cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
624
Views
0
Helpful
1
Replies

Cisco ACS 4.1 unable to authenticate client from DC placed in different forest

Sri v
Level 1
Level 1

I have 2 sites 

Site 1:

Domain - xx.ZZZ.com 

Wifi Authentication - 802.1x via Cisco ACS 4.1

 

Site 2:

Domain - YY.ZZZ.com 

 

All 802.1x authentication works fines when two sites are connected via MPLS but when we migrate the traffic to S2S VPN the below issue occurs 

 

Issue:

Whenever the user moves from Site 2 to Site 1 they are unable to connect wifi and authenticate fails with ACS 

when we further check on ACS, we could see that external database has been configured as windows and both xx & YY domain has been mapped 

 

Note: Via S2S VPN IP reachability is available for across location 

 

Question from myside:

How to check which AD is respective for the respective domain in ACS ?

why does the authentication failure happen for a different domain in S2S VPN only?

 

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

ACS 4.1 is no longer supported. Please migrate to ACS 5.7+ or ISE.

View solution in original post

1 Reply 1

hslai
Cisco Employee
Cisco Employee

ACS 4.1 is no longer supported. Please migrate to ACS 5.7+ or ISE.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: