Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,I have a problem with my Guest NAC server (GNS) - it is rejecting RADIUS access requests from my WLC. Running tcpdump (-i eth0 udp port 1812) confirms that the WLC is sending access requests to the GNS. However, GNS, with all logging configurabl...
Hi,I'm having problems settting up a Guest NAC server to authenticate administrative users against a ACS 5.x server. In the ACS RADIUS Authentication log, I can see the user authentication is successful.In the AAA Diagnostics log, I can see the fo...
Hi,I receive the following error message when the identity source within the identity policy, underpinning the ACS access service I have configured for EAP-TLS, is set to active directory (AD1):“22045 Identity policy result is configured for password...
Hi,I'm trying to set up an IPSec VPN with digital certificate authentication from a Windows 2000 Server running Certificate Services and MSCEP. When I issue the "crypto ca enroll lab4" command I recieve the following error "CRYPTO-6-CERTREJECT: Certi...
Thanks for the response. I had to create a RADIUS attribute with the Service Type set to 6 (Administration) before I could adminster NGS with RADIUS AAA. TACACS support on NGS for AAA would be very helpful!
Hi,I’d like to configure ACS to authenticate and authorise users and computer against AD, which is my authoritative directory service. More specifically, I’d like to setup ACS as described in section 8 of the Cisco ACS 5.3 user guide – from page 8-38...
Hi,When the identity source is set to the certificate services profile I have x509 PKI authentication, but I want EAP-TLS authentication.Are you suggesting that I need to create an identity store sequence to achieve this containing both the AD server...
Hi,I have set enrollment mode to ra and I think I'm receiving the CA & RA certs unless the certificate chain errors are a problem? I have installed the CA as a standalone and can display the chain?r1(ca-identity)#crypt ca authenticate lab4Certificat...