01-20-2011 12:55 AM - edited 02-21-2020 10:25 AM
Hi,
we have a Nac enviroment with users that are defined on the ACS. Also the groups are defined on this machine.
The problem is that we have to move all the users from the ACS to the domain controller, so all the users will become AD users.
In which way we have to configure the NAC enviroment to permit the authentication via Active Directory instead of Radius that runs on the ACS?
Thanks a lot!
Leonardo
01-21-2011 05:27 AM
01-21-2011 05:42 AM
Great Daniel,
I've already configured a radius server on the "Auth Servers"...can you confirm me that adding a new "LDAP" server will not influence or cause interruption of service for the roles that are already defined?
If I've understood well the "Server mapping" must be done when we create the role...or not?
Thanks!
01-21-2011 06:03 AM
Hi Leonardo,
Not cause any interruption.
In my environment is configured LDAP Auth Server and did not need to map because I'm using just a Role, so this is configured as Default Role in Auth Server settings
Tks
Daniel Stefani
01-21-2011 06:05 AM
So, If It is so...only if you add more than one auth server you chan choose the mapping?
I'm migrating the user from radius (ACS) to LDAP (AD)...so I have a mixed enviroment for some time!!!
01-21-2011 06:20 AM
You have to create a map rule if you have two or
more Roles authenticating in the same LDAP Auth Server
and not if you have two or more auth servers
If the users authenticating today in Radius Server ACS is associated with a single Role XYZ, then you can configure the LDAP Server linking users to the same Role XYZ.
You will have two providers for the same Role.
01-21-2011 06:23 AM
Thanks a lot for the answers! :-)
02-10-2011 02:31 AM
02-10-2011 06:51 AM
Sorry, but i don't know.
Do you intend mapp by groups in AD ?
If you discover, tell us.
Tks
Daniel Stefani
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide