02-01-2007 06:10 AM - edited 03-10-2019 02:57 PM
I am testing a Cisco ACS 1113 Appliance V4.0 for Wireless LAN Authentication. I have installed the Windows Agent on a Windows 2003 Active directory Server and I have installed a Certificate on the ACS and intend to use PEAP.
Has anybody been able to get Machine Authentication to work using the 1113 ACS Appliance?
Looking at the Windows security logs it looks like the server is seeing a machine called "CISCO" trying to authenticate. I believe this is the ACS.
02-05-2007 02:06 AM
Can anyone help with this???
02-09-2007 10:50 PM
For ACS to perform Windows authentications we need to specifiy a workstation name.
In AD , the user should have access to all computers.
OR
A computer account named CISCO should exist.
All users that Windows will authenticate have permission to log in to the computer named CISCO.
ACS shows error message only when the user tries to login from a work station he has no permission to log on.
If you are using ACS 4.1 this link will be useul.
We need to enable PEAP machine authentication inside ACS Windows Authentication Configuration.
02-12-2007 08:14 AM
Just to clarify
When a Windows Administrator looks in his/hers security logs it will appear that multiple wireless users are logging in to the same Machine "CISCO".
Is this correct?
When machine authentication is configured the
Windows Administrator will see the Machine account authenticate against AD. The password for the machine account is created
when the Machine joined the Windows domain.
is this correct?
Does creating the machine account CISCO represent a security risk?
02-14-2007 03:50 AM
The Windows Administrator see multiple wireless users are logging in to the same Machine "CISCO" .
As far as i know there has been no security incidents related to this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide