This problem occurs due to the presence of Cisco bug ID CSCef34765.
When Cisco Secure Access Control Server (ACS) for Microsoft Windows version 3.3 has two Lightweight Directory Access Protocol (LDAP) external databases (DBs) listed in this DB order:
Authentication works fine if the user belongs to LDAP-1. But, if you belong to LDAP-2, ACS does not start to query LDAP-2:
The AUTH.log shows this output:
AUTH IAttempting authentication for Unknown User 'XX' AUTH IExternal DB [DServDll.dll]: Starting PAP AuthUser AUTH IExternal DB [DServDll.dll]: Comparing domain name "yy" user name XX' case insensitive AUTH IExternal DB [DServDll.dll]: Domain qualifier section did not match. AUTH IExternal DB [DServDll.dll]:External DS User XX@ZZ PW [----] failed authentication: fffff7fc
For a workaround, first check if there is more than one database included in the Selected Databases list on the Unknown User Policy page.
If yes, then change the order of the databases in that list so that the Windows database is not first.
This bug is fixed in Cisco Secure ACS for Windows version 3.3.2.
In order to download Cisco Secure ACS for Windows version 3.3.2, use the TAC Service Request Tool in order to open a case with Cisco Technical Support.
In order to use Citrix, I followed the instruction in the URL: https://answers.uillinois.edu/illinois.engineering/page.php?id=81722. I selected '3_Tunnel All' when connecting the VPN. However, the connection failed, and I can no longer acce...
I recently purchased a Cisco ASA-SSM-AIP-20-K9 AIP Security Advanced Services Module from eBay and installed it into my Cisco ASA5540 firewall. It is shown properly, using the "show inv" command. I just need help in figuring out how to install...
Hi,We have a schedule ASA (HA) 5585-X up-gradation scheduled for next week end. Current ASA version is 9.1(6)10, & we are planing to upgrade to 9.8(4) 10 version.Please let me know, if i can directly upgrade to 9.8(4)10 version from current 9.1(6)10, ...
Hi, I have a problem deploying firepower 2140. I can't deploy FTD via firesight management center and show me an error "Deployment failed due to communication failure with device". when I checked in Device Manager panel, everything seems good. then I anal...