ACS 5.2.0.26 with two areas

I try to spend 4.2 ACS production plant that uses Windows Server installed on GBA as authentication mechanism underlying to 5.2 ACS who joined the field.  I have read several posts and that you have not yet found a solution to my problem.

So, we have a forest/fields of the domain X and is where the ACS server is bound.  We have a domain forest/other Y.  We have two = transitive trust relationship between the two areas.  Users can authenticate correctly if they specify the domain name.  However, if they leave out of the field, only users in the field X can authenticate.

For example, to authenticate the following work:

X\username field

Y\username field

user name - if a domain user name X

What does not work for authentication is:

user name - if a domain user name Y

How can I tell ACS to authenticate users to a list of specific areas, perhaps in a certain order, or perhaps a default domain.  We have many more users in the field Y.  So if I had to define a field by default, I could assign domain Y and tell users in domain X to be sure to put the field on the front.  Otherwise, it seems that I could move the AD link to the domain Y.  However, while the confidence is there, the field is in another University and I prefer to keep the ACS server bound to the domain of X.

When I try to search groups directory, I get only the X domain groups.  I can't even manually type the groups in domain Y.  He accepts, but they do not work.  Inevitably, it results in an error of 22056 object was not found in the point of sale applicable identity. if I omit the domain Y.

Any help is appreciated.  If more information is needed to help, please let me know what you need.

Thank you!

Jodie

Jodie,

Are unique samaccountname across the forest? This seems to be that a kind of trust related question and I have seen this crop up lately, here's an article that might help you identify the type of approval in order to make this work:

https://supportforums.Cisco.com/thread/2162234

Thank you

Tarik Admani
* Please note the useful messages *.

Tags: Cisco Security

Similar Questions

  • How to configure ESX and vCenter with two areas virtualized?

    Hi all

    I'm quite new to VMware please bare with me, I'll try to get to the point.

    I am building a new infrastructure for a customer which will look something like the image below...

    My questions concern vCenter and the best way to install it and configure it, taking into account the environment below.

    (a) is it possible for vCenter to manage these two areas, even if they are completely separate?

    (b) how to configure the physical server Win 2008 in what concerns an area? If both virtual areas have their own domain controllers is to say 'Live-domain' and 'Test-domain' box Win 2008 won't belong to one, so what do I do with it? I can't join the party to another area because it is not a. And I can't let a working group.

    Any advice would be much appreciated

    CMA_MAP.PNG

    That sounds right. Yes, the ESX host will meet your virtual domain controller's DNS information. DNS is very important in an active VMware with HA cluster.

    Virtual domain controllers (and, as a result, DNS) are fairly mundane, no worries, I designed / management of environments that were 100% virtual (incudling vCenter).

    Make sure that you do not enable the option "synchronize time with host" on the virtual domain controller VMware tools. Otherwise, you will have a loop (with VM, VM host synchronization synchronizes with host). The option is disabled by default.

  • My computer with two hard drives and 2 starting systems has the car crash in the solid state. When I got the new drive and tried to restore from time capsule, I lost some data. How can I see what backups are on the time capsule? My laptop is also backed u

    My computer with two hard drives and 2 starting systems has the car crash in the solid state. When I got the new drive and tried to restore from time capsule, I lost some data. How can I see what backups are on the time capsule? My laptop is also saved to the time capsule. Everything is in 'Data' when I look through the Airport utility. I think that the information that I've lost are still there since I was a Capsule 3 to.

    Time Machine backup to a sparsebundle.

    The sparsebundle will use the share name of computer. So, it should be obvious who is your Macbook and that is your Macpro.

    Open the sparsebundle in Finder and keep open the subfolders until you get to the backup of each separate hard drive...

    You has of course set the exclusion in Time Machine?

    By default, Time Machine will exclude your second drive unless you have included it. Did you?

    Once you get to this level during the backup, you can do a full restore manually whenever you want.

  • I am not able to download apps for my iPhone on the App Store. He just 'waiting '. But never starts the download. I tried with wifi and mobile data. The two are not download apps

    I am not able to download apps for my iPhone on the App Store. He just 'waiting '. But never starts the download. I tried with wifi and mobile data. The two are not downloading the applications Can u find out what's wrong? I use iPhone 5s

    I had the same problem. At the same time hold the screen lock button and the home button until your iPhone restarts. That solved the problem for me.

  • I have two vista windows oem sctatch disk at home. You can download it for me, these two are with the product key to the House.

    I have two vista windows oem sctatch disk at home. You can download it for me, these two are with the product key to the House.
    It is upgraded, the other is an integer telling Windows Vista;
    and the little hard up and down, mouse from left to right,.
    or can you please sent a copy of a disc to my address, this is the right path for fixed my windows vista online.
    (try to contact technical support of the direct Vista operating system)
    How about upgrading to windows 7? Give me the vista on 'the base drive OEM' continues for facilities?
    ----------------

    Replacement OEM or software support of system manufacturer in most cases, you must contact the OEM (OEM) manufacturer or the manufacturer of the system directly to replace Microsoft software that was distributed by your computer. However, an exception is made for operating system service pack media *, for which you can contact us directly.

    • Contact information for the manufacturer of the computer, see the Microsoft Web site at the following address:

      http://support.Microsoft.com/default.aspx?pr=oemphone (http://support.microsoft.com/default.aspx?pr=oemphone)
    • If the product has been distributed by an OEM or a system integrator, the product ID contains the letters "OEM". Visit the Microsoft Web site at the following address, select the appropriate product family, and then follow the steps to find the product ID:
      http://support.Microsoft.com/default.aspx?PR=notsureoem (http://support.microsoft.com/default.aspx?pr=notsureoem)
    • For OEM software, the certificate of authenticity (COA) lists the name of the manufacturer of the computer under the software version name. For more information on the certificate of authenticity, see the Microsoft Web site at the following address:
      http://www.Microsoft.com/resources/howtotell/ww/FAQ.mspx#1 (http://www.microsoft.com/resources/howtotell/ww/faq.mspx#1)

      If you have System Builder software, the COA lists "OEM software" or "OEM product" under the software version name.

    * Note Service pack support only includes what is associated with the service pack itself.

    More information: http://support.microsoft.com/kb/326246

    Regarding Windows 7 - frequently asked questions - Upgrade Options
    http://www.Microsoft.com/Australia/Windows/buy/offers/upgrade-FAQ.aspx TaurArian [MVP] 2005-2010 - Update Services

  • I want to move a large number of photos but don't want to unique, click each photo. I know there is a simple control function that allows to select groups of files with ' two'clicks ', as opposed to the selection of each file. Suggestions?

    I want to spend a lot of photos (they are in order) but and do not want to have to click to move each photo. I know there is a simple control function that allows to select groups of files with ' two'clicks ', as opposed to the selection of each file. Suggestions? I know it's apple 101, but I don't remember what order to press the button command, or shift, or other. Thank you

    Select the first file, then hold down the SHIFT key, and then click the last file. Or, select any file in the folder and then press command + A

  • Satellite Pro L40 - how to make a dual boot with two recovery disks

    A small question;
    How to dual boot with two recovery disks ive got with my laptop (Satellite Pro L40)

    discs 1 & 2 are windows vista buisness
    discs 3 & 4 are windows xp profesional
    Disc 5 is updated the bios

    The guy where I bougt garage computer (a metal regular store named expert) says that it is posible with discs tose.
    I have
    I already have a partition, but when I boot from disks, is not has the option to select a partition

    Thanks already

    > Satellite Pro L40 - how to make a dual boot with two recovery disks?
    Short answer: you can't do that. Maybe if you have two hard disks (I tried didn't) but as much as I know your SP L40 has only one.
    Ask this smart guy, how to do this. Maybe it's a useful tip.

  • How to scan a document HP MFP127fn for my Ipad Air2 (the two are connected to my home network)

    Hi, how to scan a document HP MFP127fn for my Ipad Air2?

    The two are connected to my home network - the HP printer is connected by ethernet cable, and the Air2 Ipad connected by WiFi.

    I can print from the Ipad to the printer but cannot scan.

    The printer is properly connected (IE, it scans to another laptop (windows 7) without problems)

    Hi @regtown,

    My bad

    Looks like you won't be able to scan to PC or Mac with this printer. HP ePrint app is certainly compatible via iOS for printing, but it won't help you analyze for iPad.

    Kind regards

  • Can I use with two-step verification account recovery?

    I was reading about how you can use regain access to your account with two-factor authentication.

    Regain access to your Apple ID with two factor authentication - Apple Support account recovery

    Given that two-factor authentication is not yet available for my account, I was looking for to put in place the two-step verification.

    Any type of account recovery is available for users of two-step verification?

    Or this option is available only for users of two-factor authentication?

    Want to add more security to my account, I would like firstly to determine what are the dining options.

    From my understanding, there is not a recovery option to account for users of two-step verification.

    If someone could confirm please would be great.

    "Recovery"?  What are exactly are you afraid to lose and need to recover?  Your password?  No, two-step verification can help.  The approach is quite different from two-factor authentication:

    Frequently asked questions about the audit in two steps for Apple ID - Apple Support

  • Internal matter on the placement of Vias on board four layers with TWO planes of Earth

    My design is a four-layer Board.  Surface upper and lower layers are for routing of traces and power.   Two interior floor plans (the preceding the other separated by an insulating layer) are for all ground connections.  Customer specifies that all ground connections to make for TWO inner floor plans.  When I try to place a via that will connect a trace on the outer surface to the ground, I'm not allowed to connect to more than one internal plan.

    I need to place vias completely through the Board of Directors and connect a trace in inner outer surface for TWO floor plans... Is it possible or assignment that will allow me to do?

    Ultiboard V10.0.144 running.

    Thank you

    Solved my problem.  Do inner Layer 2 the active layer, turn off all other layers.  Internal stressed Layer 2, r/c on the Properties tab copper box, click connected to the Net, drop-down list, choose DGND, apply, OK. Now place a via. R/c, choose Properties, tab, click on assume net, drop-down list, choose DGND, apply, OK.  via moment connects to the inner layer 1 so much inner Layer 2, b/c, the two are now associated with the net DGND.

    Beautiful - thank you...

  • PowerShell in two areas

    a forest, two areas using Exchange 2010.  With the command Get-MailboxDatabase-status to see how many mailboxes in a database, I get only the amount of mailboxes from one of the areas.  What I add to it in order to get the info from these two areas?

    Hi SandyZA,

    For questions about Exchange, visit the Forums of Exchange here.

    Thanks for posting your questions in the Microsoft answers Forum.

  • Trying to replace a XP computer with another XP computer in a peer-to-peer network with two other computers.

    Replace a XP computer with another XP computer in a peer-to-peer network with two other computers. became terribly frustrating. I spent a day and a half by train to get there. I know MS wants everyone to buy their new OS, but I can't afford it right now. In the meantime, I'm trying to add a computer to my existing peer-to-peer network. I have never had so much trouble. I can not get computers to eachother Duke on the network.

    Over the past 3 years I have implemented each of the existing computers. I'm familiar with the silly quirks of this operating system (i.e. a few hours waiting see if eventually the computers will warm up to each other and decide to play nice together). All computers are able to connect to the internet through the same router connection, and I was able to get each of the computers to see one another, but not all, but none of the computers is to see the new computer. (The new computer is connected to ONE of the other computers, but stopped doing and do again it). Is there a simple step by step to do this? I don't care even if I can't not all computers on the network as a whole, I would like to just the computer I replace to see the computer I replace by in order to obtain the transferred files and get back to work.

    I appreciate sincerely ANY help ANYONE can offer.

    Hi okcbz,

    1. How many computers on the network?

    I suggest you have a look at the following links in the article:

    Introduction to Windows Peer-to-Peer network

    How to set up a small network with Windows XP Home Edition (PART 1)

    Windows XP Help & how-to

  • Problem setting up Port Forwarding with two routers.

    I can't set up by Linksys RT31P2 and routers port forwarding WRT160Nv3.

    My setup is Webstar Modem = RT31P2 = WRT160N = Mac OS 10.6.5. (No configurable modem and ISP do not prevent port forwarding. It comes with two Linksys routers).

    I had a Monty Python-going around with the support of Cisco cat; and follow up with telephone assistance in which the agent knew nothing about port forwarding and his supervisor expressed the view that it was not possible with two routers. Sigh.

    If anyone can help me with step by step specific and simple instructions to configure routers. I know that the basic procedures. I'm not clear, what exactly changes on routers.

    I read that portforward.com has to say and it does not work so I must be misunderstanding something.

    The ip address of my computer is 192.168.1.103.  Are the last three digits of this speech concluded the two routers in the area on the port forwarding page? What other changes should be done what router?

    I know the port numbers that I use are OK because I can implement successfully if I connect to one or other of the routers (but not both), and my software of p2p shows port are open.

    Any help and suggestions most welcome.

    If you set up as I have suggested that you have only a single LAN that will be using in your addresses * 192.168.15 case. So in your case:

    1. change the address LAN IP of 192.168.1.1 to 192.168.15.2 WRT.
    2 disable the DHCP server.
    3. connect the LAN of the WRT port to port LAN of the RT.

    That's all. Disable the DHCP server will not affect whatever it is that you're connected LAN - LAN and DHCP server on the RT is still operational.

    After the change, previously the WRT computers may require a reboot to get a new address 192.168.15. *.

    Your computer to which you are transferring must have an IP static and not dynamic (or variable). Check the current IP information on this computer. It must have an IP address like 192.168.15.103, mask 255.255.255.0, gateway 192.168.15.1 subnet and DNS 192.168.15.1 server or maybe two other IP addresses instead. Note DNS servers if you do not 192.168.15.1.

    Then configure a static IP address on the computer. Use something like 192.168.15.10, 255.255.255.0 gateway 192.168.15.1 and the DNS servers you found before.

    After this implement 192.168.15.10 port forwarding.

  • We need heat sinks to be installed en XW8600 with two QC XEON E5450 CPU

    Hello

    I plan to buy a HP XW8600 refurbushied and it does not appear that it has installed radiators.  I wonder if it's a really must have heatsinks installed for this system with two QC XEON E5450 CPU.  I will use this system to host multiple Virtual Machines using VMWare or OracleVM.  It has 32 GB of RAM.

    Appreciate your response and pointers.

    Concerning

    Chandra

    Chandra,

    It is strange that someone would sell the workstation xw8600 without heat sinks.  You really need a heatsink / fan on each processor.  These processors run 80 watts maximum TDP each and so you do not need to worry to buy double height double-fan 'Performance' radiators.  You have to buy the combo single-large heatsink thermal / common fan which is used for the xw6600 and the xw8600 currently going for about $30.00 each, used.  The part number, you can search in eBay, is 446358-001.

    HP had the combo 'double height' radiator/fans available for processors used xw8600 greater than or equal to 120 watts TDP maximum per processor.  Those are double-expensive.

    The process of safely removing the original processors, their cleaning and loading them safely back inside with the proper application of thermal paste (Noctua is my favorite), and then properly attach the new heaters/fans with appropriate screws torque technically maybe is something best left to an expert with experience.  Given your question, suppose you who will hire.

  • Two R810s, each with two 8Gb Fiber Channel HBA + MD3620F + MD1220

    Hi people.

    I am planning an installation on this end, and I'm tender hand in the hope that the community can help me carry this all together.

    To explain, I have two servers Dell PowerEdge R810, each with two 8 GB HBA Fibre Channel adapters.

    I also have a Bay SAN of Dell PowerVault MD3620F 8 Gbps, with two controllers.

    I also have a Dell PowerVault MD1220 DAS SAS Expander Bay.

    I think to connects both R810 servers directly to the MD3620F, in order to consume all ports of four CF on the MD3620F. That is, one in each controller, from two HBAs in each server. (I can do this, or do I need a Fibre Channel switch? The MD3620F has 4 available ports, 2 per controller, so it would seem to be a natural configuration for only these two servers)

    Then, I will link the MD1220 to the MD3620F, so that its readers are also accessible through the two R810s on the link of Fiber Channel 8 Gbps. (what is the process to connect a MD1220 to a MD3620F?)

    Thoughts, tips, suggestions?

    Thank you

    -Wentil

    Hello Wentil,

    Here is a link to our deployment guide. FTP://FTP.Dell.com/manuals/common/PowerVault-md3600f_Deployment%20Guide_en-us.PDF . in the deployment guide, we show how you can do an install direct attach & network attached using a fiber switch.

    Please let us know if you have any other questions.

Maybe you are looking for

  • Nedd support reset password computers desktop bios HP Pavolion P6 2311 l

    Dear support team, I have a PC desktop Pavilion P6, I set the bios password. Then I reset bios password is again empty password and reboot the PC. But PC stills appear need password.i use old password or blank password but incorrect bios. I use deskt

  • Re: Portege 4000 - Hardware upgrades

    First of all, I would like to thank Toshiba to produce this a great product. This Toshiba laptop was bought in September 2001, with Windows 98 installed and runs another 10 years later! It is a great testament to the designers and developers at Toshi

  • E-MAIL: E-mail mysteriously leave main folder "sent"?

    I come home late last night having to check an email I sent a month earlier. This is normally no problem because I save all my emails sent and received. To my horror, when I clicked on the box sent had only 4 emails instead of several hundred! (See s

  • Microsoft Office Mac 2016 - worth it?

    Hello world! I recently bought a Mac and the need for the Office Suite. I downloaded the trial of 2016, the today, 01/27/16, and so far, I do not feel the questions that everyone seemed to have. However, any questions I read everything, was posted Oc

  • What is Vista anti-spyware 2012, is it a virus?

    What is Vista Antispyware 2012?  She has appeared on my daughters computer, who claims to have found several viruses and disabling Firefox...  It is similar to Vista internet security 2011, the Red virus? It won't leave Windows Defender runs, or to u