cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

330
Views
0
Helpful
1
Replies
jcartier
Beginner

ACS 4.0 TACACS+ - Two Domains

Hi All,

Just troubleshooting an issue here...I have two forests....with top level domains...DomainA1 and DomainB1...

The Cisco ACS is installed on a server inside DomainA1..

Users like JohnSmith.DomainA1 and JaneSmith.DomainB1 are able to authenticate off the Cisco ACS Server, which in turn passes this to the Windows AD just fine.

Users within the child domains of DomainB1 fail authentication....so a user like DomainB1.ChildDomain.MarkSmith...

I've confirmed that we have a trust between the two forests (ie DomainA1 and DomainB1)..

Does that carry over to the child-domains of the other forest (DomainB1)?

Do I need a trust between the specific child-domains to the domain that the Cisco ACS server is installed on?

1 REPLY 1
Yudong Wu
Rising star

Create
Recognize Your Peers
Content for Community-Ad

ISE Webinars


Miss a previous ISE webinar?
Never miss one again!

CiscoISE on YouTube