cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
756
Views
0
Helpful
2
Replies

Cisco ACS 3.2 Server-based vs ACS 3.2 Appliance

a.kiprawih
Level 7
Level 7

Hi,

Recently we introduced ACS 3.2 appliance to provide redudancy and backup to the existing ACS 3.2 Server (Win2K Server) for wireless access authentication.

The ACS server will forward the authentication request from wireless clients to the Active Directory (co-exist in the same server). Authentication is based on Cisco PEAP+digicert. The server is part of the Domain.

However, the new ACS appliance doesn't seems to work properly despite successfully replicating the configuration, user DB and installing digicert.

Is this due to the requirement for the ACS appliance to join the Domain which is similar to the existing server? So far, the only option available is to install/generate digicert under "System Configuration -> ACS Certificate Setup".

Has anyone experienced this before?

Thanks

Amrih

2 Replies 2

owillins
Level 6
Level 6

I am not sure if this is possible. From what I know, to any group we can apply just one server.

PAUL SHELTON
Level 1
Level 1

In order for the ACS appliance to perform AD authentication, you must install a small program on a member server for the appliance to pass auth info to. ACS uses the AD API that is peresent on every member server to contact AD. That API is not available on the appliance because it is not a full server. So to due AD auth, it must proxy that request to a full server. Check the docs, it will point you to the program you need.