<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC 4.7.1 ADSSO can't work on client in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301367#M829298</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two things:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- One of your DC's being returned when we do a nslookup is a 169.254 address. This means that one of your DCs has DHCP enabled on one of it's interfaces and that is also being registered in your AD as a DC. This will cause problems for you, so best to have your AD cleaned up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- You posted the netstat output. I was looking for the unauthenticated role policies. To get those, go to the CAM gui, and click on User Roles, Traffic policies, choose unauthenticated role and hit select. The resulting page is what I wanted to see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Dec 2009 02:48:39 GMT</pubDate>
    <dc:creator>Faisal Sehbai</dc:creator>
    <dc:date>2009-12-16T02:48:39Z</dc:date>
    <item>
      <title>NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301362#M829252</link>
      <description>&lt;P&gt;Dear Sir ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used NAC 4.7.1 and config&amp;nbsp; AD SSO with Windows 2k Server . ( LDAP auth is OK)&lt;/P&gt;&lt;P&gt;The service of&amp;nbsp; SSO is running on CAS , but TCP/8910 port can't be listen .&lt;/P&gt;&lt;P&gt;How should I do open TCP/8910 port and how to fix it ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301362#M829252</guid>
      <dc:creator>beckman.yang</dc:creator>
      <dc:date>2020-02-21T11:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301363#M829264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yang,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should be available when the SSO service is started. Is the SSO service running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you bounced the perfigo service, or the server itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Dec 2009 02:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301363#M829264</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-12-08T02:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301364#M829274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir ,&lt;/P&gt;&lt;P&gt;ADSSO service is running . I had tried service restart on CAS , but can't work on client .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 02:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301364#M829274</guid>
      <dc:creator>beckman.yang</dc:creator>
      <dc:date>2009-12-14T02:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301365#M829283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If SSO service is running, then the next thing you have to look at (if it's failing at the agent) is the ports that are open in the unauthenticated role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post a listing of those?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you also post the output of the following command from your CAS: nslookup &lt;YOUR_DOMAIN_NAME&gt; where your_domain_name is the domain name you're trying to do SSO against.&lt;/YOUR_DOMAIN_NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 16:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301365#M829283</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-12-14T16:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301366#M829290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fyi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Dec 2009 01:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301366#M829290</guid>
      <dc:creator>beckman.yang</dc:creator>
      <dc:date>2009-12-16T01:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301367#M829298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two things:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- One of your DC's being returned when we do a nslookup is a 169.254 address. This means that one of your DCs has DHCP enabled on one of it's interfaces and that is also being registered in your AD as a DC. This will cause problems for you, so best to have your AD cleaned up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- You posted the netstat output. I was looking for the unauthenticated role policies. To get those, go to the CAM gui, and click on User Roles, Traffic policies, choose unauthenticated role and hit select. The resulting page is what I wanted to see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Dec 2009 02:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301367#M829298</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-12-16T02:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301368#M829308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fyi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Dec 2009 05:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301368#M829308</guid>
      <dc:creator>beckman.yang</dc:creator>
      <dc:date>2009-12-17T05:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301369#M829319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please open traffic to ALL your DCs, and not just one, and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't work, try opening ALL IP in the unauthenticated role (just for testing) and see if AD SSO succeeds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Dec 2009 15:14:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301369#M829319</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-12-17T15:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301370#M829324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;I have the same problem and you can see the nslookup result from my CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At Now I could to start the ADSSO Service on CAS but I couldn't see port 8910 opened on CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 May 2010 18:07:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301370#M829324</guid>
      <dc:creator>danielnunes</dc:creator>
      <dc:date>2010-05-13T18:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301371#M829339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The screen shot shows the SSO service not starting. Post your CAS logs so we can see why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 19:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301371#M829339</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-05-14T19:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 4.7.1 ADSSO can't work on client</title>
      <link>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301372#M829349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Faisal,&lt;/P&gt;&lt;P&gt;thanks for your attention,&lt;/P&gt;&lt;P&gt;We had two problems, first of all our AD Domain was with incorrect number IP add, there were more IP address that is necessary and first we made a clean-up there, second thing was that I saw that machines that couldn't make AD SSO because the kerbero ticket does not appear on machine, I used a Kerbtray program to do this, and i could figure out that there were some UDP ports that does not open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this everything works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 20:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-4-7-1-adsso-can-t-work-on-client/m-p/1301372#M829349</guid>
      <dc:creator>danielnunes</dc:creator>
      <dc:date>2010-05-14T20:41:10Z</dc:date>
    </item>
  </channel>
</rss>

