ACS 4.1 dynamic users
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-09-2010 02:58 AM - edited 03-10-2019 05:14 PM
Hello all,
I have some problems with the dynamic users. I want to move them to another group and do some changes on userid, but I also want that they are replicated then. The first is no issue, the second is, since they stay flagged as "dynamic users".
Can this be solved without deleting and recreating them?
Another question --> Can I block the button "remove dynamic users"?
regards,
Patrick
- Labels:
-
AAA

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-09-2010 07:35 AM
ACS won't replicate users previously set for dynamic mapping
CSCsi13785
http://cdetsweb-prd.cisco.com/apps/dumpcr?identifier=CSCsi13785&parentprogra
m=QDDTS
It stated, ACS Database replication may inappropriately flag users as
"learned dynamically" and fail to replicate them in certain cases. If we
modify the group membership for one of these users and explicitly set the
group membership, the user will still fail to replicate to the secondary ACS
server. This is a bug.
This bug was resolved in 4.1.4.13.7.
Based on the above bug, if you make a change for a user present on the
external DB (the user account haven't been manually created on the ACS db)
and not on the internal ACS DB under User Setup, ACS considers it to be
still a dynamically mapped user and thus doesn't replicate it.
Also, you can not block the this tab " remove dynamic users". However, you can restrict user not to access External User Databases section by unchecking the option under administration control >>> click on the user account and disable this option.
HTH
Jatin
Do rate helpful posts-
