<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC ADSSO doesn't work in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954945#M745079</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It worked. I was missing the VLAN mapping.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_auth.html#wp1158789" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_auth.html#wp1158789&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jun 2008 13:09:33 GMT</pubDate>
    <dc:creator>yprasannas</dc:creator>
    <dc:date>2008-06-11T13:09:33Z</dc:date>
    <item>
      <title>NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954940#M745074</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I have 1 CAS and 1 CAM. Everything works fine if I use localDB authentication.&lt;/P&gt;&lt;P&gt;I tried to complete SSO AD configuration, from CAM installation guide. SSO service started to work successful. I'm trying to login to the domain - It's ok, I see green kerbtray icon, tickets are ok, but anyway I receive CCA Agent login/password screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AD logging looks like: (172.16.13.100 is AD server)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mar 14, 2008 1:10:00 PM com.perfigo.wlan.jmx.admin.GSSServer loginToKDC&lt;/P&gt;&lt;P&gt;INFO: GSSServer - SPN : [cisco/&lt;A href="mailto:computer-c.zozo.gov@ZOZO.GOV" target="_blank"&gt;computer-c.zozo.gov@ZOZO.GOV&lt;/A&gt;]&lt;/P&gt;&lt;P&gt;Mar 14, 2008 1:10:00 PM com.perfigo.wlan.jmx.admin.GSSServer buildKDCList&lt;/P&gt;&lt;P&gt;INFO: buildKDCList - KDC-1: computer-c.zozo.gov/172.16.13.100&lt;/P&gt;&lt;P&gt;Mar 14, 2008 1:10:10 PM com.perfigo.wlan.jmx.admin.GSSServer loginToKDC&lt;/P&gt;&lt;P&gt;INFO: GSSServer - KDC(s) : [172.16.13.100]&lt;/P&gt;&lt;P&gt;Mar 14, 2008 1:14:22 PM com.perfigo.wlan.jmx.admin.GSSRetrier$RetrierTask run&lt;/P&gt;&lt;P&gt;INFO: GSSR - Windows SSO is running&lt;/P&gt;&lt;P&gt;Mar 14, 2008 1:19:22 PM com.perfigo.wlan.jmx.admin.GSSRetrier$RetrierTask run&lt;/P&gt;&lt;P&gt;INFO: GSSR - Windows SSO is running&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's may be wrong in my configuration? Local time on CAM, CAS and AD is the same, TCP/8910 in CAS is in listening mode. I opened full IP from * to my AD Server for Unauthenticated Role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Andrey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954940#M745074</guid>
      <dc:creator>a.goldstein</dc:creator>
      <dc:date>2020-02-21T09:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954941#M745075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ooops, I found the problem.&lt;/P&gt;&lt;P&gt;Workstation OS version was w2003server. With w2000wks and XP my configuration is working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Andrey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2008 15:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954941#M745075</guid>
      <dc:creator>a.goldstein</dc:creator>
      <dc:date>2008-03-14T15:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954942#M745076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having issue with AD SSO. CAS talks to AD because the service is started. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I can login to the domain but the NAC agent displays the window..Windows domain authentication but gives me a username and password window with drop down box as LOCAL DB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 May 2008 16:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954942#M745076</guid>
      <dc:creator>yprasannas</dc:creator>
      <dc:date>2008-05-30T16:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954943#M745077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you created an Authentication Server for your AD SSO?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log on to CAM&lt;/P&gt;&lt;P&gt;User Management -&amp;gt; Authentication Server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 14:19:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954943#M745077</guid>
      <dc:creator>gojericho0</dc:creator>
      <dc:date>2008-06-02T14:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954944#M745078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you verify User Login Page content setting to include "Available Providers"?&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_pages.html#wp1095025" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_pages.html#wp1095025&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2008 02:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954944#M745078</guid>
      <dc:creator>vinhtran427</dc:creator>
      <dc:date>2008-06-11T02:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954945#M745079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It worked. I was missing the VLAN mapping.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_auth.html#wp1158789" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_auth.html#wp1158789&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2008 13:09:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954945#M745079</guid>
      <dc:creator>yprasannas</dc:creator>
      <dc:date>2008-06-11T13:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954946#M745080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello yprasannas...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having the same issue with AD SSO...Loging into the domain is ok, but we set the CCA Agent login/password screen as well...We also configured vlan mapping as well, but no luck...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed vlan mapping fixed your issue, what other things did you do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Aug 2008 17:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954946#M745080</guid>
      <dc:creator>mrSS</dc:creator>
      <dc:date>2008-08-04T17:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954947#M745081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you running OOB Layer-3 with Real-IP gateway? Are you running 4.1.3? Are you using Certificate Authority? If the answer is yes to all.  You may want to review this &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/413/413rn.html#wp74768" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/413/413rn.html#wp74768&lt;/A&gt;.  Be careful though, you may also need to apply an egress ACL to block trusted vlan from sending TCP-8910 to the FQDN of the OOB-CAS's Untrusted IP.  Otherwise, the CCA agent may continue to send TCP-8910 to CAS and process SSO and refresh IP continuously(looping process).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Aug 2008 22:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954947#M745081</guid>
      <dc:creator>vinhtran427</dc:creator>
      <dc:date>2008-08-04T22:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954948#M745082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i answered yes to the first 2...not sure about the certificate authority...ill take a look at the link and update....thanks for the response&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2008 13:47:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954948#M745082</guid>
      <dc:creator>mrSS</dc:creator>
      <dc:date>2008-08-05T13:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAC ADSSO doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954949#M745083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having an issue with Windows Server 2008 Datacenter Core 2 64Bit and AD SSO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting the “Client not found in Kerberos database (6)” error I confirmed that the customer has the KB951191 hot fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC is saying it is not supported on Windows 2008 64Bit although their documentation says it IS supported with the new v4.7.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone else running 2008 64 with issues similar?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Dec 2009 22:53:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-adsso-doesn-t-work/m-p/954949#M745083</guid>
      <dc:creator>manfernandez</dc:creator>
      <dc:date>2009-12-01T22:53:04Z</dc:date>
    </item>
  </channel>
</rss>

