Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

Labels

Forum Posts

There are two RADIUS servers - Cisco ACS and some freeradius. Both servers are proxy servers for each other - we have on our distribution table their RADIUS as proxy, and they have ours. Problem - we can authenticate to their RADIUS with their userna...

jlipacis by Level 1
  • 1222 Views
  • 1 replies
  • 0 Helpful votes

Hi gurus,Please help:acs (net172.16.1.12)---PIX(10.0.20.1/28)-----(10.0.20.32/28)PIX----NASRouter (Fa0/0 192.168.0.1)--Dial-in User. NOTE: --Between PIX there has 2 network coz go throughservice provider --The Fa0/0 has being NAT-ed to 10.0.20.46. --...

j.hato by Level 1
  • 1310 Views
  • 2 replies
  • 0 Helpful votes

I'm trying to use ACS 2.6 and ACS 3.2 as a radius server to for my Msft win-xp client to do authentication before it brings up its pptp client.To that end, on ACS, I enable the attributes:MS-CHAP-MPPE-Keys (N/A)MS-CHAP-MPPE-Types (128 bit)MS-MPPE-Re...

admin_2 by Level 3
  • 1457 Views
  • 1 replies
  • 0 Helpful votes

Hello,I have a LNS configured to send start and stop accounting messages to the Radius server.It seems some stop messages aren't received by the server.Is there a retransmission timer for the accounting stop messages ?Thanks

guyber by Level 1
  • 1220 Views
  • 1 replies
  • 0 Helpful votes

Which is the behaviour of a LNS in such a situation :A Radius server sends an access-accept with an IP address which is already linked to a PPP session.Does the LNS maintain the PPP session and refuse the creation of a new one, or does it react by de...

guyber by Level 1
  • 1187 Views
  • 1 replies
  • 0 Helpful votes

Anyone have an ini file which adds the packeteer attributes to an acs 3.2 server. I'm having problems with the "=" in the VSA. I'll keep trying but if someone has already done this please send it over.Does Cisco have a site that might already have ...

wes by Level 1
  • 1181 Views
  • 1 replies
  • 0 Helpful votes

Our VPN 3030 Concentrator is sitting in the DMZ zone of our firewall. The ACS is sitting behind the firewall inside our LAN. Our mobile users are authenticated through the ACS server when they wants to establish a VPN connection to our network. Curre...

jliew by Level 1
  • 1179 Views
  • 1 replies
  • 0 Helpful votes

I have on the main site Cisco Secure running and in the remote sites i'm configuring AAA. However i'm not interested on authenticate users to work with the router. What i Need is to authenticate the users to restrict or permit Internet Acceess. How c...

xe1zvo by Level 1
  • 1217 Views
  • 1 replies
  • 0 Helpful votes

Is there a way to allow a particular user to login to a network by means of a predefined path? For example: User A is logging in via a WLAN and has a security profile A. Let's say that user A has very strong security needs. User B wants to use ISDN o...

6tschraml by Level 1
  • 1175 Views
  • 1 replies
  • 0 Helpful votes

Is there a configuration to have a backup authentication for the enable mode for the PIX 501. I currently have a 501 configured to authenticate to a AAA server, but want to have a backup like a local authentication, in case the connection is lost, an...