cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
688
Views
0
Helpful
3
Replies

ACS for Windows Server (3.3) and AD External User Database

canghel
Level 1
Level 1

Set up ACS to authenticate users agains an AD database.

When using an invalid account name to log on to a device (switch), I see "External DB user invalid or bad password" in the ACS Failed attempts log but there is nothing in the Security logs of the AD domain controllers.

How can I verify the user ID / password is passed to AD? (Without using a sniffer).

Thanks!

3 Replies 3

owillins
Level 6
Level 6

The document Installation Guide for Cisco Secure ACS for Windows Server has more information about installing, reinstalling, and upgrading to Cisco Secure Access Control Server (ACS) for Windows Server, version 3.3.

http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/install/inst02.htm

Thanks! I've already read the document before installing and posting.

canghel
Level 1
Level 1

Solution provided by Jasjeet Singh (Cisco TAC)

Workaround for bug CSCdy18833:

Providing you don't want to use the dial check or callback features there is this registry switch to disable the RAS fetch:

HKLM/SW/Cisco/CiscoAAAv3.3/CSAuth/FetchRASInfo = 0 (REG_DWORD)