several remote agent

Hi all

I installed version 4 of the ACS. We have several devices in the group all of them use the same ad for authentication. We have created several NDG, now I need to create remote agent with the same IP for each NDG but ACS helped to create several remote agent with the same IP address. How can I create several NDG, but all use the same remote agent?

Thank you

Alex

Hello

I don't know if I understand your question. In any case, I am setting my understanding below:

AAA clients are defined in the NDG on the GBA unit.

ACS appliance authenticates via AD.

ACS appliance must RA to talk to AD.

Now in your question, here's my understanding:

The AAA Clients are defined in NDG. they must authenticate via the AD. so, to talk to the AD, we define RA by NDG.

Is it true that your question?

If so, then the flow is a bit like this:

AAA Client sends the authentication request.

The request is received by the GBA unit. For the device, it's just a query no matter whence it. He sees that this must be authenticated through the AD. Inorder to do that he must send to the Remote Agent. then it will send Remote Agent who will forward in turn to the announcement.

Thus, defination RA by NDG does not come into picture.

For reference the link describing the NDG aims as follows:

http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/NetCfg.html#wp342699

The link to the Remote Agent is as follows:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/3.3/installation/guide/remote_agent/rawo.html.

I hope that I have answered the question.

Kind regards

Anisha

PS: Please note that this link solved if you feel that responds to the request.

Tags: Cisco Security

Similar Questions

  • Which remote agent accounts set up ad?

    I need to install remote agent for ACS, after reading several posts here, I see that there is a requirement for configuration 1 or more accounts on AD.

    I see no mention of this in documentation Cisco RA, which accounts I have to configure? Is - it related to the configurable name on the configuration of the ACS for RA, cisco or the name of ACS may be used.

    The AR has been configured with the IP address of the ACS, do I need to configure anything else on the RA to make this work?

    Hello

    You can go to http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.2/installation/guide/remote_agent/rawi.html and check the configuration of windows authentication. These steps should be followed so that Remote Agent to work properly.

    Please see the installation guide according to the version of the Remote Agent you are running.

    Kind regards

    Kush

  • Unable to connect to the Remote Agent of VMware Converter

    I'm trying to V2V an our old infrastructure of VMware 2.5.x our vSphere infrastructure W2K Server.

    I've done several servers of the old infrastructure without problem.

    On this particular server, however, fails with the error "Unable to connect to the Remote Agent of VMware Converter"

    The journal of the points below on the $ IFC share.

    [2011-01-14 12:32:40.008 'P2V' 4788 info] [ClientConnection, 101] Connection to IPC$ on 10.101.0.171 like 10.101.0.171\administrator
    [2011-01-14 12:33:10.086 'P2V' 4788 info] [, 0] SMB Manager: connection error for share [\\10.101.0.171\IPC$]: 1792

    [2011-01-14 12:33:10.086 'P2V' 4788 WARNING] [ClientConnection, 115] Unable to connect to IPC$ on 10.101.0.171. Reason: Error unspecified in the mechanism of the remote execution
    [2011-01-14 12:33:10.086 'P2V' 4788 info] [ClientConnection, 119] Renounce the attempt to connect to IPC$ on 10.101.0.171
    [2011-01-14 'P2V' 4788 error 12:33:10.086] [task, 295] Task failed: P2VError REMOTE_UFA_FIREWALLED (10.101.0.171)
    [2011-01-14 12:33:10.086 'P2V' 4788 verbose] [task, 339] The transition of InProgress asked congestive
    [2011-01-14 12:33:10.086 'P2V' 4788 verbose] [task, 388] Successful passage

    Any suggestions for a solution would be appreciated.

    It looks like maybe the firewall on the server. Install the converter directly on the machine you want to convert, or temporarily disable the firewall.

  • Active Directory + ACS Remote Agent

    I have a camera ACS (3.2). I understand that I need to use a remote ACS agent installed preferably on a domain controller, Windows authentication. My question is: if I use Active Directory, can I not use external user databases and configure generic LDAP with the appropriate settings to access Active Directory? So I wouldn't need a remote agent? Or I have to use external user databases and configure the databases Windows (which means using an external remote agent? Or I can choose two methods? His confusion as active Direcory cann support for pre-2000 windows domains and I do not know which method of mapping of external user database to use.

    My apologies, missed the word "apparatus" in your original post.

    You can probably do this use anyway, I guess, even though we suggest using a Remote Agent with the Windows DB. If you are not going in this direction, make sure your security permissions (http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/raig/rawi.htm#642394)

    I've had users use the LDAP with Windows Ad database before and it works very well, the only difference (IIRC) is you don't get all the group maps of Windows with this method, but for the authentication of the user only, it should work fine.

  • Secure ACS unit and Remote Agents

    Hello

    We test Secure ACS 3.2 device and authentication against AD via remote agents. When two or more remote agents are registered with the device in the network menu, is the pretty smart device to try the second machine remote agent if she can't talk to the first? We tested this failover by stopping the service of the remote agent on the first domain controller where it has been installed. However, failover does not occur. We want to know if this failover is supposed to work, and if so what we need to do to make it work.

    Yoshi Nagase

    Hello

    I implement a solution similar to yours... 2 ACS unit with 2 Remote Agent...

    I set the remote agents on the Network Configuration and the external user DB - database of Windows - Windows Remote selection of the Agent.

    In this menu the value primary and secondary Remote Agent

    HTH

    Omar

  • Upgrade ACS 4, 1 - question of Remote Agent

    I've updated Cisco ACS 3.2 to 4.1. Having satisfied certain issues, we finally got installed. Now, we are facing this problem of the remote agent. There is a lot of configuration to do for this agent? Here is the part of the instructions. I know right what they want me to. Where is this Cisco computer? Where we put the Cisco account? We certainly do not have a domain controller on our network called Cisco. Is it better to put this on a domain controller or a member server?

    Thank you

    Dwane

    Step 1 Add CISCO workstation.

    To meet the requirements of Windows for authentication requests, ACS must specify windows

    in my computer to which the user tries to open a session. Because the ACS cannot determine this information

    of authentication requests that send AAA clients, it uses a name of generic workstation for all applications.

    Use CISCO under the name of the workstation.

    In the local domain and in each trusted domain and a child domain that uses ACS to authenticate users.

    ensure that:

    ? A computer named CISCO account exist.

    ? All users that Windows will authenticate are allowed to connect to the computer named CISCO.

    For more information, see the Microsoft documentation for your operating system.

    Go down to da external user---> DB Configuration---> Windows---> Configiure--->---> RA remote agent choose in the drop-down list---> Summit.

    ACS will now use this remote agent.

    Kind regards

    ~ JG

    Please rate if this helps

  • ACS Remote Agent

    HI guys,.

    I installed the Remote Agent ACS on my AD controller. I can add the agent to ACS... but I do not see the Windows authentication avaiable in the agent...

    The Agent runs with a service account that has all rights AD.

    Anyone able to help?

    Make sure that this worm device software and remote agent are the same.

    To display the version of CSAgent.exe, type csagent.exe - v, and then press ENTER to command line

    C:\Program Files\Cisco\CiscoSecure ACS Agent\csagent

    Kind regards

    ~ JG

  • WLC centralized with several remote Sites

    Hi people,

    I read the documentation of design for wireless devices, and I can't find a definitive answer to the following:

    Is it possible to have a WLC centrally (in a DMZ), who controls several remote sites?  Each site must have the same SSID, however the IP subnet will be different at each site.

    I have attached a base PDF showing what we are trying to achieve.

    Thanks for your help.

    Kris

    Of course, you could put either the AP mode H-REAP so that the data of the customer traffic is enabled locally to the AP or you can use groups of AP.  With groups AP customer traffic be dug to the controller and group AP policy would determine which interface / VLAN, traffic should be poured in.

  • Cisco ACS & remote agent

    Hello

    Is it mandatory that remote agent for CSA will be installed on the primary domain server, would this work if it were to be installed on a virtual server that is a member of the main domainserver? This should be used for authentication using a vpn.

    What impact is remote agent has on the operation of the wrt the CPU server, disruption, etc.

    Thank you.

    ACS can be installed on a member server.

  • ACS 4.2 Remote Agent on Server 2008 R2

    Hello

    We migrate our 2003 to 2008 R2 domain controllers and would like to know if the remote agents are compatible to run on 2008 R2.  I saw the release notes that RAS have been tested on 2008 SP1 but not R2.

    Can someone advise or confirm that RAS are supported on 2008 R2?

    We are running engine Solution and the fix 4.2.1.15 4.2.1.15 - 1.  RAS are the same version.

    Thanks in advance for your help.

    Well, it is a known bug of improvement:

    CSCta35271    Support for Windows server 2008 R2

    ACS 4.2.x supports all the latest versions of Windows 2008. It only supports the registered version. You can also consult the release notes.

    Section of OS supported

    -Windows Server 2008, Standard Edition

    -Windows Server 2008, Enterprise Edition

    -Windows Server 2008, Standard Edition, Service Pack 2 Japanese

    -Windows Server 2008, Enterprise Edition, Service Pack 2 Japanese

    This bug can get fixed in upcoming Release\patches. It's in the pipeline/roadmap and the development team working on it

    Regds,

    JK

    The rate of useful messages-

  • The Remote Agent Upgradition

    We need to migrate ACS version 4.2.0.124.16 to 4.2.1.15.8.The same way we have Remote Agent 4.2.0.124.14 to 4.2.1.15.8(hopefully la fois ACS et RA doivent s'exécuter sur la même version).

    What is the procedure to upgrade RA on Win 2003... ? (Backup file while migration)

    Do we not have to uninstall before proceeding... ?

    ini and config file provider review... ?

    Restoration...?

    All quick help on this would be helpful...

    Yes you need to uninstall the previous installation of RA before upgradeing to 4.2.1.15.8

    I have noted problems with patch 8, sometimes it create problems with ACS services. I suggest you apply.

    Should not take backup of the .ini file. During the installation of RA, it would invite, you can enter the IP address of your primary SE ACS.

    Kind regards

    Jousset

    The rate of useful messages-

  • ACS 4.2 Remote agent compatibility issues.

    I did a little reading on the compatibility of remote ACS 4.2 with Windows 2008 R2 agent, and it seems that the only way out is to upgrade the ACS to 5.2. We have Cisco ACS 4.2 SE and I would like someone to confirm that I have installed what happens if the remote agent on a Windows 2003 server of Member rather than the 2008 R2 domain controller. Such a scenario will work?

    Comments are appreciated.

    Concerning

    Yes, here's what a bug documented with this CSCtg37183 information:

    http://Tools.Cisco.com/support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtg37183

    Excerpt from the previous link:

    ACS 4.x does not support the Server 2008 R2 to AD.

    Symptom:

    ACS 4.x does not support authentication to a back-end Server 2008 R2 Active Directory.

    Conditions:

    ACS 4.x
    Windows Server 2008 R2 installed on the domain controller
    ACS or remote agent installed on a member server in the environment (even if the Server 2003/2008)

    Workaround solution:

    Install the ACS or the Remote Agent on a domain controller 2003/2008

    Cisco does not support this scenario because sometimes work well other doesn't work at all, so nobody wants an unstable network right, unfortunately workaround doesn't help much. Although there is an ACS 5.2 trial version that you can test, let me know if I can get you the links.

  • A remote agent sends multiple ACS journal.

    Could you please show example of how to configure more ACS to a remote agent. I tried to add ConfigProviderHost in CSAgent.ini as follows:

    ConfigProviderHost = 192.168.1.x, 192.168.2.x

    But this isn't a job. The remote agent has not earned any newspaper.

    I need to add the remote agent in the network menu or modify CSAgent.ini or...

    Please notify.

    Thank you.

    Nash

    Hi Nash,

    I think you should level version of the ACS SE 4.2 (in your case).

    And then upgrade your software to Remote Agent 4.2 and everything will work.

    The problem is that the version a single agent (4.x) can not serve two distinct versions SE

    You can use only a single hosting provider with more customers.

    ConfigProviderHost = 192.168.1.1

    Kind regards

    -Aryan

  • Remote agent ACS could not start

    Hello

    I installed the agent remmote ACS for windows from the ACS 4.1 Update CD (the CD migration is not found). I followed the guide of installation and configuration of the remote agent. In the services window I assigned the user of services created in ad in the log on tab and I stopped the process. When I try to start a warning message is displayed that explains the process carried out and stopped. How can I solve this problem? the software is on the CD to upgrade not the right one?

    Seems to be a permission problem. Make sure that this remote agent running Server account is part of the domain administrators group. If she is already using domain administrator account, then do use the local account. It should work.

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.1/installation/guide/remote_agent/Rawi.html#wp300510

    Let me know how it goes

    Kind regards

    ~ JG

  • Remote agent ACS - can I install on windows server 2003 64-bit

    I have Setup tehfor customer 4.2 ACS to authenticate the client wirneless, ACS have to communitate with AD (windows 2003, Enterprise Edition, 64 - bit). Can I install remote agent (ACS 4.2) for ACS ACS can contact the AD to do?

    Please help me.

    Currently we do not support 64 bit OS.

    Kind regards

    ~ JG

    Note the useful messages

Maybe you are looking for

  • Firefox crashes after startup

    HelloI've updated to Firefox 8.0 today. When we ask him to do, I disabled an add-on (ICQ Toolbar). Since then, Firefox crashes immediately after opening. I can't even try and see if it boots up in safe mode, because I do not understand this measure.

  • Z220 CMT Workstation: restore the system to factory settings.

    Model: Hp Z220 CMT WorkstationOS: Windows 7 ProfessionalI'm trying to restore my computer to factory settings. I pressed ESC several times at the start to the top of the computer. Select the system restore, but the computer just hoot to Windows form.

  • Equium L40-14i - can I get a recovery disk?

    Hey,. I'm stuck with that laptop right now because when I did a scan for virus about 4 weeks ago we found 179 virus and endless malware, and since this analysis I can start is no longer a normal Windows Vista 32-bit area unless it is Safe Mode. When

  • All my pictures have disappeared...

    I have an iPad 4 and I went on my photos and all my photos and videos have disappeared. When I go into the settings, it still says I have more than 8 GB of photos and videos, but they are not there. I tried to reboot and turn my new iPad but nothing

  • Where is the Clipboard on Windows 7?

    I recently bought a Dell Windows 7 Professional 32-bit.  I can't find the Clipboard on the operating system.  Perhaps it is not come with one.  If so, is there a Microsoft site where I can download a Clipboard and install it on this machine? I would