cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
186
Views
0
Helpful
1
Replies

Cisco ACS Device Adminstration

Hi All,

 

I am migrating Cisco ACS 4.2 to 5.6 without migration tool. I am  manually configuring ACS 5.6 and I have done following steps.

 

1) Added Cisco ACS group

2)Added Location

3) Added devices

4) Joined to AD

5)Created a identity group

6) Created internal user where same user available in AD.

7) Created Shell profile and Access policy.

 

Now I am authenticate the user but I am getting Command authorization failed.I think I am doing something on creating internal user same as AD.My requirement is to give the permission to user which is available in AD. IN 4.2 I was adding creating users which was available in AD. Kindly help me to configure same.

 

Thanks in Advance..

1 Reply 1

nspasov
Cisco Employee
Cisco Employee

Are you trying to perform AAA based on AD user group? If yes, then you don't need to create an internal user to match the one in AD. Instead, you can configure your ACS server to query the AD group where that user is located. 

Let me know if that does not make sense. 

 

Thank you for rating helpful posts!