ACS alternatives

An ACS server is too expensive and overkill for our small network.  What alternatives do I have if I want my Microsoft AD to authenticate access admin or privileged for switches, routers, and Cisco firewalls?

Thank you

Diego

Hi Diego.

Absolutely, you can use ad groups. Take a look at the link below:

http://aplustoccie.blogspot.com/2012/02/how-to-make-NPS-your-RADIUS.html

Thank you for evaluating useful messages!

Tags: Cisco Security

Similar Questions

  • Alternative of DRM for ACS 4.0 client?

    Hi all

    I'm building an ebook for Windows instead of draw reader party ADE for ACS 4.0.

    After reviewing the document, and the Adobe forum, I found the ACS client seems to be packaged with RMSDK to activation / authorization.

    It's the alternative to implement a customer of ACS windows without using the RMSDK?

    Any suggestions are welcome.

    Thanks in advance for the help.

    Kenneth

    N ° only the RMSDK customers are allowed for ACS4 (activaiton Adobe servers).

  • Alternative ACS 5 ip local pool

    Hello

    We have the problem with ACS 5.3, that local ip pools are more supported. Until we have a 4.2 ACS where worked the PPPoE configuration below (the pool has been configured dynamically in the user attributes or group of ACS 4.2). Now we would like to use a local DHCP pool (pool INTERNET) for some of the PPPoE clients, but at the same time, we have a few customers who should have a static IP address (managed by a box-IP-Address).

    Now we have the problem, that the DHCP pool is not used for dynamic PPPoE clients, can anyone help?

    local group AAA of ADSL ppp authentication RADIUS

    AAA authorization network group local ADSL RADIUS authenticated by FIS

    start-stop radius group AAA accounting network ADSL

    AAA accounting system default start-stop Ganymede group.

    INTERNET IP dhcp pool - new

    import all

    network 192.168.1.0 255.255.255.0

    .ch domain name

    !

    IP vrf ADSL INTERNET

    RD 65500:101

    Route target export 65500:101

    Route-target import 65500:101

    !

    interface Loopback3

    IP vrf forwarding ADSL INTERNET connection

    IP 10.10.10.10 address 255.255.255.255

    !

    interface virtual-Template1

    model description of the incomming PPPoE sessions

    MTU 1492

    Loopback3 IP unnumbered

    not the peer default ip address of - old

    ! peer default ip address dhcp-pool INTERNET - new

    KeepAlive 5

    PPP mtu Adaptive

    Protocol chap PPP authentication ADSL

    authorisation of PPP ADSL

    Accounting ADSL PPP

    !

    ! IP local pool INTERNET 83.144.249.1 83.144.249.254 group ADSL - old

    Thanks a lot and best regards

    Dominic

    Hi Dominic

    As we have already tested together in the lab, the following RADIUS attribute works for you, then you can always use the "local ip pool" on the router:

    Attribute: cisco-av-pair

    Value: ip:addr - pool = TEST

    Best regards

    Heiko

  • CS ACS Solution engine with external AD database

    I have a client who has set up a CS ACS Solution engine (device). They currently have VPN tunnels that terminate on the SAA and the ACS provide authentication via an external database to the AD. I did the installation or configuration of the device and I'm new to ACS. There is a group in an ad that was created to allow access to the VPN, and it works. I created a second group in AD and a test user. The user account will not correctly authenticate when establishing a VPN session. I checked the agent ACS logs on the controller of the AD is to show that the user performs the authentication correctly, and it seems that the agent is not transmitting this information to the ACS. Alternatively, the ACS is ignorant. The GBA, the generated error is "external DB account Restriction." I can't find anything specific to this topic. I checked that the announcement represent works and can log on to a workstation. I checked the properties of account for the test account. I think it's related to the membership of the group. I have a group in ACS named exactly the same as the ad group and of the test account is a member of this group. I don't know where to start any help would be appreciated.

    You must map this group

    User to external databases > database group mapping > Datbase of Windows... section

    A group of ACS, naming the group exactly the same as the Windows AD Group ACS establishes no relationship between them.

    I guess that your all other combinations in the group mapping are mapped to one ' "group, OR to a group that is disabled.

    Please ensure that the mapping of good group on ACS for the new group you created on AD.

    If you move in the right direction, problem seems to reside in group mapping

    Kind regards

    Prem

  • Secure ACS 5.7 - adding a secondary server to the primary

    Hello.

    I recently set up two servers Secure ACS 5.7 primary. I want to make one of the main servers a secondary server. When I try to register at the elementary level, I get the following message:

    This failure has occurred: save failed due to invalid certificate. Your changes have not been saved.

    Both servers have valid certificates. But other that to extend the validity of the cert, no other changes have been made.

    Any ideas please?

    Thank you

    Daniel

    Hello Daniel,.

    For the communication of trust option work. It is necessary to use certificates signed by one or the other it external or internal, and add to it, you must import the transmitter respective root/intermediate cases under "users and storage of identity > section"Certificate authorities"on both ACS servers.»

    Alternatively, you can choose not not to use the feature "Trust communication" by going in "System Administration > Configuration > global system Options > Trust Communication Settings." and uncheck the check box for the feature.

    Note: Please mark responded as appropriate.

    Note

    Note

  • ACS any Version with Windows Server 2008 R2 64-bit domain controller

    Hi all

    Is there any version of ACS is currently working with Windows Server 2008 R2 domain controllers?

    Our server controls has recently upgraded domain controllers to 2008r2 and off 2003 servers. This did not our ACS 4.1.4 really happy.

    I read now serveral messages about problems with the ACS and Server 2008r2 and hope to find a solution (not to mention that switching to LDAP, yukk).

    Thank you

    Pato

    ACS currently cannot be installed on a server running Windows 2008 R2.

    As an alternative, you can install ACS on a member server.  Authentication

    ACS uses the local machine net API authentication both compared to a 2008

    R2 domain will work.  The Remote Agent can also be installed on a 2008 R2

    Server if you use devices.

    If you install ACS on a member instead server here is how to configure services

    to authenticate properly with the domain:

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/installation/guide/Windows/postin.html#wp1041304

    -Jesse

  • Problems with patching: ACS 5.0 to 5.1 upgrade

    I'm following the instructions to upgrade ACS 5.0 to 5.1

    But I can't get past the first step:

    Step 1 Install the ACS 5.0 patch:

    Issue the following command from the patch CSA in EXEC mode to install the fix for the ACS:

    Install patch ACS patch-name. tar.GPG repository repository-name

    Here is my result:

    / Admin # acs patch install repository 5-0-0-21 - 9.tar.gpg mytftp
    chmod: cannot access at the "* .sh ': no such file or directory".
    Error: Could not open the patch 5-0-0-21 - 9.tar.gpg

    It download the patch via TFTP ok, but cannot install it.

    Can anyone help?

    Thank you

    There are problems in 5.0 with using tftp for file transfers that exceed 32 MB. There may be problems with the ftp servers that exceed this limit.

    I recommend to start using the alternative repository type. For example, ftp or a local repository on the server.

  • Access to the ACS SPECIFIC group router

    I want allows you to control access to all of our routers and switches Cisco GANYMEDE. I have a Cisco ACS device that can be used for centralized management accounts of the engineer. The ACS server, however, also used to store our business users VPN accounts.

    Can I restrict access to routers and switches only to users in the Group of engineers on the ACS server?

    Hello

    If you use ACS 4.x, limiting access through Restrictions on access network (NARS) could help you:

    http://www.Cisco.com/en/us/products/sw/secursw/ps2086/products_tech_note09186a0080858d3c.shtml

    I would like to know if this helps, or alternatively if you use DCC 5 (in which case the scenario is a little different).

    Kind regards

    Fede

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • ACS 5.1 tcpdump tech dumptcp 'feature '.

    Hello

    I'm just installing ACS 5.1 for the first time and came across the dumptcp tech 'feature '.

    This command seems to be almost completely useless to capture the packets to the ACS 5.1 OS!

    It is not possible to specify a filter or to capture packets on the disc.  The only options that exist are the ability to specify the number of packets that are dumped into the console, which rather limits its usefulness, especially if you're SSHed in ACS 5.1 in the first place.

    County of Tech dumptcp 0?
      <1-10000>County of package

    Read the order reference http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/command/reference/cli_app_a.html#wp1039556 made me laugh.  Author tech showed the while command as SSHed in and together they captured onscreen, surprise, their console session SSH packets.

    So - 2 questions:

    (1) does anyone know of an alternative within the ACS 5.1 host operating system to capture network packets while SSHed in?

    (2) at - it already creates a demand with Cisco to improve the tech 'feature' dumptcp by adding the ability to filter packets and capture the disk?

    Thank you very much.

    There is an improvement CDETS open:

    CSCtd13775: ACS5 and TCPDump/Sniffer features

  • Unable to connect wireless, "ACS user exceeded max sessions" users

    Some corporate users are unable to connect to the wireless company.

    On the WLC, I get the following logs:

    Authentication failure AAA for UserName:dto029 user Type: USER WLAN

    The GBA, I get the error:

    Authentic doesn't have a default group for ACS user exceeded max sessions (by default) 192.168.47.46 DTO029......

    That means "user ACS exceeded max Sessions? How can I solve this problem? Connection problem faces few users, while others are able to connect.

    Corporate SSID, Session Timeout & Client Exclusion is not enabled. The WLC version is 7.0.98.0 and the version of the CSA 4.2.0.124

    The problem is solved the ACS is restarted. Is there a permanent solution?

    Thanks in advance.

    Hello

    the error means that the users belong to the ACS Group (or the user themselves) has a "max session" setting, as described here:

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/Overvw.html#wp826493

    .. and the user exceeds this limit.

    ACS can indeed limit the number of concurrent sessions for the same user name; This counter is based on the RADIUS account management information received from the AAA client: the session counter is increased when receiving a 'Start' accounting and it is decreased when you receive a "Stop" on accounting package.

    ACS for a reason if any don't receive an Acct-Stop, it won't reduce the number of session, so it may happen that your users exceed the max concurrent sessions allowed indeed.

    You can check the active sessions on the "users" ACS report:

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/LgsRpts.html#wp680304

    If you restart ACS, this info is reset, so everything will work again, as you say; as an alternative, you can also use the options 'Purge logged in users' on the logged users page, but it would be wiser to really solve this problem by checking if... :

    -do you really need the config of max sessions? Otherwise, you can simply disable this on users/groups configuration

    -If you need for this limitation and the problem is related to the session that overlap, which means that the WLC should not send the Acct-Stop because there is always a session active and a new one is created at the same time, you can consider increasing the number of maximum session.

    HTH,

    Federico

    --

    If this answers your question please mark the question as "answered" and write it down, so other users can easily find it.

  • Best alternative to Photoshop for iPad Pro?

    I am a print and web designer and I just bought an iPad Pro. IM has decided to try to work only on my projects using my new iPad Pro for the next few days. Certainly, it should not be a replacement for my iMac, but I want to give it a try.

    I notice that Adobe has a lot of products by way of illustration, but I don't see an alternative to Photoshop. Pixelmator is cool, but it's meh. Model of Adobe is also cool, but it lacks a lot of features.

    Has anyone found an alternative good photoshop that would allow me to create and edit PSD files, when I travel?

    No matter what other digital designers out there that the spirit of sharing their favorite applications?

    Thanks in advance.

    Suz

    Adobe has many applications of Photoshop.

    Search the IOS App Store for only Adobe.

    If you want to maintain an all workflows Adobe, Photoshop, in order to get most of the functionality of Photoshop on a computer, you will need to use all the different Adobe Photoshop applications to work with.

    If you are using an older version of Photoshop and not the current Adobe Creative cloud suite with subscription, most Adobe applications, in order to better integrate them will pay for a monthly subscription of CreativeCloud or connect to your cloud Creative account if you are already paying a subscription.

    If you are using an older version of Photoshop, you'll need to use a service like DropBox Cloud or box or some other Cloud Service, like iCloud Drive Apple, Amazon Cloud Drive or GoogleDrive to bandy your work back and forth between your iPad and your computer.

    Adobe, I guess, won't or don't know how to create a version of Photoshop on iOS that is a close approximation of Photoshop on a full blown computer.

    Adobe Photoshop full in a variety of applications to cover different areas of Photoshop broke.

    You'll find yourself using the multiple applications of Photoshop to cover everything you do with full Photoshop.

    You'll find yourself using several apps to do a great many things, perhaps more easily on a computer, no matter what, in any case.

    This is how iOS works.

    There is not a single application that will cover everything that you could possibly need.

    Working in the iOS is mainly working with multiple applications.

    For the work and digital painting and illustration of image editing, you will find that you will have to constantly import/export files from an application to another.

    If you don't like this multiple iOS approach Photoshop app, your only alternatives are Pixelmator for iPad and may, in addition, http://bit.ly/joc0zm.

    I use apps and paint a little image editing applications, but Pixelmator and http://bit.ly/joc0zm are apps that are in the top of the applications on my big iPad Pro.

    There are other image editors and applications of paint you can use

    I have a little.

    Here is my own incomplete list of creative image and drawing apps I have installed and you are using.

    In no particular order.

    Pixelmator

    Childbearing

    Sketch book / SketchBook Pro

    Sketch of Pro

    Concepts

    Forge

    Inspire Pro

    Ibis paint

    Art Studio

    Memopad

    Chart

    Hit the draw draw

    More than

    Transfer

    HD Photo sorting (an image/document organization function app folder)

    Photogene

    Camera

    TItleFX

    Retype

    Union

    Filterstorm

    Photomotion

    If you want to add more fonts to your iPad applications that might access to, find the app

    AnyFont.

    Good luck!

  • iTunes and alternative player

    Since apple stopped supporting the iPod classic is there 3rd program/app used with inexpensive mp player who would recommend? I'm afraid to invest in the music from iTunes more because of the difficulty of using freely once it was purchased.

    Apple stopped adding DRM to purchased music in 2009.

    The most recent Apple's music service includes so that playback rights can be withdrawn at the end of a subscription.

    iTunes offers backward compatibility with all the Apple iPod. If you encounter problems, update your iPod with iTunes, start with If iTunes does not your iPad, iPhone or iPod - Apple Support.

    MediaMonkey is an alternative media player good.

    TT2

  • I won't accept tab, is there an alternative in FF?

    I won't accept tab, is there an alternative in FF?

    If you don't want to use tabbed browsing? If you don't want new links to open in a new tab, you can uncheck the preference "Open new windows in a new tab instead" in the Firefox options.

    In addition, your Firefox is out of date, please update Firefox 42 (Firefox updated to the latest version)

  • Is it possible to create a spreadsheet Numbers alternating line colors I choose (rather than just a line alternating color)?

    Is it possible to create a spreadsheet Numbers alternating line colors I choose (rather than just a line alternating color)?

    Hi tochan,.

    No, but it is possible to create this look.

    Procedure:

    Open a table.

    Format > table

    Check the alternative line color. The yellow value.

    Click the form button, select the rectangle.

    Click the shape to select it.

    Format > Style

    Set the fill color to green.

    The border value without border.

    Move the shape to align with the upper left corner of the table.

    Drag the handle at the bottom right of the form to the lower right of the table.

    Go to organize > Send to back (or backward and repeat until the form is behind the table, and the Green shape is visible through the non colored lines).

    Note that the form is independent of the table. If the lines are added to the table, alternating lines will continue to have the yellow filling, as it has been applied to the table itself, but the lines between indicate white background, until the shape is expanded to match the size of the table.

    Select the Table (by clicking on the 'target' at the top left.

    Go arrange > Send backward. (Repeat if necessary until the form is in the front of the table)

    Select the shape.

    Resized according to the table.

    Go arrange > Send backward.

    Kind regards

    Barry

  • What is the alternative to the Flash from Adobe that is blocking Firefox.

    reviews Adobe is blocked by Firefox, I can use instead.

    Unfortunately there is no alternative. However, adobe did release a update Flash today, so please update flash.

Maybe you are looking for

  • Emergency assistance: can't remember the password!

    Hi all, I use an iPod Touch 4th gen and it is running iOS 7. When I turn on my iPod Touch I tells me to enter in a 4digit passcode, but I do not remember what and I don't want to get locked into the iPod Touch. I have my AppleID so can I use this som

  • Satellite 1900-100 - what is a maximum size of HARD drive

    HelloI would replace the drive ide 2.5 "on a Satellite S1900-100.What is the maximum capacity of hard disks in this laptop?Max

  • Error code 1073807346 visa.

    I'm contacting a digital wattmeter of Yokogawa WT210.  My LabVIEW application test works very well initially, getting data from this instrument, but ONLY errors after exactly 4 loops.  My program contains two frames.  I connect the resource (GPIB::5)

  • WiFi dies after a few minutes - computer notebook dv7-6199us

    I have a laptop dv7-6199us Win7 64 bit running.  My wifi has become extremely reliable - it will work for a few minutes, then stop.  The system says it is always connected to the wifi hotspot, but I can't go out on the web.  I disconnect/reconnect -

  • I forgot Windows 7 password

    I'm running Parallels so I can run Windows 7 and OS 10