Cisco ACS 5.3 several AD domains

Hello everyone

I have a quick question about Cisco ACS 5.3 and multi domain authentication. How exactly is it treated?

Can I join more than one field with the ACS server? Or do I still need to configure this two-way trust between forests AD relationship (even with GBA 5.3)?

Thank you

Markus

Hello

You can join only acs to a single domain. Here's a thread that will help you identify the confidence you will need to get this working.

https://supportforums.Cisco.com/thread/2162234

Thank you

Tarik Admani

Please evaluate the useful messages

Sent by Cisco Support technique iPad App

Tags: Cisco Security

Similar Questions

  • Cisco ACS and the domain controller

    Hello

    We are currently using the Cisco ACS 3.2.3.11 solution engine and using a Windows domain as a remote agent controller.

    We now have the ACS to 4.1

    1. do I need to upgrade the remote agent on the domain controller as well?

    2. any computer on the network can be used as a Distribution Server?

    3. after an initial backup and upgrade then to 3.3.3.3 I make another backup before the upgrade to 4.1?

    You can use any PC in the network as a Distribution Server.

  • Cisco ACS, multiple CA, assignment of VLAN relevant to the domain

    Hi all

    I searched for a solution to a specific customer requirement.

    I want authenticate users with certificates from different RootCA wireless and assign them to one VLAN based on their field?  Ideally, using the same SSID and a Cisco ACS server.

    Is this possible?  Has anyone seen that it works?

    I realize that the ACS can have trust company for the relevant RootCA (dunno what version is needed for this?).  And that assignment VLAN is also possible to a unique SSID based on RADIUS attributes.  But I am not sure that these parts would fit together?

    Would appreciate some advice!

    Thanks in advance

    Rob

    Hello

    Yes, this is possible. I suggest that you implement one by one to make sure that everything works, but no problem to do so. All recent versions of ACS allow this.

    You can do mapping group from ad groups (a group for each area, so if you want to) and assign the vlan based on the mapping of this group.

    GBA can trust several certification authorities and authenticate users with certificates of all these cases. It's just a matter of import these number certificate in the trust list.

    And you can assign the vlan and use only one ssid as well.

    I can't guide you on the procedure that it depends on which version you have and if you have IOS ap or WLC, but it is basically each function separated as in the config Guide and just used all together.

    Nicolas

    ===

    Remember responses of the rate that you find useful

  • Problem with Cisco ACS and different areas

    Hello

    We are conducting currently a problem with Cisco ACS that we put in place, and I'll try to describe:

    We have ACS related directory AD areas, where we have 2 domains and appropriate group mappings.

    Then we have our Cisco switches with the following configuration,

    AAA new-model

    AAA-authentication failure message ^ CCCC

    Failled to authenticate!

    Please IT networks Contact Group for more information.

    ^ C

    AAA authentication login default group Ganymede + local

    AAA authorization exec default group Ganymede + local

    AAA authorization network default group Ganymede + local

    AAA accounting exec default start-stop Ganymede group.

    orders accounting AAA 15 by default start-stop Ganymede group.

    !

    AAA - the id of the joint session

    But the problem is that with the users in a domain, we can authenticate, but not the other. Basically, the question is that when we check on the past of authentication, two authentications are passage and the display of 'Authentic OK', but on the side of the switch, there is a power failure.

    There may be something wrong with the ACS?

    Thank you

    Jorge

    Try increasing the timeout on IOS device using radius-server timeout 10.

    Do we not have journaling enabled on the ACS server remotely?

    -Philou

  • Cisco ACS 4.1 for external advertising for authentication

    Hello

    We have just configured Cisco ACS 4.1 solution engine and using a Windows 2003 domain controller as a remote agent.we use as Protocol Ganymede.

    Users that are created in ACS himself are able to connect to various network devices. but users in domain (active directory) can not connect. We get the access denied message. same time we get external DB is not operational message in ACS.

    Active directory server where agent that runs in CSWINAgentlog, we get the following error 'NDLIB'... FOUND 0 TRUSTED DOMAIN.

    Could you please help us to isolate the problem.

    Thank you & best regards

    Make sure that the worm of acs and remote agent software is the same. And also execution of remote agent account must have special domain administrator rights, like the act as part of operating system and log in as a service.

    Kind regards

    ~ JG

  • Cisco ACS user password change?

    Hi all

    Even if I don't check "Change Enable by PEAP password" setting on Cisco ACS, when a user tries to log on to the wireless network, whose domain password is going to expire, receives a popup on Windows XP, saying that their password is about to expire?

    Is this normal?

    PS: Check the screenshot attached.

    ACS is not able to send these messages for wireless users.

    He sends the AD.

  • [Cisco ACS 5.2] Disk partitions used by display of the CSA?

    Salvation (and happy new year)

    In Cisco ACS 5.2, there are several disk partitions:

    Which partition is used by the view of the CSA?

    A document that explains all the features of partitions exist?

    Kind regards

    Patrick

    Patrick,

    I'm not aware of a document that explains all the ACS 5.x Disk Partitions. However, I can assure that the display of the ACS are stored on the/opt partition.

    If you have an ACS 5.x on a Production network, one of the requirements is to install using the 500 GB HARD disk. The / opt folder on a 500 GB ACS reserves 347 Go to this folder (/ opt) because it stores the information in view of the CSA (reports and newspapers). It is the large partition as ACS View data includes all the ACS reports.

    I hope this helps.

    Kind regards.

  • connection via Cisco ACS 5.0 limit

    Hi all

    My infrastrucer wireless a few days ago I deploy Cisco ACS 5.0 with Active directory integration. My wireless users are connecting through web authentication process. The authentication process is gone through AD & his works very well. But I want to work on my 5.0 ACS that a user cannot simultaneously connect several devices at a time.

    Hello Sabine,.

    'max sessions' featre introduced acs 5.3.

    Maximum user sessions

    For optimal performance, you can limit the number of concurrent users to access the network resources. ACS 5.3 imposes limits on the number of simultaneous sessions of service by the user.

    The limits are defined in several different ways. You can set limits to the user level or at the level of the group. Depending on the configurations of the user's maximum session, the session number is applied to the user.

    IMPORTANT: for maximum sessions work for access of the user, the administrator must configure RADIUS account management.

    You can go through the link listed for more information below:

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/access_policies.html#wp1176806

    The code that you're using now ACS 5.0 is not recommended for a production environment. You need to upgrade the ACS to achieve the functionality of session max.

    Jatin kone
    -Does the rate of useful messages-

  • Problem with certifcate on Cisco ACS

    We want to authenticate our internal wireless users using our Cisco ACS running 5.3.  GBA questions our Active Directory environment for the user name and password provided.  I created a CSR on GBA and it provided to Entrust.  They gave me a root certificate, string and server.  I've linked the server certificate to the CSR under System Administration > Local Server Certificates > local certificates.  I then added the chain and the root certificates to the users of the site and identity stores > autorit├⌐s.  When I try to connect to a laptop client he asks a user name and password, but after entering this information, I am presented with the warning on this certificate below.  This certificate is to Entrust and I see the certificate root in the root store on the laptop.  Any ideas what would cause this.  TAC does not seem to have all the answers.  They say it's a problem of the client machine.

    In case you want to check your configuration settings.

    http://www.Cisco.com/en/us/products/ps10315/products_configuration_example09186a0080bd1100.shtml

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • Cisco ACS server

    Hello

    I currently have a Cisco ACS 3.3 Server. I want to upgrade the server to the latest version and cluster with one another so that we can have a redundant infrastructure because if one fails it also includes...

    Can provide you a solution for this?

    Thank you

    Hello

    The latest version is 4.1 ACS. You can upgrade 3.3.3 build 11 directly to 4.1.

    Then, you can install an another ACS 4.1 on a different machine and replication configuration between these two. In this way, you will need to make changes to only one that ACS and the secondary will be automatically updated.

    Once these two are defined, you can set both of these servers as a server Radius/Ganymede on devices and there will be a redundancy.

    Kind regards

    Vivek

  • How can I use Cisco ACS to save Shell commands

    Hi guys, pleeeease how can I configure Cisco ACS to do command authorization on my Cisco 3660 router. I get the accounting logs and authentication but no newspaper that show orders issued by users - shell and it's the most important paper that I need. I read materails and download articles on the site of Cisco... but the thing is still does not give me the papers.

    I have these lines on my router:

    ...

    AAA authorization config-commands

    AAA authorization exec default group Ganymede +.

    AAA authorization commands 15 default authenticated if

    AAA authorization network default group Ganymede +.

    ...

    It's funny, when I turn on debugging of the authorization of the AAA on the router, it shows me every command being sent by the user on the debug log. But nothing shows under Administration TACAC + on the Cisco Secure ACS. What is responsible for this?

    *****************************************************

    I installed the trial version of the Cisco ACS 90 days and made all necessary settings and I have to say I like what I see already. I'm opening moves to recommend the product to purchase. Thank you guys, I got about the features of this ACS software through this forum, keep up the good work. I recommend the software for those who need to have adapted to the management reports Security Audit logs.

    If I understand what you're asking correctly, the answer is not in the authorization, that it is in accounting. I set up on my routers and send to ACS orders that level 15 privilege users enter on the router.

    orders accounting AAA 15 by default start-stop Ganymede group.

  • Cisco ACS 1113 appliance v4.1 - integration of RSA Securid v6.1

    The Windows of Cisco ACS version seems to have the ability of integration with RSA Securid its listed in external databases. It can also support the SDI Protocol if you install the agent on the Windows ACS platform. I need to use a Cisco ACS 1113 but RSA Securid does not appear in the section external databases. This mean that I won't be able to use the SDI Protocol only available RADIUS.

    And Yes you are right,

    With ACS, we need to configure using RADIUS, on ACS SE it won't work with SDI.

    Kind regards

    Prem

  • Cisco ACS 5.8 CLI admin account lockout

    Hi all

    We recently deployed device Cisco ACS 3495 and running on a version 5.8.

    Everything seems well while our for the CLI admin account was locked out.

    Found a bug in Cisco for the same problem with version 5.5, but no solution yet...

    ACS 5.5 CLI Admin account locked and no Log Message
    Someone out there who might have encountered the same issue and can help advise?
    Thank you and best regards,
    NDA

    Hello

    Unfortunately, the only solution for this is the DVD of password recovery.

    Once fixed, you can increase the car locked out amounted to something greater than the default value of Cisco.

  • 5.4 double certificate option Cisco ACS

    Hello Experts

    I wonder if anyone knows if I can get two certificates on my Cisco ACS 5.4 server. The documentation says I can have it as long they have different 'from' and 'to' dates with a same name CN. However, this is a production server and wanted to if sure before I make changes. I currently have a certificate installed and everything works well but need to add a second for migration purposes.

    Hovsep Armeni
    LAN, UK

    A certificate can be linked to these two services (HTTP and EAP), however, each service can only be associated with a single certificate. Thus, for example, you cannot have two certificates that are related to the EAP process.

    Thank you for evaluating useful messages!

  • How to restore the password on Cisco ACS 5.4

    Hello!

    Try to restore the Cisco ACS 5.4 password installed on vmware. Where can I get the password recovery DVDs? There is no software in the list on the site.

    TAC may provide to you. You will need to open a folder and the application.

    HTH

Maybe you are looking for

  • Select a single image of a Live Photo Webcam

    I accidentally turned on Live Photos.  I have a dozen of them.  I want to choose the best picture of each of them and to keep only that frame.  I know how to do this with gusts of photos, but how do you go with Photo Live?  Thank you.

  • Satellite M70: Need WLan driver and his

    Firstly all Hello everyone. I am writing because I have format my laptop and now I'm trying to get the drivers on my laptop. Downloads of the Toshiba site are very slow, I tried on more than 1 computer and very, very slowly. Something? There is anoth

  • Internal hard drive has all of a sudden the write Protection

    Hello My internal hard drive has suddenly developed the write protection and has resisted each of my attempts to change this. I found issues related to external hard drives, but have not met a subject that bears on the disk system hard to develop thi

  • Cannot sign as me?

    Hello I downloaded 5 releases after trying to correct the mistakes that I have received from the review team. All refused... I use all Flash CS5 to my application and the command line to compile the signed application. When I check my files and wrap

  • Adobe descargarse cuanto soon en flash cs6 :(

    cuanto soon en descargarse adobe flash cs6