ACS 5 + bookmarklet proxy server requires authentication

Hello

I'm curious to know if the following scenario is possible:

I have 2 x ACS 5 +, located on different subnets. I have a MR configured to authenticate on the 1st two ACS systems. A user tries to connect to MR. If the 1st ACS can not find this specific user in its database (internal or external), is it possible that 1st ACS to send a request for 2 GBA, so it can check is the database?

Each ACS has a different user database (for example users the first GBA will be not be configured on the other and vice versa).

Someone has heard strange at this thing? It is possible (at least in theory)?

I'm always looking here and on the Internet, but until now, I couldn't find anything related to this kind of concept.

Thank you!

Hello hug,

Never saw its use, but if you want to do it for RADIUS authentications I guess it would be possible by:

1 configuration ACS 2 as identity on ACS 1 RADIUS server

2. you set up a sequence of identity store, based password and select the internal users and servers Radius ID defined earlier as authentication servers. They will be checked in a top down approach until the first authentication succeeds. Please refer to the screenshot:

Don't know what version of ACS that you use, so I'm including 5.2 links to documentation.

Stores of radius of ID:

http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/users_id_stores.html#wp1181773

Sequences of store ID:

http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/users_id_stores.html#wp1054132

I hope this helps!

Best regards

Bernardo

Tags: Cisco Security

Similar Questions

  • Set the Proxy Server for Web services

    Hello

    I am trying to create a web service via the WSDL Wizard (Apex 4.0.2). We are behind a firewall and connect to the internet through a proxy server. The proxy server requires authentication with a user name and password. Does anyone know how to include the user name and password to set the Proxy Server in the Application definition page or possibly in another location on the page of the Web Service Wizard of manual? I guess the basic definition of the proxy server's [http://]host[:port]]

    Thanks in advance,
    The

    You can add your user name and password to the definition of the proxy server. Then it will look like
    http://:@:

  • Authentication problem of proxy server for the domain while accessing internet users?

    We have a problem in my company with the proxy server.

    We have an Isa proxy server to restrict some users who access the internet

    allow us some users and sites for them to access

    but some times it requires authentication for all users who have access also. At that time they keep calling us. so I created a temporary rule to allow all traffic for all users. After awhile, we disable and it is working... but in some cases allow same temp rule also does not work so we say - join the domain and join the domain again...

    It seems that these are all temporary, full-time for us of how, it became

    Is there a permanent solution to this problem...

    Please help us solve this problem

    Thank you and best regards,

    Hi jagdeeshk,

    Your question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please post your question in the TechNet Windows Server forum.

    http://social.technet.Microsoft.com/forums/en-us/winservergen/threads

  • Suddenly cannot send email, I get error message saying: an error has occurred when sending mail. The mail server responded: authentication is required before to

    Thunderbird has worked perfectly on 9/3. This morning all of a sudden I can't send e-mail. The message is: an error occurred while sending mail. The mail server responded: authentication is needed before sending it [R0107005]. Please make sure that your e-mail address is correct in your e-mail preferences and try again.

    I made no changes between 9/3 and 9/4

    any help appreciated, have been using Thunderbird for many years.

    Jerry

    problem solved. a message to update thunderbird stood, updated and now works. WOW!

  • Why Firefox 18 behind a proxy server refuses all connections https?

    I used to have Firefox 17 and everything worked ok but I just installed Firefox 18 in my environment of Windows XP sp3 and I can't connect to https through proxy of the company sites.
    Company proxy requires LM/NTLM authentication, the proxy server is a machine IPCOP (squid proxy.)
    After the update to Firefox 18, for all sites that uses an https connection, the answer is:
    The proxy server refuses connections

                  Firefox is configured to use a proxy server that is refusing connections.
     Check the proxy settings to make sure that they are correct.
     Contact your network administrator to make sure the proxy server is
       working.
    

    Squid log shows lines with connection refused because of required authentication (domain/username and password) settings
    1357912572.640 1 (my IP) TCP_DENIED/407 1586 CONNECT www.orange.ro:443 - NONE/text/html
    As you can see no domain/username were filled in the newspaper.
    Here is a line with authorization from another browser
    1357920874.657 1348 (my IP) TCP_MISS/200 2549 CONNECT www.orange.ro:443 (mydomain\myusername) DIRECT/109.166.184.137-
    I changed the sensitive data

    Thank you

    I see a lot of proxy problems reported by users of Firefox 18. If you're not the only one with this problem.

    For now, I advise you to go back to Firefox 17.0.1 until Mozilla fixes this bug.

    Link:

    http://www.Mozilla.org/en-us/products/download.html?product=Firefox-17.0.1 & OS = Win & lang = en-US

    http://www.Mozilla.org/en-us/products/download.html?product=Firefox-17.0.1 & os = OSX & lang = en-US

  • Unable to access the store using the proxy server.

    I'm in Windows 8. I'm unable to access the app Store. He said:-"we were not able to connect to the Store.This could not have come because of a problem with the server or the connection network has expired. Please, wait a few minutes and try again.and some other applications also. I use a 1.1 proxyserver (squid) that requires basic authentication.
    However I m able to use some of them as weather, maps, etc.

    I read solutions who suggested to temporary disable firewall and antivirus for test, I even try it but fails again.

    Other suggestions where has been going for windows 8.1 upgrade level, but how can I get this update, as it is downloaded in store that I can't access. Help, please.

    Hi Anand,

    Your computer is connected to a domain?

    Using a proxy server can allow the administrator to limit access to the Internet.

    You can reduce the effect of these problems by allowing unauthenticated through your proxy server access. We recommend that you enable unauthenticated access only for connections to URLs used by each application that has a problem. Some proxy servers may suggest that you create a list of URLs (also known as the 'white list') permissions.

    Please refer to the article to address these issues that relate to the use of Windows Store apps or use of Microsoft applications that are included with Windows Update or Windows 8, you can include the addresses mentioned in the article in a list of permissions ('white list') on your proxy server and enable HTTP and HTTPS access for them :

    The use of proxies authenticated with Windows 8

    For more information, see the article:

    Using the Proxy selection and Proxy bypass lists

    You can also consult the steps by Rajesh Govind, Support Engineer, may 4, 2013 and check.

    Windows 8 apps not able to detect the proxy for my machine settings.

    Hope the helps of information. Let us know if you need help with Windows related issues. We will be happy to help you.

  • When I try to start firefox I get a message that says proxy server refusing conections

    problems last night macafee said something was trying to download on my computer wanted t allow I said no then everything froze for a few minutes, when everything was closed and I try to restart firefox, I got the proxy server message refusing to connect, I tried to turn on and turn on my computer but still got the same message tried to restore the system , but only date I was given was 07/07/2010 so that not help do not know what to do to solve the problem

    This has happened

    Each time Firefox opened

    == 7 July about 18:00

    This solution for firefox but there is always something wrong I tunes says it can not connect to store in fact everything which requires the connection to the network will not work, will not allow a connection

  • Netflix cannot show films due to server or proxy server problems when using Windows Media Center. How can I solve this?

    I can access Netflix without a problem, but when I select a movie to watch and click on play, a window opens stating could not display the page, the server is not responding or is something wrong with the proxy server.  Try again later or contact your administrator for assistance.  I closed the program and all over again and still get the same message.  How can I solve this problem?

    Hello

    1. What is the exact error message?

    2. are you on a computer in the domain? If not, is that your ISP requires a Proxy Server client?

    If so, you should contact your ISP for Support of parameters appropriate Proxy Server client.

    If you are on a domain, you must check with the person supported on the local network to the appropriate client Proxy Server settings.

  • Software exists for the creation of a 'virtual' network card and going to all the traffic on the local network through a proxy server, then by this adapter?

    I can access net through LAN and my college requires a proxy for all access to the internet. If you want to use the internet, it is impossible to do not use a proxy. This is a problem for many programs that do not seem to allow you to enter the proxy settings.

    any software is to create a 'virtual' network adapter that will pass all traffic network (or any protocol x traffic) through the proxy?

    So I have do not need to enter the proxy anywhere... and I have normal internet access.
    What I saw is possible with OpenVPN, but it is a vpn service that I need .i just want to use the feature. In OpenVPN I just enter my proxy server in its framework and OpenVPN to connect to a VPN service and routes all traffic to the FAUCET adapter after which I don't need to set the proxy address anywhere... so my idea is how can I use only the last part that is routing all my LAN traffic to a virtual card.

    Support the LAN---> proxy---> virtual adapter--->, then software I access the net

    That's what I like to do...

    Although I am facing this problem on Windows 7, solutions for all operating systems are welcome.

    P.S: Proxifier is not my solution to not offer something like this.

    Hi Sapan,
    Thanks for posting in the Microsoft community!
    You can use your favorite search engine and look for the software that meets your requirements.

    WARNING: Using third-party software, including hardware drivers can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the use of third-party software can be solved. Software using third party is at your own risk.

  • Popup on XMLHttpRequest for 'requires authentication' - Webworks on BB OS 5.0 +.

    Hello

    In my app Webworks for OS 5 +, I do multiple XMLHttpRequest calls to my server for you to connect, pull down, etc.  The usual.

    Occasionally and without apparent motive (and not always the first time after starting the app.) Not only the queries. ) I have will get a popup with something in the sense of 'this page requires authentication, enter the user name and password' and then request for domain, user name and password.

    However, I can just regularize and try again and it works perfectly.

    Anyone have experience with this and know what is possibly cause it or a fix?

    Or any portrait?  I'm stumped at the moment.

    This does not only happen on real devices, however.  I saw not in ripple (not provided) or the emulator.  Unfortunately, my curve doesn't seem to let me so I don't have any information other than the dialog box that opens for debugging.

    Thank you

    Rob.

    OK, it turns out it was a 401.  DOH.  And the solution for it is here: http://supportforums.blackberry.com/t5/Web-and-WebWorks-Development/Suppressing-HTTP-401-Authenticat...

  • Proxy server does not.

    I have some aging confuguring my proxy server.
    IE does not ask me for the username and password for the server after entering the name and port.
    Therefore, whenever I try to navigate, I'm connected to the server, but it blocks me saying: "authentication failed" because the username and password did not intervene.
    Why is this not to come and especially how it can be repaired.  I tried IE, Firefox and Chrome, with uninstalled Antivirus and always without success.
    Help much appreciated.

    Thank you.

    Managed to finally make it work.

    Go to Internet options > Security > Internet > Custom > authenticating user > automatic login with user name and password has been around.

    Password box came. :)

    Works fine now in Internet Explorer.  Impossible to get all other browsers to work but it's not serious.

    Appreciate the help.

  • Window popup message: the SMTP server requires a secure connection...

    Hi This is my first attempt to help in this way. my asset is not only the best please understen. About a week or two ago, I started to get a wjndow pop up on my desk which read "the smtp server requires a secure connection or the Chief client was not authenticated. the response from the server was 5.5.1 that required authentication. Learn more,". Microsoft won't say that Live Mail only on line help. If anyone can help, I would be greatfull. Tanks

    Hi Firedog, thanks for your effect. You're really nice. There was a misunderstanding from the very beginning because a technician of Optus suggested Live Mail. Here is a link to the screen shot of the message (thanks to a tip on how to do this). https://SkyDrive.live.com/redir?RESID=5EBCF026C069D223! 112 & authkey =! AEbfWyyrYKtIH3g by the way the problem has been resolved by a kind person in Switzerland with whom I am in regular correspondence. Here's what we did. I downloaded a track from "Trojan Remover" version, run it and it removed a Trojan horse embedded in a file named skillfully as one of the windows updates. Unfortunately the file has been deleted by Trojan Remover without register the full name. He was placed in users /my name /folder AppData. If the problem is solved but a big thank you to all who helped. I have a program of security installed on my PC, but it does not take this Infection, time to consider my safety. Greetings and thanks a lot again.

  • proxy server is not meet windows 7 by sending to the address wrong (999)

    Trying to connect to a WI - FI connection but message this proxy server is unresponsive, apparently windows 7 sends the response to the bad address-999. How to ensure an adequate response. I tried Lan settings and the user authentication auto open a session, but it does not work. Thanks for looking... Bob.

    Thanks for depuis23 tried them all but it seems that in my case re-installing Internet Explorer 10 has been around, it is perhaps interesting to try for the others.

  • Problem ACS 4.0 and Server RSA Token

    Hello

    We are having a problem trying to get 4.0 for Windows GBA authenticate users on a Server Token RSA wireless.

    Our Cisco 1200 AP series is configured for WPA2 and LEAP Authentication. He points to the ACS server for RADIUS authentication. Now, it works very well for users with a static password defined on the internal database of GBA. However, for obvious security reasons, we? d as the transmitted authentication to our server internal RSA.

    I installed RSA Agent on the same server as the ACS along (after adding the sdconf.rec file in the System32 folder). The RSA server was added to the ACS external database and a user configured to use the Token RSA server for password.

    When we try to authenticate, the ACS fails the attempt with reason? External DB passes invalid?. The same user can authenticate successfully during the use of the RSA test authentication tool that is installed on the ACS server under the RSA Agent software.

    After running some debugs a pix in front of the servers, I see traffic to and from the servers when you use the test tool (that works), but it looks like GBA doesn't? t even send traffic to the RSA server during authentication.

    Any help or advice appreciated.

    Thank you

    no no no no! Do not use EVER of RSA with WIFI + PAP.

    The token + pin can be sniffed and is good for 60 seconds... on the Wifi which is disastrous.

  • Theme of WFS requires authentication, how pass/configure credentials?

    Hello

    I use the quick start kit mv11ps5_quickstart Mapviewer with last MapBuilder.

    I'm trying to set a WFS theme to an external server that requires authentication (username/password name). (here the mapviewer acts as a wfs client).

    I searched the forum and read the available documentation, but I couldn't find the way to pass these credentials in the definition of the theme.

    Is - it possible/supported anyway?
    If so, how should it be solved?

    Any help is appreciated on this.

    Thank you

    Luke

    Hi Luke,.
    It is not yet supported for the WFS and WMS themes.

    João

Maybe you are looking for

  • Please help error: "Could not complete the operation" when I buy the item at stake.

    I buy the currency in the game was the error message is unable to complete the transaction. Although the application was purchased with success.

  • Exchange 2013 - DAG (questions)

    Hi all I have a scenario where a client has a 2013 DAG Exchange up on two sites. Site 1: ECP Server Server CASE (CASE internal only), 1, mailbox Server1 Site 2: Server 2, Server 2 mailbox store For the PCE is on an internal server in the face of secu

  • Double digital control change

    Dear friends I have two digital controls in the front. Now I want to program numerical controls such as when I changed one of them another imposition of a change. for example in the VI attached when I put 'A' 1 'B' must be automatically 1 to and when

  • Windows Vista crashes, the screen becomes pink with diagonal dotted lines

    My HP Pavilion DV9500 laptop started making a few months ago: The computer and the programs sometimes simply freeze, sometimes the screen becomes a light pink with diagonal lines dotted, and sometimes the laptop itself restarts without warning.  The

  • BIOHD-8 error code

    I have a HP Elite, office e9270t model running 64-bit Windows. Read the mail, nothing new installed, computer stops responding. He can not get Windows to boot in any mode (std or repair). Fact Diag tools of marketing, all OK tests except by car. BIOH