cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
629
Views
0
Helpful
1
Replies

Password expire - IOS

sgramos
Level 1
Level 1

I'm integrating remote user with windows active directory. My AAA client is a Router IOS with radius protocol, it "speak" with Cisco ACS 3.3. When a user has to change a password, bc it has expiry, the user can't authenticate and the ACS logs says "Windows user must change password" but it dosen't show in the user's pc.

For example in VPN3000 there is a command "Radius Expire" to permit change password, are there a similar commands to config the IOS router with radius or tacacs+?

Thanks a lot. Santi.

1 Reply 1

didyap
Level 6
Level 6

I would suggest turning on the user/password audit trail in Microsoft. It will show if the request is coming to Microsoft or not. If it does, then its a problem with AD policy.