We have loaded a Windows 2000 Member Server in an NT domain with CiscoSecure ACS 3.0. The CS services are all started with an NT domain admins ID.
This system is used to authenticate Internet users (outbound) using TACACS through a PIX firewall.
The ACS works fine with users that have no workstation logon restirictions (meaning they can logon to any workstation). Users that have workstation restrictions fail when ask to authenticate.
We have added the PDC and every BDC as permitted workstations to logon over and above the ACS Windows 2000 server and their own workstation.
Has anyone had a similar problem? Does the ACS unit have to be a domain controller in the accounts domain?
Any help would be greatly appreciated.
Thanks.