013. Visit this forum often to view responses to your questions and those of other Cisco Support Community members.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325069#M92226</guid>
      <dc:creator>ciscomoderator</dc:creator>
      <dc:date>2019-03-11T03:57:49Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325070#M92227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="border: none; border-collapse: collapse; list-style: none; margin: 0px 0px 10px; clear: none;"&gt;&lt;H2 style="border-collapse: collapse; font-size: 2em; list-style: none; margin: 0px 100px 0px 0px; font-weight: normal; width: auto;"&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/4059311#4059311" style="border-collapse: collapse; font-size: 27px; list-style: none; outline: none; color: #ee6804; text-decoration: none; width: auto;"&gt;CSACS 1121 V5.4.0.46.4&lt;/A&gt;&lt;/H2&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="border-collapse: collapse; list-style: none; margin: 0px 0px 20px; padding: 2px; overflow: visible; position: relative; zoom: 1; width: 705.859375px;"&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Good morning, I'm Eric Jones and I'm a CISCO equipment user.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;I have some questions on the 1121 AAA server.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;We have 2, one is configured to work with our Active Directory.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;It access the AD data and will pull the username from the AD group; however, when you attempt to enter the AD group users password it fails to login into the IOS device chosen.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;What it wants is the enable password created for the local admin account on the IOS device.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;The Shell profiles and Command Sets have been created.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;The binding has been completed.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;The IOS device has its configuration completed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Part II of this issue.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;When I first began configuring the device there were now Default Device Admin or Default Network Admin Access Policies configured.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;I had to create these myself.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;After that surprise everything went smoothly as mentioned above with the Shell Profiles and Command Sets.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Has anyone seen this issue before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Part III of this issue.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;When entering the Monitoring and Reports section and enabling Support Bundle I get an error when trying to start it.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;I get a red warning banner at the top stating the server isn't running. Well Clearly it's running but it doesn't think so.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Also when trying to view the reports to see any accounting, authorization, authentication information in the logs there's nothing there.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;I have configured the logs to write to a Server but nothing ever gets written.&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;And since nothing is being done locally on the ACS I can't tell why it's not writting to the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;ej&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 21:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325070#M92227</guid>
      <dc:creator>Eric R. Jones</dc:creator>
      <dc:date>2013-10-04T21:11:41Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325071#M92228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm implementing a Cisco ACS in a multi tenant private cloud.&amp;nbsp; Has anyone else done this using multiple LDAP identity stores?&amp;nbsp; I need to research other work done in this area by universities, government and individuals.&amp;nbsp; Can you help me with any examples?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-anne&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Oct 2013 05:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325071#M92228</guid>
      <dc:creator>aducey01</dc:creator>
      <dc:date>2013-10-06T05:11:49Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325072#M92229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I found my answer, the IP address format I was using was incorrect.&lt;/P&gt;&lt;P&gt;I had been using 10.*.*.* or a combination of this when I should have been a bit more detailed.&lt;/P&gt;&lt;P&gt;I have used 10.#-#.*.* or 10.0.#-#.#-# and now that issue has been resolved.&lt;/P&gt;&lt;P&gt;The next issue deals with AD and some users not being able to use their passwords to access the Priv Exec portion.&lt;/P&gt;&lt;P&gt;Should be an easy thing to track down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ej&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 01:32:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325072#M92229</guid>
      <dc:creator>Eric R. Jones</dc:creator>
      <dc:date>2013-10-08T01:32:28Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325073#M92230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anne,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS supports having multiple LDAP servers as identity stores.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have specific configuration scenarios in mind that you'd care to discuss?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 05:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325073#M92230</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-08T05:12:27Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325074#M92231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding your questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can you post the AAA configuration that you're using on the router? Please redact any passwords and IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) By default, ACS has a RADIUS default access policy called Default Network Access, and a TACACS+ access policy called Default Device Admin. You can create additional policies, as needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Please log into the CLI and run the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# show application status acs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then post the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, what version of ACS are you running? Include patch level, please. You can get this information from the "About..." link on the GUI, or "show version" on the CLI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 05:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325074#M92231</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-08T05:17:08Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325075#M92232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Javier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; We configured AAA on the switch on the group, and we added 2 ACS on that group, and on the row we added Enable last.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; So first i can see deny message on our ACS but 2 time i can go switch by my Enable password, but on second ACS on the group at the moment shut down, is that affected or ? that Enable command is allowing us to access switch any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 15:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325075#M92232</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2013-10-09T15:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Ask the Expert:  Installing and Configuring Cisco Access Con</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325076#M92233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tulgabat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could I see the current switch configuration, please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In general, authentication methods are tried in the order in which they appear, until a valid response is received.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: access-reject is a valid response, so if the user enters an invalid username/password combination and ACS returns access-reject then no subsequent methods will be tried.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, consider the following configuration on a router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above case, access-reject by ACS will cause the router to reject the login. if ACS returns an error condition, or is unreachable, then the local user account configuration on the router will be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Cisco Systems&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 15:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325076#M92233</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-09T15:17:53Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325077#M92234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Javier,&lt;/P&gt;&lt;P&gt;For the purpose of ACS database replication - what ports need to be open on any firewalls between primary and secondary nodes?&amp;nbsp; appreciate your help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 23:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325077#M92234</guid>
      <dc:creator>John Ventura</dc:creator>
      <dc:date>2013-10-09T23:33:40Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325078#M92235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Javier, &lt;/P&gt;&lt;P&gt;How are you? I'm Jackson from Westrac Australia, we use AIRONET 1300 series WIFI radios.&lt;/P&gt;&lt;P&gt;Quick question, &lt;/P&gt;&lt;P&gt;Logging in via hyperterminal, we are normally present with "AP&amp;gt;" , we've seen a couple of "Bridge:".&lt;/P&gt;&lt;P&gt;Could you point out to me how to go from Bridge prompt to AP prompt pls, thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 00:54:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325078#M92235</guid>
      <dc:creator>jacksonseow</dc:creator>
      <dc:date>2013-10-10T00:54:13Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325079#M92236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following table lists what ports are used by ACS, and for what purpose:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/admin_operations.html#wp1093548"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/admin_operations.html#wp1093548&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 10:47:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325079#M92236</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-10T10:47:01Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325080#M92237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Javier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; That error condition making some confusions ... i've tried both Drop,Reject actions on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vty lin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; session-timeout 10&lt;/P&gt;&lt;P&gt; password 7 121A0C041104&lt;/P&gt;&lt;P&gt; authorization commands 1 COMMANDS-1-AUTH&lt;/P&gt;&lt;P&gt; authorization commands 15 COMMANDS-15-AUTH&lt;/P&gt;&lt;P&gt; authorization exec EXEC-AUTH&lt;/P&gt;&lt;P&gt; accounting commands 1 COMMANDS-1-ACCT&lt;/P&gt;&lt;P&gt; accounting commands 15 COMMANDS-15-ACCT&lt;/P&gt;&lt;P&gt; accounting exec EXEC-ACCOUNTING&lt;/P&gt;&lt;P&gt; logging synchronous&lt;/P&gt;&lt;P&gt; login authentication VTY-LOGIN&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt; transport output telnet ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and AAA config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TEST&lt;/P&gt;&lt;P&gt; server **.11&lt;/P&gt;&lt;P&gt; server **.12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login VTY-LOGIN group &lt;SPAN style="font-size: 10pt;"&gt;TEST &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login CONSOLE group &lt;SPAN style="font-size: 10pt;"&gt;TEST &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and i can see deny message in ACS on our primary ACS, and second time it is allowing to access it by Enable password, so i am guessing that is why because our Secondary ACS is shutdown ... so wondering procedure is it should access both ACS in the group? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 14:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325080#M92237</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2013-10-10T14:22:55Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325081#M92238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tulgabat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router should try to contact both ACS serves listed in the TEST server group. If neither respods, or both respond with an error condition, then the router should try the next method on the list, which in your configuration is "enable" (ie, the enable password configured on the router).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind that if either of the ACS servers returns a deny then the authentication process will stop at that point and reject the login attempt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 14:39:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325081#M92238</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-10T14:39:59Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325082#M92239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jackson,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Bridge: prompt is from the bootloader, rather than IOS. Please refer to the wireless area of this support forum for further assistance, since this event is centered around ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 16:06:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325082#M92239</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-10T16:06:40Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325083#M92240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Javier,&lt;/P&gt;&lt;P&gt;Another quick question, h&lt;SPAN style="font-size: 10pt;"&gt;ow do I configure ACS to use Windows AD credentials for administrative access to the ACS GUI? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 01:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325083#M92240</guid>
      <dc:creator>John Ventura</dc:creator>
      <dc:date>2013-10-11T01:18:15Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325084#M92241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To configure ACS to use Windows AD credentials for administrative access to the GUI once ACS has been joined to an AD domain:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Go to System Administration -&amp;gt; Administrators -&amp;gt; Administrative Access Control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Click on Identity, then for Identity Source select "AD1"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Click on Save Changes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Click on Authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5) Create an authorization policy with the desired criteria to grant access and grant the desired role&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Complete, step by step instructions are available in the following document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/user/guide/admin_admin.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/user/guide/admin_admin.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 11:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325084#M92241</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-11T11:36:00Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325085#M92242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Javier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we integrate ACS with RSA Authentication Manager for two factor authentication.&lt;/P&gt;&lt;P&gt;How does the two factor authentication work in this integration scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other App other than RSA, we can integrate with ACS for two factor authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rajmohan R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 15:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325085#M92242</guid>
      <dc:creator>RAJMOHAN RAMAMOORTHY</dc:creator>
      <dc:date>2013-10-14T15:07:58Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325086#M92243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rajmohan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS supports the RSA product, in addition to other third party products as external user databases to provide two-factor authentication.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Details on the configuration steps can be found int he following document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/user/guide/users_id_stores.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/user/guide/users_id_stores.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have specific questions regarding ACS configuration once you had a chance to read that document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 15:19:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325086#M92243</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2013-10-14T15:19:53Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325087#M92244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Javier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Looks like 5.2 version bug ... &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 04:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325087#M92244</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2013-10-16T04:55:31Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert:  Installing and Configuring Cisco Access Control</title>
      <link>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325088#M92245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Javier,&lt;/P&gt;&lt;P&gt;Thank you for covering this topic.&amp;nbsp; Have a question for you.&amp;nbsp; What are the requirements for the AD account used to join ACS to AD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jessica&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2013 17:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ask-the-expert-installing-and-configuring-cisco-access-control/m-p/2325088#M92245</guid>
      <dc:creator>Jessica Deaken</dc:creator>
      <dc:date>2013-10-17T17:19:26Z</dc:date>
    </item>
  </channel>
</rss>

