<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA-active directory agent problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688158#M536678</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;'I am using the built-in radius function'&lt;/PRE&gt;&lt;P&gt;Witch built-in radius function are you using? IAS from Windows 2003?&lt;/P&gt;&lt;P&gt;In that case you the ports 1812 and 1813 are allready taken by the radius services from IAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AD-agent is a small radius server by itself. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a common problem with SBS installations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Jul 2013 07:54:20 GMT</pubDate>
    <dc:creator>hvdhelm</dc:creator>
    <dc:date>2013-07-12T07:54:20Z</dc:date>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688146#M536648</link>
      <description>&lt;P&gt;hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im trying to configure the&amp;nbsp; user identity feature on my asa and there isnt real debugging document,so hopefully u can help me.&lt;/P&gt;&lt;P&gt;ive configured my ad agent on a server the installion went well and im able to see users from the AD srv.&lt;/P&gt;&lt;P&gt;ive configured the ASA with the ip address of the AD SRV and im able to reach the srv via LDAP,the problem is in the configuration of the connection to the&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ad client via radius (my asa is 10.2.16.110 and the ad client is configured on 10.2.16.169),i do have ip connectivty between the two and i can see in the wireshark that ive opened in the server that i do recieve RADIUS sesions from my ASA but according to the ASA debug the server respone is timed out....&lt;/P&gt;&lt;P&gt;im attaching the debug of the asa and some relevant commands from the AD client hopefully someone can tip me..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the asa debug&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;arsed packet data.....&lt;/P&gt;&lt;P&gt;Radius: Code = 1 (0x01)&lt;/P&gt;&lt;P&gt;Radius: Identifier = 44 (0x2C)&lt;/P&gt;&lt;P&gt;Radius: Length = 87 (0x0057)&lt;/P&gt;&lt;P&gt;Radius: Vector: A0591EFFCC152A1BB891F6F764CD8293&lt;/P&gt;&lt;P&gt;Radius: Type = 1 (0x01) User-Name&lt;/P&gt;&lt;P&gt;Radius: Length = 3 (0x03)&lt;/P&gt;&lt;P&gt;Radius: Value (String) = &lt;/P&gt;&lt;P&gt;20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Radius: Type = 26 (0x1A) Vendor-Specific&lt;/P&gt;&lt;P&gt;Radius: Length = 40 (0x28)&lt;/P&gt;&lt;P&gt;Radius: Vendor ID = 9 (0x00000009)&lt;/P&gt;&lt;P&gt;Radius: Type = 1 (0x01) Cisco-AV-pair&lt;/P&gt;&lt;P&gt;Radius: Length = 34 (0x22)&lt;/P&gt;&lt;P&gt;Radius: Value (String) = &lt;/P&gt;&lt;P&gt;65 6e 74 69 74 79 2d 61 74 74 72 3a 63 6e 74 6c&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; entity-attr:cntl&lt;/P&gt;&lt;P&gt;3a 6b 65 65 70 2d 61 6c 69 76 65 3d 74 72 75 65&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; :keep-alive=true&lt;/P&gt;&lt;P&gt;Radius: Type = 4 (0x04) NAS-IP-Address&lt;/P&gt;&lt;P&gt;Radius: Length = 6 (0x06)&lt;/P&gt;&lt;P&gt;Radius: Value (IP Address) = 10.2.16.110 (0x0A02106E)&lt;/P&gt;&lt;P&gt;Radius: Type = 80 (0x50) Message-Authenticator&lt;/P&gt;&lt;P&gt;Radius: Length = 18 (0x12)&lt;/P&gt;&lt;P&gt;Radius: Value (String) = &lt;/P&gt;&lt;P&gt;1b c0 0b 2e 52 7a 56 eb c5 b8 80 93 b9 e5 5b 71&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; ....RzV.......[q&lt;/P&gt;&lt;P&gt;send pkt 10.2.16.169/1645&lt;/P&gt;&lt;P&gt;RADIUS_SENT:server response timeout&lt;/P&gt;&lt;P&gt;RADIUS_DELETE&lt;/P&gt;&lt;P&gt;remove_req 0xce7bce7c session 0x3b id 44&lt;/P&gt;&lt;P&gt;free_rip 0xce7bce7c&lt;/P&gt;&lt;P&gt;radius: send queue empty&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ad client config:&lt;/P&gt;&lt;P&gt;---------------------------------&lt;/P&gt;&lt;P&gt;c:\IBF\CLI&amp;gt;adacfg client list&lt;/P&gt;&lt;P&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP/Range&lt;/P&gt;&lt;P&gt;-------- --------------&lt;/P&gt;&lt;P&gt;asa-lab2 10.2.16.110/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c:\IBF\CLI&amp;gt;adacfg client status&lt;/P&gt;&lt;P&gt;Subscribed-IP Sync-Status&lt;/P&gt;&lt;P&gt;------------- -----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the asa config&lt;/P&gt;&lt;P&gt;-------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server AD-agent-16.169 (inside) host 10.2.16.169&lt;/P&gt;&lt;P&gt; retry-interval 4&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt; radius-common-pw *****&lt;/P&gt;&lt;P&gt; no mschapv2-capable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fredy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688146#M536648</guid>
      <dc:creator>fredy.maizelev</dc:creator>
      <dc:date>2019-03-11T20:54:25Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688147#M536654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fredy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please send the output of the following:&lt;/P&gt;&lt;P&gt;sh run aaa&lt;/P&gt;&lt;P&gt;sh run aaa-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly enable the following debugs &lt;/P&gt;&lt;P&gt;deb aaa authen&lt;/P&gt;&lt;P&gt;deb radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly run the following command and let me know the results:&lt;/P&gt;&lt;P&gt;test aaa authen &lt;RADIUS aaa-server=""&gt; host &lt;IP address="" of="" aaa-server=""&gt;&lt;/IP&gt;&lt;/RADIUS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 02:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688147#M536654</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-07-05T02:57:25Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688148#M536659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same problem here.&lt;/P&gt;&lt;P&gt;@Anisha: You can't run test aaa authen on a AD-Agent server groups:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa/pri(config)# test aaa-server authen adagent host x.x.x.x&lt;/P&gt;&lt;P&gt;ERROR: This test is not supported for AD agent server groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm at a loss here, I can't explain why the AD Agent found the ASA and lists it inside the adacfg client list, but the ASA keeps spamming the logg with %ASA-3-3746005.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug user-identity ad-agent gives me spamming of KEEPALIVE packets send to the AD-Agent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 11:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688148#M536659</guid>
      <dc:creator>Tim Schneider</dc:creator>
      <dc:date>2011-07-29T11:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688149#M536661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having the exact same issue and the firewall is disabled on the DC the adagent is installed on. I can authenticate via LDAP, pull user names and groups and even create acl's with the user names...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however the test aaa-server ad-agent adagent against the DC with the adagent on it fails&amp;nbsp; with &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: Ad-agent Server not responding: No error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the adacfg client status shows as being blank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 21:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688149#M536661</guid>
      <dc:creator>nathanfink</dc:creator>
      <dc:date>2011-08-02T21:26:34Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688150#M536663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wasn't able to fix this yet. Hopefully next week when I'm attending a lab from Cisco I'm able to clear up some things here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 09:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688150#M536663</guid>
      <dc:creator>Tim Schneider</dc:creator>
      <dc:date>2011-09-13T09:04:15Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688151#M536665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still not working. Tried this on another machine with Windows 2008, still no AD Agent connectivity...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Nov 2011 14:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688151#M536665</guid>
      <dc:creator>Tim Schneider</dc:creator>
      <dc:date>2011-11-10T14:12:01Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688152#M536667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any other applications or services on the server that act as a RADIUS server? This is not supported since we cannot change the hard-coded port the AD Agent's RADIUS server listens on. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see the AD Agent listening on UDP/1645 in the output of 'netstat -anb | more' on the Windows command prompt?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're still having trouble after this it would be a good idea to open a TAC case and have this investigated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Nov 2011 16:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688152#M536667</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-10T16:54:29Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688153#M536668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Tim Schneider wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still not working. Tried this on another machine with Windows 2008, still no AD Agent connectivity...&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are you using on the AD server as the radius client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've just done a Radius server using the built-in Windows services and it works fine - my ASA config isn't much different to yours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I basically followed this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://fixingit.wordpress.com/2009/09/08/using-windows-server-2008-as-a-radius-server-for-a-cisco-asa/"&gt;http://fixingit.wordpress.com/2009/09/08/using-windows-server-2008-as-a-radius-server-for-a-cisco-asa/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;document - maybe it'll help you out also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 04:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688153#M536668</guid>
      <dc:creator>darren.g</dc:creator>
      <dc:date>2011-11-11T04:42:10Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688154#M536670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Setup information ASDM 6.4 and ASA 5505 with IOS 8.4.3.&amp;nbsp; Radius server running Windows 2008 R2.&lt;/P&gt;&lt;P&gt;I also received the same error message when I test the Radius server group from ASDM:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: Ad-agent Server not responding: No error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have made the following change on my AAA Radius Server Group setting to fix the issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configuration &amp;gt; remote access vpn &amp;gt; aaa/local users &amp;gt; aaa server groups&lt;/P&gt;&lt;P&gt;edit radius server group&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;uncheck&lt;/STRONG&gt; enable active directory agent mode&lt;/P&gt;&lt;P&gt;apply and test.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2012 06:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688154#M536670</guid>
      <dc:creator>steven_lean1u90</dc:creator>
      <dc:date>2012-04-02T06:44:07Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688155#M536672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be it's a bug...(Ethernet interface or ASA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to locate the Agent in the DMZ interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 May 2012 11:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688155#M536672</guid>
      <dc:creator>libriskz</dc:creator>
      <dc:date>2012-05-19T11:12:25Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688156#M536674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to disable MSCHAPv2 support on the AAA-server config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 13:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688156#M536674</guid>
      <dc:creator>hvdhelm</dc:creator>
      <dc:date>2012-11-27T13:58:19Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688157#M536676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did anyone figure this out yet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a similar problem:&lt;/P&gt;&lt;P&gt;test aaa-server ad-agent adagent&lt;/P&gt;&lt;P&gt;Server IP Address or name: 10.5.55.36&lt;/P&gt;&lt;P&gt;INFO: Attempting Ad-agent test to IP address &amp;lt;10.5.55.36&amp;gt; (timeout: 12 seconds)&lt;/P&gt;&lt;P&gt;ERROR: Ad-agent Server not responding: No response from server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run aaa-server&lt;/P&gt;&lt;P&gt;aaa-server AD protocol ldap&lt;/P&gt;&lt;P&gt;aaa-server AD (inside) host 10.5.55.36&lt;/P&gt;&lt;P&gt; server-port 389&lt;/P&gt;&lt;P&gt; ldap-base-dn DC=tagltd,DC=com&lt;/P&gt;&lt;P&gt; ldap-scope subtree&lt;/P&gt;&lt;P&gt; ldap-login-password *****&lt;/P&gt;&lt;P&gt; ldap-login-dn cn=aduser,cn=Users,dc=tagltd,dc=com&lt;/P&gt;&lt;P&gt; server-type microsoft&lt;/P&gt;&lt;P&gt;aaa-server adagent protocol radius&lt;/P&gt;&lt;P&gt; ad-agent-mode&lt;/P&gt;&lt;P&gt;aaa-server adagent (inside) host 10.5.55.36&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh run aaa&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication telnet console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the event log of the domain controller, I see:&lt;/P&gt;&lt;P&gt;"the user account domain cannot be accessed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the server is widnows 2003 and it is not R2. I am using the built-in radius function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Parsed packet data.....&lt;/P&gt;&lt;P&gt;Radius: Code = 1 (0x01)&lt;/P&gt;&lt;P&gt;Radius: Identifier = 77 (0x4D)&lt;/P&gt;&lt;P&gt;Radius: Length = 87 (0x0057)&lt;/P&gt;&lt;P&gt;Radius: Vector: D42E1169F2C9F06E94CCA6183D3BE1CD&lt;/P&gt;&lt;P&gt;Radius: Type = 1 (0x01) User-Name&lt;/P&gt;&lt;P&gt;Radius: Length = 3 (0x03)&lt;/P&gt;&lt;P&gt;Radius: Value (String) = &lt;/P&gt;&lt;P&gt;20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Radius: Type = 26 (0x1A) Vendor-Specific&lt;/P&gt;&lt;P&gt;Radius: Length = 40 (0x28)&lt;/P&gt;&lt;P&gt;Radius: Vendor ID = 9 (0x00000009)&lt;/P&gt;&lt;P&gt;Radius: Type = 1 (0x01) Cisco-AV-pair&lt;/P&gt;&lt;P&gt;Radius: Length = 34 (0x22)&lt;/P&gt;&lt;P&gt;Radius: Value (String) = &lt;/P&gt;&lt;P&gt;65 6e 74 69 74 79 2d 61 74 74 72 3a 63 6e 74 6c&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; entity-attr:cntl&lt;/P&gt;&lt;P&gt;3a 6b 65 65 70 2d 61 6c 69 76 65 3d 74 72 75 65&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; :keep-alive=true&lt;/P&gt;&lt;P&gt;Radius: Type = 4 (0x04) NAS-IP-Address&lt;/P&gt;&lt;P&gt;Radius: Length = 6 (0x06)&lt;/P&gt;&lt;P&gt;Radius: Value (IP Address) = 10.5.2.1 (0x0A050201)&lt;/P&gt;&lt;P&gt;Radius: Type = 80 (0x50) Message-Authenticator&lt;/P&gt;&lt;P&gt;Radius: Length = 18 (0x12)&lt;/P&gt;&lt;P&gt;Radius: Value (String) = &lt;/P&gt;&lt;P&gt;4c 4f 9b 9d 7f 73 96 37 cc 81 16 d9 d8 61 95 be&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; LO..s.7.....a..&lt;/P&gt;&lt;P&gt;send pkt 10.5.55.36/1645&lt;/P&gt;&lt;P&gt;RADIUS_SENT:server response timeout&lt;/P&gt;&lt;P&gt;RADIUS_DELETE&lt;/P&gt;&lt;P&gt;remove_req 0x00007fffa3e3ead8 session 0x40000634 id 75&lt;/P&gt;&lt;P&gt;free_rip 0x00007fffa3e3ead8&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 03:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688157#M536676</guid>
      <dc:creator>Ivaylo Georgiev</dc:creator>
      <dc:date>2013-07-12T03:28:35Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688158#M536678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;'I am using the built-in radius function'&lt;/PRE&gt;&lt;P&gt;Witch built-in radius function are you using? IAS from Windows 2003?&lt;/P&gt;&lt;P&gt;In that case you the ports 1812 and 1813 are allready taken by the radius services from IAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AD-agent is a small radius server by itself. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a common problem with SBS installations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 07:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688158#M536678</guid>
      <dc:creator>hvdhelm</dc:creator>
      <dc:date>2013-07-12T07:54:20Z</dc:date>
    </item>
    <item>
      <title>ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688159#M536679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there are two domain controllers, would it work if we remove IAS from one of them and configure the AD agent there?&lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have access to the controllers so I was hoping I could get some feedback before making that recommendation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 13:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688159#M536679</guid>
      <dc:creator>Ivaylo Georgiev</dc:creator>
      <dc:date>2013-07-12T13:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA-active directory agent problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688160#M536680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can ..&lt;/P&gt;&lt;P&gt;But ... You don't have have to install the AD-Agent on a domain controller! You can install it on any member server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco has a perfect howto: &lt;A href="http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_install.html" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_install.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 13:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-directory-agent-problem/m-p/1688160#M536680</guid>
      <dc:creator>hvdhelm</dc:creator>
      <dc:date>2013-07-12T13:42:04Z</dc:date>
    </item>
  </channel>
</rss>

