<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco NAC AD SSO in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615296#M811711</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN class="jiveTT-hover-user jive-username-link active_link"&gt;Sanjeev,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was implemented the Cisco NAC in a multi domain environment and works fine until the customer add third AD server on Windows 2008.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you verify that the created user CASUSER is &lt;SPAN class="active_link"&gt;visible&lt;/SPAN&gt; on domain B?&lt;/P&gt;&lt;P&gt;The CASUSER in my opinon must be created on root domain and will be broadcasted to domains A&amp;amp;B.&lt;/P&gt;&lt;P&gt;Do you used LDAP user mapping to roles?&lt;/P&gt;&lt;P&gt;Do you tested that was created user in domain B and verify in site A? It's the simple test for what you want to do.&lt;/P&gt;&lt;P&gt;Which version Cisco NAC have you got?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;DIV class="jive-author"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Feb 2011 10:51:49 GMT</pubDate>
    <dc:creator>wkamil123</dc:creator>
    <dc:date>2011-02-27T10:51:49Z</dc:date>
    <item>
      <title>Cisco NAC AD SSO</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615292#M811630</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need help with configuring CASUser Account for NAC AD SSO in a multidomain enviorment.&lt;/P&gt;&lt;P&gt;We have two child domain (based on region) say A &amp;amp; B. We have created the casuser account in domain A. If a user from Domain A login, everything works fine and they are authenticated.&lt;/P&gt;&lt;P&gt;But the problem starts if some one from domian B tries to login - they are authenticated by AD (checked through kerbtray and net time \set (can't see ticket for casuser account)....the NAC agaent keeps on prompting for username &amp;amp; password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Domain: Windows 20003&lt;/P&gt;&lt;P&gt;Domain functional level: Windows 2000 native&lt;/P&gt;&lt;P&gt;Cisco NAC Agent: Version : &lt;SPAN id="about_appver"&gt;4.8.0.32&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615292#M811630</guid>
      <dc:creator>sanjeev3090</dc:creator>
      <dc:date>2020-02-21T12:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC AD SSO</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615293#M811649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which domain is the master? The domain in site A&amp;amp;B&amp;nbsp; are Windows 2000 native?&lt;/P&gt;&lt;P&gt;Do you configure kerbtray only on master domain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 15:10:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615293#M811649</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-25T15:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC AD SSO</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615294#M811663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which domain is the master? The domain in site A&amp;amp;B&amp;nbsp; are Windows 2000 native?&lt;/P&gt;&lt;P&gt;Do you configure kerbtray only on master domain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 15:10:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615294#M811663</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-25T15:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC AD SSO</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615295#M811685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kamil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you are quering about the KTpass command as kerbtray is just a tool to display the ticket information.&lt;/P&gt;&lt;P&gt;Both A &amp;amp; B are child domains as we don't have any user accounts in root domain. The CAS user account was created in domain A (having multiple DC's in both domain A &amp;amp; B) and we ran the ktpass command for the CASUSER account in domain A. Everything works fine for users created in domain A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our requirement is that when user in domain B are visiting domain A, they can be authenticated as well through NAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 09:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615295#M811685</guid>
      <dc:creator>sanjeev3090</dc:creator>
      <dc:date>2011-02-27T09:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC AD SSO</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615296#M811711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN class="jiveTT-hover-user jive-username-link active_link"&gt;Sanjeev,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was implemented the Cisco NAC in a multi domain environment and works fine until the customer add third AD server on Windows 2008.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you verify that the created user CASUSER is &lt;SPAN class="active_link"&gt;visible&lt;/SPAN&gt; on domain B?&lt;/P&gt;&lt;P&gt;The CASUSER in my opinon must be created on root domain and will be broadcasted to domains A&amp;amp;B.&lt;/P&gt;&lt;P&gt;Do you used LDAP user mapping to roles?&lt;/P&gt;&lt;P&gt;Do you tested that was created user in domain B and verify in site A? It's the simple test for what you want to do.&lt;/P&gt;&lt;P&gt;Which version Cisco NAC have you got?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;DIV class="jive-author"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 10:51:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-ad-sso/m-p/1615296#M811711</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-27T10:51:49Z</dc:date>
    </item>
  </channel>
</rss>

