cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1375
Views
0
Helpful
1
Replies

ACS -SecurID and Active Directory SSO

jarvoy
Level 1
Level 1

I just installed a 3000 concentrator, ACS and RSA Securid. The concentrator points to ACS as an authentication server. RSA is configured as an external database to ACS, User is defined on ACS with the thier password authentication set to "RSA SecurID Token Server". Everything works great, when a user hits the concentrator they log in with two factor authentication granting them VPN access to our network. But they also need access to Active Directory resources....which require another login. Is there a way to setup ACS so this second login does not happen? Some sort of SSO? Thanks.

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

No. This really has nothing to do with ACS, it is your Windows OS requesting access to resources that require authentication, just like if it was sitting on the local network. You can forget that you're connected in over a VPN at all, cause as far as your Windows OS knows it is just trying to connect to a network resource, it has no idea that it's getting there over a VPN tunnel. This really has nothing to do with ACS or with the VPN3000, so no way around it.