cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5124
Views
5
Helpful
3
Replies

TACACS+ on ACS 5.1 and LDAP

HaikoHertes
Level 1
Level 1

Hey Guys,

I've set up a ACS 5.1 Server an want to use it with our LDAP System. Therefor, I'm trying to login to a Cisco 1841 by using my LDAP Account, but it dosent work. The ACS seems not to know that it should use LDAP, because I get:

"22056 Subject not found in applicable identity stores"

LDAP is configured as Identitiy Store, the bind test works successfully and I created a sequence, where LDAP is at first position. What goes wron?? (TATACS for loal ACS Users works)

3 Replies 3

Kent Heide
Level 1
Level 1

I had problems with this on 5.0, but haven't tried on 5.1. I will check it now and post back.

dcmgash
Cisco Employee
Cisco Employee

Hi Haiko,

Did you select the store in the Identity Policy for the service?

(Access Policies/Access Services//Identity

By default the "Internal Users" store is set, you can configure it to go either to your LDAP store directly, or to the identity Sequence you have created.

Thank you dcmgash, this resolved my issue!