cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1412
Views
0
Helpful
2
Replies

802.1x with ACS and Windows AD

Hi

Im trying to setup 802.1x with ACS 5.2 but am struggling as its very differnet to ACS 4.2.

I have setup the ACS to be the domain and think i have setup up the External Idnetity Store, however when i try to authenticate a pc using authentication Medthod 'PEAP (EAP-MSCHAPv2), i get a failure reason '22056 Subject not found in the applicable identity store'

Marco

1 Accepted Solution

Accepted Solutions

alex.dersch
Level 4
Level 4

Hi Marco,

i guess you've missed a mapping configuration in the Access Policy Section.

Create a Access Service name it AS-802.1x select User Select Service Type and select Network Access. Select the Policy Structure Identity and Authorization. Select PEAP as allowed Protocol. Click Finish

You'll see the new service click Identity.

Select the identity source you've created then save.

Click on authorization

Select a default authorization rule permit access and save.

Create a Service Access Rule name it 802.1x

Select Protocol Radius as Condition and as Compound Condition select RADIUS-IETF:Service-Type match Framed then select the service you created before.

then you can try again.

regards

alex

View solution in original post

2 Replies 2

alex.dersch
Level 4
Level 4

Hi Marco,

i guess you've missed a mapping configuration in the Access Policy Section.

Create a Access Service name it AS-802.1x select User Select Service Type and select Network Access. Select the Policy Structure Identity and Authorization. Select PEAP as allowed Protocol. Click Finish

You'll see the new service click Identity.

Select the identity source you've created then save.

Click on authorization

Select a default authorization rule permit access and save.

Create a Service Access Rule name it 802.1x

Select Protocol Radius as Condition and as Compound Condition select RADIUS-IETF:Service-Type match Framed then select the service you created before.

then you can try again.

regards

alex

Alex

Thanks. That is what i was missing.

Found another link on there that was having the same problem.

Document is located here

https://supportforums.cisco.com/docs/DOC-13545. though not sure if can donwload it properly but if do a google search for the document name, you can then download from there