04-01-2005 07:01 AM - edited 03-10-2019 02:05 PM
Set up ACS to authenticate users agains an AD database.
When using an invalid account name to log on to a device (switch), I see "External DB user invalid or bad password" in the ACS Failed attempts log but there is nothing in the Security logs of the AD domain controllers.
How can I verify the user ID / password is passed to AD? (Without using a sniffer).
Thanks!
04-07-2005 07:06 AM
The document Installation Guide for Cisco Secure ACS for Windows Server has more information about installing, reinstalling, and upgrading to Cisco Secure Access Control Server (ACS) for Windows Server, version 3.3.
http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/install/inst02.htm
04-08-2005 07:57 AM
Thanks! I've already read the document before installing and posting.
04-13-2005 07:57 AM
Solution provided by Jasjeet Singh (Cisco TAC)
Workaround for bug CSCdy18833:
Providing you don't want to use the dial check or callback features there is this registry switch to disable the RAS fetch:
HKLM/SW/Cisco/CiscoAAAv3.3/CSAuth/FetchRASInfo = 0 (REG_DWORD)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide