<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS 5.2 Active Directory Trust Relationship in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275176#M94617</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again Dears, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I installed ACS 5.3 with patch 4.7. Now I can authenticate users whch is located in Domain B. But only Netbios &lt;STRONG&gt;domainb\user, &lt;/STRONG&gt;I can't authenticate with UPN suffix &lt;STRONG&gt;&lt;A class="jive-link-email-small" href="mailto:user@domainb.com"&gt;user@domainb.com&lt;/A&gt;&lt;/STRONG&gt;. Trust is a forest and two-way authentication. Do you know what is the reason?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Jul 2013 09:26:25 GMT</pubDate>
    <dc:creator>Mikayil Qasimov</dc:creator>
    <dc:date>2013-07-18T09:26:25Z</dc:date>
    <item>
      <title>Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275164#M94605</link>
      <description>&lt;P&gt;Hello Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Cisco ACS 5.2 server and 2 DC with two different domain name. Cisco ACS is connected to DC1(xxx.xdomain.com), and working well. Between these DC(ydomain.com) have two-way Trust Relationship. &lt;/P&gt;&lt;P&gt;How I can authenticate DC2 users in Cisco ACS? Please help&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275164#M94605</guid>
      <dc:creator>Mikayil Qasimov</dc:creator>
      <dc:date>2019-03-11T03:38:41Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275165#M94606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to add a UPN suffix or NETBIOS prefix to&amp;nbsp; the username when authenticating to a domain that the ACS is not joined&amp;nbsp; to, including the child domains. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS does not support user authentication in AD&amp;nbsp; when a user name is supplied with an alternative UPN suffix configured&amp;nbsp; in OU level. The authentication works fine if the UPN suffix is&amp;nbsp; configured in domain level. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/users_id_stores.html#wp1053213"&gt;http://www.cisco.com/en/US/partner/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/users_id_stores.html#wp1053213&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 17:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275165#M94606</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-12T17:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275166#M94607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Jatin,&lt;BR /&gt;&lt;BR /&gt;Thanks for quick reply. Can you explain it in detail?&lt;BR /&gt;For example: ACS is connect to xxx.domain.com and in directory we can add the groups like xxx.domain.com/groups/IT . How I should add another group which is located in other Domain?&lt;BR /&gt;About UPN suffix, in which domain I should add suffix and how?&lt;BR /&gt;Thanks beforehand&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Jul 2013 10:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275166#M94607</guid>
      <dc:creator>Mikayil Qasimov</dc:creator>
      <dc:date>2013-07-13T10:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275167#M94608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nobody knows hot to fix it?&amp;nbsp; Everywhere everybody says that add UPN suffix or it's about UPN. But nobody can show some example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 07:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275167#M94608</guid>
      <dc:creator>Mikayil Qasimov</dc:creator>
      <dc:date>2013-07-15T07:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275168#M94609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If ACS is connected to DC1(xxx.xdomain.com) and you are also able to select groups from trsuted domain i.e. DC2 (ydomain.com) from the ACS by going to&lt;STRONG&gt; Users and Identity Stores &amp;gt; External Identity Stores &amp;gt; Active Directory &amp;gt; Directory Groups. &lt;/STRONG&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should work fine for users who are in DC2 (ydomain.com) if they are connecting/authenticating with the UPN format &lt;STRONG&gt;&lt;A class="jive-link-email-small" href="mailto:user@ydomain.com"&gt;user@ydomain.com&lt;/A&gt;&lt;/STRONG&gt; or &lt;/P&gt;&lt;P&gt;Netbios &lt;STRONG&gt;user\ydomain.com&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a condition created under access-policies and seleceted an AD group from the DC2 (ydomain.com) domain and it's not matching that authorization rule then it might not be coming in other attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to achieve the best results with ACS and AD, you should have ACS 5.3 patch 4 or above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are few defects where ACS fails to fetch user information from the trusted domain and that has been fixed in ACS 5.3 patch 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 13:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275168#M94609</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-15T13:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275169#M94610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again Jatin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried authentication with UPN and Netbios but unseccessfully. I'm using 5.2 ACS if I will upgrade it to 5.3 with patch 4 or above, is't will work normally with trusted domain?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 06:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275169#M94610</guid>
      <dc:creator>Mikayil Qasimov</dc:creator>
      <dc:date>2013-07-16T06:06:10Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275170#M94611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've not seen the adagent logs yet so can't say what exactly the problem is. In most of the cases, I have seen issue with 2 way external trust. Also, upgrading to acs 5.3 latest patch would be worth.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 11:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275170#M94611</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-16T11:34:17Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275171#M94612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the domain functional level across the domains?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 13:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275171#M94612</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-16T13:56:15Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275172#M94613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible there is some ports blocked to the trusted domains. A packet capture would be very helpful to see what was being blocked to trusted domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your active directory configured with&lt;STRONG&gt; trusted domain as an alternate UPN&lt;/STRONG&gt; under Active directory Domains and Trust. We could give a try if all ports are open and we are running atleast win2003 functional level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 14:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275172#M94613</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-16T14:07:25Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275173#M94614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt; &lt;A _jive_internal="true" href="https://community.cisco.com/people/mikayil1987" id="jive-5651553932138884704895"&gt;Hi Mikayil Qasimov&lt;/A&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you get a chance to check the above suggested pointers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 02:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275173#M94614</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-17T02:27:18Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275174#M94615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you domains in the same forest or are they in separate forests? See this guide for kerberos authentication in a multi-forest scenario. You may need further research in your trust type since two-way trusts may not allow kerberos (that is what ACS uses to authenticate against the domains).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://technet.microsoft.com/en-us/library/cc772808%28v=ws.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/cc772808%28v=ws.10%29.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://setspn.blogspot.com/2009/09/ad-external-trusts-and-kerberos.html"&gt;http://setspn.blogspot.com/2009/09/ad-external-trusts-and-kerberos.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 05:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275174#M94615</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-07-17T05:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275175#M94616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all, I installed acs 5.3 with package &lt;SPAN style="font-size: 10pt;"&gt;5.3.0.40. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2 AD are Windows server 2008. Between them before it was forest trusted but didn't work after I changed it to external trust the same result, now it's External Trust. I check trust for me it works,in AD2 I gave administrator privilage for user which is located in AD1, after this I can connect with RDP to AD2&amp;nbsp; with that user. Added UPN under active directories. I can send images to your email if you will send me your email address with private messages.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 06:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275175#M94616</guid>
      <dc:creator>Mikayil Qasimov</dc:creator>
      <dc:date>2013-07-17T06:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275176#M94617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again Dears, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I installed ACS 5.3 with patch 4.7. Now I can authenticate users whch is located in Domain B. But only Netbios &lt;STRONG&gt;domainb\user, &lt;/STRONG&gt;I can't authenticate with UPN suffix &lt;STRONG&gt;&lt;A class="jive-link-email-small" href="mailto:user@domainb.com"&gt;user@domainb.com&lt;/A&gt;&lt;/STRONG&gt;. Trust is a forest and two-way authentication. Do you know what is the reason?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 09:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275176#M94617</guid>
      <dc:creator>Mikayil Qasimov</dc:creator>
      <dc:date>2013-07-18T09:26:25Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 Active Directory Trust Relationship</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275177#M94618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mikayil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were you able to find my post useful, I dont think the trust type you have supports kerberos authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if this article is of any use - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://technet.microsoft.com/en-us/library/cc784334%28v=ws.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/cc784334%28v=ws.10%29.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 06:12:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-active-directory-trust-relationship/m-p/2275177#M94618</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-07-19T06:12:49Z</dc:date>
    </item>
  </channel>
</rss>

