<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with NAC and Active Directory in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570777#M770087</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like Faisal said, you've got to open a bunch of ports to each AD domain controller for AD SSO to work.&amp;nbsp; It's like 8 or so ports, some TCP, some UDP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Oct 2010 18:43:57 GMT</pubDate>
    <dc:creator>csmgdswafford</dc:creator>
    <dc:date>2010-10-27T18:43:57Z</dc:date>
    <item>
      <title>Problem with NAC and Active Directory</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570775#M770085</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please I need help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my server with the "Active Directory SSO" started, but when a user try to connect to the network with his credentials that have in the Active Directory, the agent PC say that "Invalid username and password"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My server is listening by the port 8910.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have conectivity with the cas and the active directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the command kpass runs sucessfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570775#M770085</guid>
      <dc:creator>jmanzur1683</dc:creator>
      <dc:date>2020-02-21T12:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC and Active Directory</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570776#M770086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If service is running, then you need to focus on the client/AD communication and see where the break is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you make sure that in the Unauthenticated Role, you have all the required TCP/UDP ports open, along with ICMP and IP FRAGMENTS to all your Domain Controllers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If you find this post helpful, please rate so others can find the answer easily&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2010 03:43:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570776#M770086</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-10-22T03:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC and Active Directory</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570777#M770087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like Faisal said, you've got to open a bunch of ports to each AD domain controller for AD SSO to work.&amp;nbsp; It's like 8 or so ports, some TCP, some UDP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2010 18:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570777#M770087</guid>
      <dc:creator>csmgdswafford</dc:creator>
      <dc:date>2010-10-27T18:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC and Active Directory</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570778#M770088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I have the following ports open. In the Unauthenticated role&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP: 88,135,389,445,636,1025,1026&lt;/P&gt;&lt;P&gt;UDP: 0,8,88,123,137,389,636,3268,8910&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I have the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to mention that the command "netstat -a | grep 8910"&amp;nbsp; is not listening, but in the server the service of Active Directory is stared.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thks!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="stock"&gt;&lt;TBODY&gt;&lt;TR title="88(Kerberos), 135(RPC), 389(LDAP), 445(SMB), 636(LDAP), 1025(RPC), 1026(RPC)"&gt;&lt;FORM&gt;&lt;TD&gt;:88,135,389,445,636,1025,1026,8910&lt;/TD&gt;&lt;TD&gt;&lt;INPUT id="fromcheck" name="fromcheck" type="hidden" value="1" /&gt;&lt;/TD&gt;&lt;/FORM&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE class="stock"&gt;&lt;TBODY&gt;&lt;TR title="88(Kerberos), 135(RPC), 389(LDAP), 445(SMB), 636(LDAP), 1025(RPC), 1026(RPC)"&gt;&lt;FORM&gt;&lt;TD&gt;:88,135,389,445,636,1025,1026,8910&lt;/TD&gt;&lt;TD&gt;&lt;INPUT id="fromcheck" name="fromcheck" type="hidden" value="1" /&gt;&lt;/TD&gt;&lt;/FORM&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE class="stock"&gt;&lt;TBODY&gt;&lt;TR title="88(Kerberos), 135(RPC), 389(LDAP), 445(SMB), 636(LDAP), 1025(RPC), 1026(RPC)"&gt;&lt;FORM&gt;&lt;TD&gt;:88,135,389,445,636,1025,1026,8910&lt;/TD&gt;&lt;TD&gt;&lt;INPUT id="fromcheck" name="fromcheck" type="hidden" value="1" /&gt;&lt;/TD&gt;&lt;/FORM&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2010 22:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570778#M770088</guid>
      <dc:creator>jmanzur1683</dc:creator>
      <dc:date>2010-10-27T22:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC and Active Directory</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570779#M770089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm... what's your deployment model?&amp;nbsp; Inband, OOB, real-ip gateway, etc?&amp;nbsp; Also, can you authenticate w/o the use of AD SSO (such as via RADIUS to an ACS box).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Oct 2010 11:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570779#M770089</guid>
      <dc:creator>csmgdswafford</dc:creator>
      <dc:date>2010-10-28T11:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC and Active Directory</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570780#M770090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean the CAS is not listening on 8910 or your DC is not listening on 8910?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not that this will solve your problem but try 'nestat -an | grep 8910', it is probably translating it to the name of the port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a auth server of type active directory (non-sso)? See if that works, otherwise we probably need to start by looking at the agent logs from a host attempting SSO.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Oct 2010 19:26:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570780#M770090</guid>
      <dc:creator>Elly Bornstein</dc:creator>
      <dc:date>2010-10-28T19:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC and Active Directory</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570781#M770091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN&gt;Thank you all.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;was a certificate problem. &lt;/SPAN&gt;&lt;SPAN&gt;but the funny thing is that even I do not listen on port 8910.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Nov 2010 19:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-and-active-directory/m-p/1570781#M770091</guid>
      <dc:creator>jmanzur1683</dc:creator>
      <dc:date>2010-11-23T19:36:46Z</dc:date>
    </item>
  </channel>
</rss>

