Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

Labels

Forum Posts

Hello!Could someone explain me what happened when we use user certificate authentication via ACS and AD as an external database.For example i have configured 802.1x with EAP-TLS authentication type. I know enough (i hope :) about EAP conversations be...

asp13 by Level 1
  • 597 Views
  • 1 replies
  • 0 Helpful votes

Hello everybody,this the first time I write on this forum, so please excuse me if I do something wrong.My objective is to authenticate servers in my customer's server farm, so that none can put an unauthorised server in place.I am thinking about usin...

Hi I am looking for a really basic AAA Radius login configuration for my Cat4507 to authenticate to MS IAS.I have reviewed all documentation on cisco website and am clearly having trouble understanding this!!(user error)Btw, I can ping my raduis serv...

makkers by Level 1
  • 751 Views
  • 2 replies
  • 0 Helpful votes

Hello, I am trying to get a remote user to always have the same IP address when they connect to the VPN. Our group is simply pulling from an address pool 10.10.10.1-10.10.10.254. I could not find a way to get a static IP so I created another group...

philhess1 by Level 1
  • 820 Views
  • 2 replies
  • 0 Helpful votes

Hi,I have been able to do a test migration with our ACS. I'm moving the service from an NT 4.0 server to a W2K server by doing a backup and restore then upgrade the W2K ACS from 3.0.4 to 3.3. I've got all the users and groups but how do I get all t...

Hi,My config is:...username user1 privilege 15 password 7 pwd...aaa authentication login vtymethod group tacacs+ local enable... password 7 pwd_vty login authentication vtymethodWhen the Tacacs server disappeared from the network(because of missing r...

aruzsi by Level 1
  • 1365 Views
  • 1 replies
  • 0 Helpful votes

Is it possible to apply a per-user ACL from ACS3.2 to a wired 802.1x port on a 3560?I have got dot1x authentication and vlan assignment working perfectly, when looking at the debug it says it sucessfully applied the per-user acl; however the user can...

will.shaw by Level 1
  • 594 Views
  • 1 replies
  • 0 Helpful votes

Here is the case. We have to deny telnet to group of devices for particalar user. The IP addresses of the hosts are in range from 192.168.1.1 to 192.168.1.5 The following is the TACACS+ server config:user = test { default service = permit login...

When setting up a ACS server to work with a CA to authenticate wireless clients via machine authentication, does the CA need to be an Enterprise CA or can I do it with a standalone CA?Note that for machine authentication, I need to push down group po...

pkapoor by Level 3
  • 535 Views
  • 1 replies
  • 0 Helpful votes