cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
217
Views
0
Helpful
1
Replies
Highlighted
Beginner

Cisco ACS 4.1 unable to authenticate client from DC placed in different forest

I have 2 sites 

Site 1:

Domain - xx.ZZZ.com 

Wifi Authentication - 802.1x via Cisco ACS 4.1

 

Site 2:

Domain - YY.ZZZ.com 

 

All 802.1x authentication works fines when two sites are connected via MPLS but when we migrate the traffic to S2S VPN the below issue occurs 

 

Issue:

Whenever the user moves from Site 2 to Site 1 they are unable to connect wifi and authenticate fails with ACS 

when we further check on ACS, we could see that external database has been configured as windows and both xx & YY domain has been mapped 

 

Note: Via S2S VPN IP reachability is available for across location 

 

Question from myside:

How to check which AD is respective for the respective domain in ACS ?

why does the authentication failure happen for a different domain in S2S VPN only?

 

Everyone's tags (1)
1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: Cisco ACS 4.1 unable to authenticate client from DC placed in different forest

ACS 4.1 is no longer supported. Please migrate to ACS 5.7+ or ISE.

1 REPLY 1
Cisco Employee

Re: Cisco ACS 4.1 unable to authenticate client from DC placed in different forest

ACS 4.1 is no longer supported. Please migrate to ACS 5.7+ or ISE.