Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I'm in the middle of a migration from ACS 3.3 (Windows) to ACS 5.4, and I'm adding some Nexus 7Ks to add to the ACS 5.4.Previously, these 7Ks we're never on the ACS 3.3. The reason, I was told, is because ACS 3.3 didn't support Nexus (NX-OS n7000-s2...
I have a pair of 7206 routers for Internet access. The Internet was provided over OC3, and used interface POS1/0. I just upgraded the Internet to Ethernet so now the interface is GigabitEthernet 0/3.I just discovered that there there is another int...
I have a pair of test ACS appliances running 5.4. We are using AD for our external authentication, the ACS has a proper domain account and has pulled down the AD group list.Recently, I noticed that the domain controllers that the ACS is associated t...
Hi,I have a pair of SNS 3514's running ACS 5.4. They were purchased with a single power supply, and I have since added a second power supply to each one. I'm looking for a way to confirm that the appliance recognizes both power supplies and will u...
Hi,I'm configuring a new ACS5.4 appliance from scratch. My previous ACS was a 3.3 Windows system so we decided to redesign the configuration. You can imagine that the new ACS is very different to me.My question is what is the best approach to settin...
Thanks Tim,That may be. I searched through the 7K documentation and didn't find any mention of not using ACS 3.3, but I didn't search through the bug list. I'll check that out.Ray
Hi Ed,To recap your steps:1. I already have AD groups2. I defined the devices on the ACS, and have new NDGs by sites:Site1-CoreSite1-DistroSite1-Access3. Each device part of the respective NDG (Router, Switch, FW, etc.)4. In the Access Service sectio...
Thanks Ed!I think you've confirmed what I was thinking; Identity groups in this case were just complicating the configuration.I'm going to give this a try and let you know how it works. Ray
Thanks Jennifer & Karsten,Yes you are correct, this wouldn't be the best for a long term solution. The external partner is doing a DR test and has to bring up the VPN tunnel at another location as part of the test. I was just looking for an altern...