Replication of ACS and integration with the Active directory database

Hi all

I have to configure two ACS SE with the internal database replication. I have also a server active directory that must integrate with ACS. My doubt is that I need to configure the IP address of the ACS during installation of the remote agent on active directory or only the primary ACS

No need to give the IP of two ACS. Give the primary IP of ACS.

Kind regards

~ JG

Note the useful messages

Tags: Cisco Security

Similar Questions

  • Using Oracle with Microsoft Active Directory database

    Hello
    Because of too many nodes, we have in our company communicate each other (using the old files tnsnames.ora), we are now in the time to find a central location to store our net service names.
    I know that we can use for this OID to store the names of Service Net, but my question is it possible to use Microsoft AD, because our infrastructure using Microsoft AD as a central point.
    I have read the documentation oracle Oracle® Database Platform Guide (Chapter 12 Using Oracle Database with Microsoft Active Directory), but the problem is what happens if my database is not on the Windows operating system (such as Unix/Linux, we have number of it).
    I also read the document Oracle® Database Net Services Administrator's Guide (Chapter 3 Configuration Management Concepts) where you will find statement on the end of the chapter:
    Oracle supports Microsoft Active Directory only on Windows operating systems. Therefore, the client computers and the database server must also run on the Windows operating systems to access or create entries in Microsoft Active Directory.

    From this text, it looks like that my only option in this different environment with multiple operating systems is the OID (I wish it isn't true).

    Thank you

    Dragan,

    Sorry for the late reply. Since once it has clearly mentioned in the white paper that IO is a must; If you want to use MS AD, because 'oracle white paper' means 'documentation' refined and very authenticated.

    Enter the information useful/correct and close the debate.

    Concerning
    Girish Sharma

  • ACS integration with Microsoft Active Directory Services

    Hi all

    I was responsible for developing the integration of GBA with MS AD. What I want to know is below assuming I have a software ACS or ACS device and the authentication protocol's RADIUS

    -What is the criterion of the announcement to integrate with ACS to device software

    -Should that AD hosted on the domain controller or not?

    -Otherwise, on what (DC, tree, forest, branch, flower, Fruit) the announcement must be hosted on?

    -What should I do to authenticate users logging into Cisco ACS Security Manager integrated with AD?

    -Are there other dependencies that I'll have to speak categorically in my description?

    Thank you

    Rishi

    First of all, I love the flower fruit one keep it up.

    If ACS is for windows, it can be installed on the domain controller or member server. For detailed information about installation tasks post must have full integration, please see the following link that contains fancy things you are looking for:

    http://www.Cisco.com/en/us/partner/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/installation/guide/Windows/postin.html#wp1041202

    If ACS is soultion engine then you need piece of software called remote agent to be installed either on the domain controller or member server, also check the following link for more details on how to integrate it with AD:

    http://www.Cisco.com/en/us/partner/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.2/installation/guide/remote_agent/Rawi.html

    I hope this was informative for you.

    -----------------------------------------------------------------------------

    Please ensure good answers to rate

  • 5.2 ACS does not check the Active directory changes

    Hi all

    I work with ACS 5.2 and using Radius Authentication client vpn.

    The authentication method used is Active Directory in a Windows environment with multiple domains in the same forest.

    My problem occurs when I change from one group to the other user in Active Directory. After that, I get the following message appears when try to connect:

    15039 selected authorization profile is DenyAccess

    The message is as correspond to the default policy.

    Another user in the same ad group works very well.

    All domains in the forest have a relationship of trust between them.

    I use universal groups to include all domain users belongs to this forest.

    Can someone help me?

    Concerning

    What is your rule of authentication corresponding against a single ad group?

    You can check which groups were extracted for the user, as follows:

    -goto "monitoring and troubleshooting.

    -Select authentication - RADIUS - today

    -Find the input that do not match and click on the Details icon

    -Expand the section "Details of authentication". Look under "Other attributes" groups comes from AD to be enrolled in the user

  • domain with the active directory security / user name

    Hello

    I use weblogic 12 c, I create the provider for active directory in myrealm like going to the console >security domains>suppliers > New and I put specific provider and I don't have a ADF application using security ADF taking Kingdom deployed to the same server, weblogic, its work well with username and does not work with the id of the user for example if the user as described below:

    User ID Username Password
    aa123Test userXXXX
    bb123Test User2XXXX

    its fine work when put the username: User of Test or Test User2 but does not work with aa123 or bb123 how I let provider to keep the user id instead of the username?

    for the user name attribute active directory samAccountName, can you please try that instead of CN?

    If it doesn't work, can paste you the information from the user, you can use the ldifde command to export the user to Active Directory.

    I hope this helps.

    -Faisal

    http://www.WebLogic-wonders.com

  • Problem with the Active Directory plugin

    I am trying to create some decom workflow automation based on the Microsoft/AD plugin (version 1.0.5) on my box of vCO 5.5.2. I'm running into a weird error and I hope that someone can help you.

    Right now, just trying to take advantage of the ActiveDirectory.searchExactmatch () function to return an AD:ComputerAD object. The script is the following:

    var computers = ActiveDirectory.searchExactmatch("ComputerAD", Name, 1);
    if (computers != null){
       var actionResult = computers[0]; 
    }
    

    My workflow takes as input of type string, type ActiveDirectory AD:ActiveDirectory name and has an attribute of type actionResult AD:ComputerAD. I am constantly getting this error - TypeError: cannot find searchExactmatch function in the object notfound. (Workflow: fast / Scriptable task (item1) #54823) - apparently, which indicates that the AD:ActiveDirectory object is not found.


    Maybe there is something to permissions for this, but I ran the workflow as a domain administrator and I still have this error. When I run the workflow, I am able to successfully navigate my AD resource:

    selectAD.png

    Any ideas?

    Are you really sure that you have an input parameter named ActiveDirectory? ActiveDirectory is a singleton object script, so it's not really appropriate for the input parameter. Singletons are visible everywhere in the script code, and you can use . (...) to call its methods.

    BTW, by setting convention names must not start with the capital letter; for example. Name should be the name. Please stick to this convention in order to avoid name conflicts.

    Then it seems that you misspelled the name of the method that call you. Instead of searchExactmatch we searchExactMatch (with capital "M").

  • hard drive crashed reloaded family pack upgrade from windows 7 Home premium and cannot be activated with the Activation Center

    hard drive crashed reloaded windows 7 Edition home premium and now the automatic activation Center said I failed to meet the requirements to activate my copy of windows. I have the keys to the family upgraded to windows 7 Edition pack Home premium.  If I remember correctly which is enough for six computers. then I am owner of a key for windows 7 Professional and three keys for windows 8 Professional I have only 5 computers and we got xp on 3 have windows 8 and the hard drive crashed on my computer with windows 7, replaced the hard drive and reloaded windows 7 and now I can't turn it on. what I am doing wrong?

    Have you tried to restart by phone?

    How to activate Windows 7 manually (activate by phone)
     
    1) click Start and in the search for box type: slui.exe 4
     
    (2) press the ENTER"" key.
     
    (3) select your "country" in the list.
     
    (4) choose the option "activate phone".
     
    (5) stay on the phone (do not select/press all options) and wait for a person to help you with the activation.
     
    (6) explain your problem clearly to the support person.
     
    http://support.Microsoft.com/kb/950929/en-us

    Please note that the family pack is an upgrade.

    However, the requirements for the media upgrade is that you have an operating system already eligible such as Windows XP or Vista installed to use it. Since the Windows 7 end user license agreement.

    15 UPDATES. To use upgrade software, you must first be licensed for the software that is eligible for the upgrade. After the upgrade, this agreement takes the place of the agreement for the software that you upgraded. After upgrade, you can no longer use the software that you upgraded.

    So, if you are always denied, you will just have to reinstall Windows XP or Vista and let it do the verification of eligibility.

  • When you try to activate Windows I get an error: Code 45123 could not establish a connection with the activation server.

    the error number is 45123 and said "we could not establish a connection with the activation server." Please give me an answer to this error and try to solve it! If you want I can send you my product key to activate it, but I think it's better on email not here because there are a lot of... the pirates who have access to this site! provide me with an email address and I'll send you my product key and try to activate it and then give me the id I need to enter the activation window! Thank you!

    I solved this problem! Thanks for the help!

  • System will not be activated. Receive the error message "system could not establish a connection with the activation server.

    Activation.

    My OS system has been altered, so I formatted and installed new, but can not activate. I have this installation id 348020-631951-163976-154093-556113-629786-940105-229483-661432, I need confirmation id because my system could not establish a connection with the activation server

    How to activate Windows XP
    http://support.Microsoft.com/kb/307890/en-us

    See the section titled: "how to activate Windows XP by phone.
    Also, make sure that you do not confuse the product key numbers and letters
    (number 8 for the letter B, etc.)

    How to contact a Microsoft Product Activation Center:
    http://support.Microsoft.com/default.aspx/KB/950929/en=us

    Microsoft Activation centers worldwide telephone numbers:
    http://www.Microsoft.com/licensing/existing-customers/activation-centers.aspx
    (This site is for activating Volume License, but if you call, they will help you)

    The phone number is not working:
    Microsoft Wordwide contacts: http://www.microsoft.com/worldwide/default.aspx

    Once Windows activated / Genuine Advantage Notifications:
    http://www.Microsoft.com/downloads/en/details.aspx?displaylang=en&FamilyID=afd45b36-3d77-4259-801c-d31a9a90cdcf
    (This tool will confirm that the copy of Windows installed on your PC is genuine and authorized)

    J W Stuart: Http://www.pagestart.com

  • How can I put Windows on a USB key which will be bootable by BootCamp and how transfer the activation code?

    * Original title: Windows 7 - CD to USB

    I bought Windows 7 (the two CD 32 & 64) many years for use on my early 2008 MacBook Pro, with an optical drive, via BootCamp. It worked very well.

    Now I have a new MacBook Pro without optical drive, but would like to install BootCamp and use Windows again.

    How can I put Windows on a USB key which will be bootable by BootCamp and how transfer the activation code?

    Thanks in advance for your help.

    Use Rufus:

    Rufus - create USB bootable the easy way discs

    Another solution:

    http://www.AddictiveTips.com/Windows-tips/create-bootable-Windows-7-USB-flash-drive-from-DVD-disc/

  • unloading of feature to make dhcp off the WLC and put it on Active Directory.

    I need to use the feature of unloading to dhcp off the WLC and put it on Active Directory.  Someone at - it a walkthrough or a page for this?  I know it's just a checkbox and a redirect to the new dhcp server, but where the hell is the configuration on the WLC?

    Thank you!

    -anne

    You can go there.

    http://www.Cisco.com/c/en/us/TD/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_01001001.html

    Point to your existing ad integrated DHCP server.

  • 'Impossible to connect with the activation server' while trying to activate Windows 7

    Stater of the i run windows 7 on a laptop dell inspiron N5050 32-bit, windows asks me to re-enter my product key each tome I get it it displays after loading: impossible to connect with the activation server, see other ways to activate windows, pls make serious saying my trial period has expired why it cannot connect to the server to check the product key? Help, please

    Original title: activate windows

    Have you tried to restart by phone?

    How to activate Windows 7 manually (activate by phone)
     
    1) click Start and in the search for box type: slui.exe 4
     
    (2) press the ENTER"" key.
     
    (3) select your "country" in the list.
     
    (4) choose the option "activate phone".
     
    (5) stay on the phone (do not select/press all options) and wait for a person to help you with the activation.
     
    (6) explain your problem clearly to the support person.
     
    http://support.Microsoft.com/kb/950929/en-us

    Please run the Microsoft Genuine Diagnostics Tool then copy and paste the results into an answer here for further analysis:
    http://go.Microsoft.com/fwlink/?LinkId=52012

  • I have a problem with the Activation of the key window expiring.

    Original title: recovery partition

    Hello

    My Windows 7 ultimate activation code has expired, I was wandering if, in case I do a restore system from the recovery partition on my PC I could get it to work again for another year. Thank you.

    Hi Casperthe,

    If you had a real computer of Windows 7, or a valid Windows 7 product key, try these steps and check if it helps. A recent hardware change can cause this problem. I suggest you activate Windows 7 manually (activate by phone) and check if it helps.

    a. click Startand in the search for box type: slui.exe 4
    b. press the 'ENTER' key
    c. Select your 'country ' in the list.
    d. Select the "Phone Activation" option.
    e. stay on the phone and wait for a person to help you with the activation.

    Check out the link for more information:

    How to activate Windows 7 by phone

    http://support.Microsoft.com/default.aspx/KB/950929/en=us

    Hope this information helps. Answer the post with an up-to-date issue report to help you further.

  • Integration with the PIX IDS firewall

    I read the Release Notes for Cisco Intrusion Detection System Sensor Version 3.0 S4 (1), and tripped on the new features of this version it pretends the integration with the PIX firewall

    How do implement you this? What kind of integration offer?

    Instructions for the sensor and the basic configuration of PIX can be found here:

    http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid23

    Instructions for sensor and PIX SSH configuration can be found here:

    http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid16

    You can configure the sensor to connect to the PIX via telnet when

    using the PIX inside interface, otherwise you have to use SSH.

    SSH with 3des encryption is supported in version 3.0 or later

    sensors for connections of PIX.

    Warning: If you use telnet with a version 6.2.1 or PIX more late or if

    you want to use SSH with encryption on any PIX, so you

    need a patch for your sensor. If so, open a case of TAC and demand

    the latest version of nr.managed engineering. Reference

    [email protected] / * / for any question.

  • Serving AVDF 12.1.2 integrated with the package DBMS_AUDIT_MGMT allowing the automation of audit records

    I have a question about this part of the vault of the audit and the Guide Release 12.1.2 database firewall administrator documentation:

    -Start quote-

    Schedule for a job of automatic Purge

    Oracle AVDF is integrated with the DBMS_AUDIT_MGMT package on an Oracle database. This integration automates the purge of the AUD $ audit records and files of $ FGA_LOG and operating system .aud and .xml files after that that they have been properly applied in the repository of Audit Vault Server.

    Once the complete purge, officer of Vault automatically sets a timestamp on the audit data that has been collected. Therefore, you must set the property USE_LAST_ARCH_TIMESTAMP set to true to ensure that the right set of audit records are purged. You don't need to manually set a work of purge interval.

    -Extract-

    According to the documentation above, how AVDF brings integration resulting in automation?

    Hello

    When you configure an audit trail in the AV server, say a table AUD$ path, once it collects the audit data he attributes automatically the last time stamp archive on the secure target database (you can check it out of view DBA_AUDIT_MGMT_LAST_ARCH_TS).

    However, the trail (or the AV itself server) does not purge that verification data already collected.

    You have to clean these data with the DBMS_AUDIT_MGMT. Procedure CLEAN_AUDIT_TRAIL, example for AUD$ table only:

    BEGIN

    DBMS_AUDIT_MGMT. () CLEAN_AUDIT_TRAIL

    audit_trail_type-online DBMS_AUDIT_MGMT. AUDIT_TRAIL_AUD_STD,

    use_last_arch_timestamp => TRUE);

    END;

    /

    You can simply run this procedure via a job depending on how often you want to cleanup audit and what time recordings. You don't need to worry about the timestamp of last archive.

Maybe you are looking for

  • The Portege 7020CT power supply works with the dock?

    Hello I have a Toshiba Portege 7020CT (I know its old)I would buy a Toshiba PA3007E-1DST on eBay!In the description of sellers on eBay, it is written that a power supply is not included!So he lies to be included power supply? Or am I ment to use my l

  • Satellite Pro L770-149 - cannot get working Wlan

    Hello I recently rebuilt a Toshiba Satellite Pro L770-149 with windows 7 64 bit, when I installed first the operating system, all the drivers were missing so I installed all of the correct drivers and had run as it was before. Form Apart wireless con

  • Think of a T410 laptop, is it useful?

    Hey there. I recently bought a laptop T61 used; GPU from Intel, Intel T7500 2.2 GHz, 4 GB of ram and a 14 "4:3 1400 x 1050 screen. I added a 128 GB SSD and configure the BIOS middletom SATA2 support. I also have Win8.1 64 bit that works very well wai

  • Can I upgrade to Windows 8?

    Hello I have a laptop DV6 6011TX, product number LQ436PA #UUF and running Windows 7 Home Premium (which was preinstalled). My question is can I switch to windows 8 with all the features? I mean do all drivers are available for my laptop compatible wi

  • Blocked Windows in safe mode activation loop.

    So here's the problem, I used windows xp pro x 64 now for a little over 2 years and it has worked perfectly until today. I play with some programs of hertz of mouse that required me to start in safe mode. I went to boot safe mode via msconfig. My com