cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1757
Views
0
Helpful
3
Replies

Embedded NT groups won't LEAP authenticate

mabouchard
Level 1
Level 1

I have a group mapping in ACS to a Windows 2000 Active Directory Group. If I add the NT users individually to the NT group they are able to authenticate with LEAP just fine. If I add the same users to an NT group and add that NT group to the ACS mapped group it will not let the users authenticate with LEAP. Does anyone officially know if it is supported?

3 Replies 3

ovanjara
Cisco Employee
Cisco Employee

Hi,

Authenticating LEAP to an external NT or AD domain should work fine and is supported.

BTW, can you authenticate any other devivces to the external database? What do the failed attempts log show?

Thanks,

Obaid.

mhoda
Level 5
Level 5

Hi,

-Where is the ACS installed (Member Server or on the domain controller)

-Version of ACS?

-Server (NT/2K) where ACS is installed?

-Is it system local admin under which ACS services are running ? Or the domain Admin account?

Pl. use radtest/tactest to simulate authentication packets from/within the server and see if authentication succeds. This link will help you troubleshooting this issue further.

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a00800afec1.shtml

Thanks,

Mynul

Also, whats the main domain (is it NT or AD)? Are you authenticating against a different domain? Thanks,

Mynul