cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
632
Views
0
Helpful
3
Replies

ACS two different domains - WLAN Authentication

markus.fuchs
Level 1
Level 1

Hi Cisco Community,

I have a question regarding support Cisco ACS and two AD Domains. I have found a few interesting discussion, but none answered my questions directly.

We are using the ACS (version 5.3 at the moment) to authenticate our NB to logon to the internal WLAN. At the moment we plan to migrate all user to a complete new AD domain, it's a new forest and a trust exists to from the old to the new one.

The ACS is "joined" to the old one. I understand it has something to do with MSCHAPV2 or not?

Will this work? What would be the best approach to this?

Thank you for your support.

Markus                   

3 Replies 3

edwjames
Level 3
Level 3

Markus,

If its a two way trust, it will work.

IMP: you need to use suffix or prefix for the other domain users that the ACS is not connected to.

**Share your knowledge. It’s a way to achieve immortality.
--Dalai Lama**

Please Rate if helpful.
Regards
Ed

**Share your knowledge. It’s a way to achieve immortality. --Dalai Lama** Please Rate if helpful. Regards Ed

Hi Edward,

thank you for your answer. What do you mean exactly with "suffix or prefix" of the domain users? I did put the "test OU" of the new domain into the ACS config and plan to do a test of a migrated client in the next few days and let you know.

Thank you

CISCO/edward (prefix)

edward@cisco.com (Suffix)

I hope this helps, btw, cisco is the domain.

**Share your knowledge. It’s a way to achieve immortality.
--Dalai Lama**

Please Rate if helpful.
Regards
Ed

**Share your knowledge. It’s a way to achieve immortality. --Dalai Lama** Please Rate if helpful. Regards Ed