08-10-2012 06:35 AM - edited 03-10-2019 07:24 PM
Hello everyone
I do have a quick question about Cisco ACS 5.3 and multi domain authentication. How is it exactly handled?
Can I join more than one domain with the ACS server? Or do I still need to configure that bidirectional trust relationship between those AD forests (even with the ACS 5.3)?
Thanks,
Markus
Solved! Go to Solution.
08-10-2012 07:22 AM
Hi,
You can only join acs to a single domain. Here is a thread that will help you identify the trust you will need in order to get this working.
https://supportforums.cisco.com/thread/2162234
Thanks,
Tarik Admani
Please rate helpful posts
Sent from Cisco Technical Support iPad App
08-10-2012 07:29 AM
There could be another solution for the problem that the ACS5 can only join one domain: Query your different ADs through LDAP if possible.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
08-10-2012 07:22 AM
Hi,
You can only join acs to a single domain. Here is a thread that will help you identify the trust you will need in order to get this working.
https://supportforums.cisco.com/thread/2162234
Thanks,
Tarik Admani
Please rate helpful posts
Sent from Cisco Technical Support iPad App
08-10-2012 07:41 AM
Hello Tarik
Thanks you for the quick response. The information in the link is very helpful and I have forwarded this to our windows AD group.
Regards,
Markus
08-10-2012 07:29 AM
There could be another solution for the problem that the ACS5 can only join one domain: Query your different ADs through LDAP if possible.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
08-10-2012 07:44 AM
Hello Karsten
Thanks for the hint, but using LDAP to query the AD has some limitations that I can not work around (if I remember correctly).
Regards,
Markus
08-10-2012 10:46 AM
Markus,
If you are using peap mschapv2 then you can not use LDAP.
Here is the link when it comes authentication protocol and database support -
thanks,
Tarik Admani
*Please rate helpful posts*
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide