5.3 of the ACS cannot work with two rules of service strategy

Hello my name is Ivan

I have a question about ACS v5.3 appliance.

I have a v 5.3 ACS wo authenticate users wireless, as well as a cisco wlc. A profile is to business users and the second profile is invited.

Business users must authenticate with Active Directory and the guest with WLC. Guest users to authenticate with the local database of GBA.

I have set up two service political selection that correspond with the Radius protocol. The first rule is for users to Active Directory and the second is for users in

the local database of ACS.

When I try to authenticate users with active directory is OK, but when trying to authenticate users with the local database (Portal comments) GBA was trying to find the

internal user in Active Directory, because math the first rule and the second profile cannot authenticate.

When I change the order, first of all the State of users internal and second rule of users from Active Directory, internal users can authenticate in ACS, but

in Active Directory users cannot authenticate.

I think that my ACS authenticate only the first rule of the RADIUS to the Active Directory, not two rules of RADIUS at the same time. Or maybe there is a problem in the BONE of the ACS.

Authentication separately is OK.

Please could you help me to resolv this problem?

I enclose my two rules

Concerning

Hello Ivan,.

To solve your problem, you must configure your ACS so that the first selection policy (active directory) corresponds to only for users of the company and the other strategy of selection service (internal users) does not match.

The second strategy selection of service must be only for guest users.

If you use Cisco WLCs, it will be easier for you.

Why?

Because you can use 'End Station filter' easier to match the SSID.

In feature selection policy, you build your game to the fine filter station (add it via the Customize button).

Now, you must create two filters of end station, one is the ssid of comments and one corresponds to the ssid company. (tell how to create later)

After you create the filter end station and match the selection policy of end station filter function, you have a political service selection matches corporate only guest SSID and other SSP the SSID matches.

Now you can select different identity for the two SSP sources.

Now for the filter end of station:

End station filter is used (in our case) to distinguish the SSID.
If I want to separate applications of different SSID, I use the end station filter to match what SSID I use.
cretae end station filter to your SSID, follow the following image:

on point number 4, write resounding brand (*) asteristk of your SSiD (case-sensitive), without spaces. Be sure to avoid spaces before or after.

(I assume you are using cisco WLC. If not, the idea cannot be applied the way I described above).

So far, we're OK, except one point. The default SSID guest is not sent by the Cisco WLC to the radius server when the client tries to connect to it, while the SSID of 802. 1 x is.

To say the WLC to send the guest SSID, you must add this command to the WLC:

RADIUS config callstationidtype ap-macaddr-ssid

I hope I described correctly. Let me know if you got it or if you need more explanation.

Greetings,

Amjad

Rating of useful answers is more useful to say "thank you".

Tags: Cisco Security

Similar Questions

  • Work with two monitors in Premiere Pro.

    Hello

    I'm new in the use of first Pro CC. I would like to know how you set the workspace in first to two screens. In Final Cut Pro X, there is a button where you can set the workspace to work with two screens. Where is this feature in the first? I've not found in "Workspace" or "Preferences". Please, if anyone with a tip, I'm a happy man.

    Kind regards

    Bo

    See if they help you:

    Two monitors

    Dual display

  • My Dell all-in-one 962 stopped printing all of a sudden. The error messages are that the computer cannot communicate with the printer.

    My Dell 962 All In One Printer suddenly stopped to print. I get an error message that the computer cannot communicate with the printer. The error message suggests that I unplug and plug back the power plug and the USB cable to the printer and make sure that there are no restrictions of firewall to the printer. I did what was suggested and still no printing. I have resinstaled the printer from the CD software, I got with the computer and also installed the latest driver using the software of the software upgrade wizard.

    and also installed the latest driver by using the Software Update Wizard software.

    That would not have been the best idea... but it is unlikely that the cause of your immediate problem.

    The next thread does not make much sense to me, but it describes a situation similar to what you described and the proposed solution is supposed to have worked.  Try it and see--> http://en.community.dell.com/support-forums/peripherals/f/3528/t/19483019

    I suspect that what really happens is that the driver has become corrupted.  In many cases, simply reinstall the driver is not fix things; you have to clean the old corrupt driver before installing the new.  Thus, it is more likely that the part "Uninstall" the related response is what is helping rather than playing with services... but go ahead and follow these directions, just in case.  In fact, I suggest that you run under first antimalware scanners before following the tips in the above link.

    If I had not found the link above, that's what I would have suggested (whichrequires that you have Windows XP):

    Often, but not always, the symptoms you describe are caused by a corrupt print job stuck in the queue or a damaged printer driver.  However before you clean things up, on general principles, that you can download, install, update and run full scans with each of these two free programs.

    MalwareBytes AntiMalware

    SUPERAntiSpyware

    Use the free version, not the free trials of "pro" versions  Pay attention during installation uncheck any prechecked boxes that would install some additional third-party programs.

    Do not run the scans at the same time.  Each scan will take a while.  Start one and go do a non-it chore.  Once the scan is finished, leave the program to deal with anything it finds.

    Once done, you can keep or uninstall programs, or both.  If you keep SAS, I suggest to change its default setting does NOT automatically when Windows starts.

    Uninstall all software from Dell to control panel > Add / Remove programs

    Download Microsoft Fixit 50126 impression: http://go.microsoft.com/?linkid=9662904

    Close all running applications (anything with an icon on the taskbar).

    Run the Fixit routine.  Note: The routine Fixit has two modes, light and complete.  It will run in full mode when you check the box "Reset the spooler to print on values."  This will remove all printers, so if you have any other printer installed, I recommend running the Fixit in full mode.  If you have other printers and you do not (necessarily) want to reinstall them, run the Fixit in light mode (box unchecked).  This may work anyway.  You must restart the computer after you run in full mode; you need not restart after the Chase mode.

    After the Fixit has executed and you have restarted if necessary, make sure that the printer is disconnected from the computer and run the installation software.  You will be asked to connect the printer to a suitable place.  You can use the CD that came with the computer or download the software here (which is relatively hard to find, the claims of the main page of the 962 product support it cannot find the drivers)--> http://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverId=R89490

  • How can I work with two icloud ID on the same pc?

    How can I work with two icloud ID on the same pc?

    Define "work".

    What exactly do you want to accomplish?

    You can use the iCloud Panel to connect to iCloud account and use a browser to go to icloud.com and sign in with another account.

  • Hello everyone, I just bought a Thunderbolt Apple display to use with my 2012 15 "27" Macbook Pro, Win10/Bootcamp. Is anyone know the procedure to get the display to work with Bootcamp Windows 10?  I have connected screen but no picture. TY

    Hi all

    I just bought a Thunderbolt Apple display to use with my 2012 15 "27" Macbook Pro Win10/Boot Camp running. Is anyone know the procedure to get the display to work with Bootcamp/Windows 10? Is there a setting in the training Camp that must be turned on to make it work? I have connected screen but could not get a desktop display.  Any help would be really appreciated! TY

    The monitor should have a TB and adapter power connector. The monitor works on both OSX. ? If so, shut down of windows, connect monitor and start Windows. Your TB 2012 monitor is not plug-and-play with Windows.

    Please see ports Thunderbolt and views: frequently asked questions (FAQ) - Apple Support .

    1. the "hot pluggable" Thunderbolt devices using Windows with Boot Camp?

    Thunderbolt hot plugging is supported under Windows 8 or 8.1 on all Macs from 2014 and later.

    For all other Mac computers, Windows 7, 8 and 8.1 scans and active them Thunderbolt devices connected to ports Thunderbolt during the Windows startup process. If your device has been plugged in not at startup, Windows detects not without a reboot.

  • What is the iPad Pro works with an Apple bluetooth keyboard?

    What is the iPad Pro works with an Apple bluetooth keyboard?

    Yes.

  • Cannot install WIndows XP SP3 - wireless adapter does not work with any package of service beyond 2.0

    original title: wireless adapter does not work with any package of service beyond 2.0

    I have an AirLiink 101 wireless adapter.  Anyone know how to change the service pack 3.0 for me to update my Windows XP?   Can not install 3.1 without losing wireless connection.

    Thanks for any help.

    If you are on a wireless connection, try to switch to a wired connection and try the download with Internet Explorer.

    UTC/GMT is 06:49 on Wednesday, April 11, 2012

  • Is the program that works with Wordpress?

    Is the program that works with Wordpress?

    Please take a look at the construction with Adobe Dreamweaver CC WordPress sites

  • How do I change LR5 develop settings to the way they worked with LR4?

    I was uncomfortable with the way in which the development parameters worked with LR4.  Now when I use the brush teeth whitening or soften the skin gives a red tint to the brush, and then applies the adjustment when you tap done.  I prefer the shape of LR4 to apply the adjustment immediately with the brush stroke.  So is it possible to come back?

    Thanks for any help.

    You use the overlay!

    Press O on your keyboard.

  • VMware device with 2 network cards claiming the same IP address with two MAC addresses

    Hello.

    I see messages intermittent my gateway network two MAC addresses associated with a virtual machine running on a 5.5 ESXi host for the same IP address.

    The virtual machine is a MiTel 3300 controller for a VOIP system. the system is configured with two IP addresses, one on the local network and another with a public IP address in the DMZ. In the network configuration of the 3300, I assigned the address LAN IP at 00: 0C: 29:30:B2:B2 and the DMZ IP at 00: 0C: 29:30:B2:BC (Mac for network devices presented by the ESXi host virtual machine).

    On the host, I configured a vSwitch with exclusive access to two physical network adapters on the host machine. The vSwitch is configured with two machine virtual port groups, LAN and DMZ, with access to the physical network interface cards. Tab grouping of groups vSwitch port NIC, I replaced the order of failover of the switch to activate an active NETWORK card only for the Group of LAN ports and the other card NETWORK only for the DMZ port group. (I don't know how the content of the column of networks is determined. Neither is correct for the traffic on the physical switch. If these are configurable, please advise and I'll change the settings). The relevant parameters of vSwitch, groups of ports and VM are distinguished below.

    On the virtual machine itself, through the VMWare host, I assigned 00: 0C: 29:30:B2:B2 for the Group of LAN ports and 00: 0C: 29:30:B2:BC to the DMZ group port (best I can tell, anyway, since the MAC address field annoyingly obscures the last two digits of the MAC address - break if I invert the mapping) (, but all seems OK).

    The goal here is to make sure that MACs of ports vSwitch the 3300 is listening and sending always correspond to the physical ports that are VLAN Tag by the physical switch to ensure the routing. Generally speaking, it seems that what is happening but, intermittently, we cross one-way calls that suggests a problem of routing between us and our SIP trunk provider; coinciding with these incidents, I get an email along the lines of "the security in the network device has detected a conflict of IP address with two or more devices. The period of INVESTIGATION "DMZ. DMZ. DMZ. DMZ' is claimed by the following clients with MAC addresses: ' 00: 0C: 29:30:B2:B2' ' 00: 0C: 29:30:B2:BC'. »

    I did something in the configuration that would lead to this kind of collision intermittent? Have a hacked together a way to do something that could be accomplished in a way that is simpler and more reliable?

    Thanks for any idea that you can offer.

    Kind regards

    J.

    I probably don't fully understand your configuration, but it seems that you are not interested in using the collection of NETWORK adapters in the virtual switch of the VM MiTel 3300.

    If it is correct, why not create two virtual switches, each with a group of port (LAN and DMZ) unique and with a separate connection of (vmnic2 and vmnic1)?

    In general, collection of NETWORK adapters may be used to share traffic between uplinks and ensure that if one of the uplinks connect fails, a virtual machine still has access to the network.

  • Satellite L350 - cannot get the keyboard to work with Vista Home Premium

    I just reinstalled Vista Home Premium 32 bit but can not get the keyboard works. I tried to connect an external keyboard with the same results. I checked the disk manager that says that the driver is working OK I wonder if it could be a problem of system or a hardware problem.

    Any help would be welcome

    Jim

    Try the external USB keyboard.
    If it works correctly, then the internal keyboard works bad and must be replaced.

  • The Cliq will work with a Tmobile Sidekick prepaid?

    I buy a Motorola Cliq on craigslist and I want to know if I get a SIM with the Sidekicks $ 1 a package prepaid day (txting / data unlimited) if it works with the Cliq? And there are features that do not work?

    You cannot use the data plan for anything other than the sidekick sidekick. All data of the sidekick plan is sent to a danger first, in order to use it, you need a sidekick device.

  • SE error message saying the printer cannot communicate with the computer cause of blocked files.

    Original title: DRIVER of PRINTER BLOCKED

    A COMMS. ERROR MESSAGE ME SAYING THAT MY PRINTER CANNOT COMMUNICATE WITH MY PC. AFTER COMPLETING THE USUAL HARDWARE CHECKS THAT I USED THE SERVICE CENTER OF DELL ONLINE THAT REMOVAL OF TWO STATES ' DLEACOMS. EXE' AND ' DLEAWBGW. EXE ' MUST BE RELEASED TO ALLOW MY PRINTER TO WORK.

    I SEE NO REFERENCE TO THESE FILES IN THE WINDOWS FIREWALL AND TO THIS DAY THE ONLY WAY AROUND THIS PROBLEM IS TO REMOVE THE PRINTER AND REINSTALL, BUT IT WORKS FOR A SHORT PERIOD. I USED (BY REMOTE CONTROL) THE STATION OF SOLUTION DELL THREE TIMES BUT EVEN THEY EVENTUALLY REMOVE ALL AND REINSTALL THE PRINTER.

    SOMEONE HAS AN IDEA HOW THESE FILES CAN BE UNLOCKED?

    I suggest to disable CAPS LOCK key since your message is all in the capital and difficult to read. Have you tried to add to the exception in the Windows Firewall? Try also to change your network connection for work or at home instead of public. Also make sure you installed the latest version of the driver and are compatible. Also try to run the tool:

    http://support.Microsoft.com/mats/printing_problems/

    If the problem is not resolved, contact Dell customer service.

  • Issue of operability of the ACS as RADIUS with ASA 5.0?

    Hello

    I'm trying my VPN to get authenticated user with RADIUS (ACS 5.0). and VPN users database is created in AD. Now when I am trying to connect through the Cisco VPN client, I am unable to do so. Infact, I get an error message (through debugging at the level of the SAA for aaa and isakmp) my RADIUS server is DOWN.

    Please let me know is there any compatibility issue with ACS 5.0 on it because everything was working fine on my version 4.2 of the ACS.

    Concerning

    Ritesh

    Ritesh,

    Yes, there is a lack of ACS 5.0 with vpn authentication.

    When you try to connect with the VPN client. you will not see any hits in the follow-up and the views.
    The ASDM logs: you'll see radius server is not accessible.
    Debugs you show RADIUS period.
    This will work with Ganymede.

    Access policy rule was does not. Also, could not use RADIUS as hit CSCsy17858

    http://cdetsweb-PRD.Cisco.com/apps/goto?identifier=CSCsy17858>; Used Ganymede + instead of RADIUS.

    If you want to use the RADIUS then you need to upgrade your version of acs to 5.1

    You can down load patch 9 (5-0-0-21 - 9.tar.gpg) and ADE-OS (ACS_5.0.0.21_ADE_OS_1.2_upgrade.tar.gpg) from the below path:

    Go to Cisco.com > support > download software > Security > Cisco Secure Access Control System 5.0 > Secure Access Control System Software 5.0.0.21 >

    Reference: update of the CSA since version 5.0 to 5.1:
    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.1/installation/guide/csacs_upg.html

    HTH

    Kind regards

    JK

    The rate of useful messages-

  • How does the Macbook 12 '' works with large office files?

    Hi, I am looking to buy the 12 Macbook "", in may daly job most I ask of my current Macbook 13 "pro (early 2011) is to run excel and powerpoint files, but some are larger than 20 MB, some to the top you 80 MB." Then the Macbook 12 '' handle these files? or should I buy the Macbook pro again? The reason why I like the 12 '' is portability, I travel a lot, but I need to work with this type of files.

    The 12 '' Macbook must able to manage these files with the 512 GB of storage.

    It is only 2.03 lb > http://www.apple.com/macbook/specs/

Maybe you are looking for

  • Satellite C650-15IL - international guarantee two or one year?

    Hello I bought laptop Satellite C650-15IL in Israel.The dealer promissed 2 years warranty and 2 years international warranty appears in the description of the product:http://IL.computers.Toshiba-Europe.com/innovation/en/series/satellite-C650-series/1

  • XW4600: RAID Configuration

    Hi, I have a XW4600 workstation with a hard disk of 500 GB.  The technical specifications of the workstation seems to suggest that it can work with a RAID configuration. This is why I would like to add a second hard drive and install RAID for the pur

  • How do you choose which button is in front?

    Hello I am writing a program that will have a what channels to test user input and then will test these channels to see if everything is properly connected.  I also want a light to see if the device is a) tested (blue), b) ended stable and working pr

  • Impossible to upgrade adobe: error 1325

    Original title: upgrades to Adobe etc. When you try to upgrade Adobe, I get an error 1325. I also get messages saying: "there is no disk in the drive, please insert a disk into drive\Device |" Harddisk2 | DR2 "when I open programs such as Windows Mai

  • Dell Support Center hangs in Windows 8

    When I upgraded to Windows 8, Dell Support Center has stopped working. It worked in Windows 7.  When I reinstalled the software, the messages said that it is up-to-date.  My Dell opens, but I get the error message: "my Dell stopped working. A problem