vpn ACS 5.8 using AD and external server OTP authentication

Hello

is it possible to authenticate a user by using Active Directory, the internal database and server OTP for password?

what I want to achieve is:

-If the VPN user belongs to a specific group of our communication... to search for the user in this group and if the user exist that apply to an external server (activeidentity) password OTP

-If the user belongs to the internal ACS group, authenticate internally.

until now, I've been able to authenticate users with just the OUTER (active identity) but search AD server is not performed.

Thank you.

Yes!

Go to the access policies > Access default network > identity > select an option button "rule basis of selection of result. Here, you can use more storage of identity based on the State that you have.

It will be useful. -Jousset

Tags: Cisco Security

Similar Questions

  • How can I keep IE and FireFox Favorites in local sync to my PC only, without the use of an external server or import/export?

    FireFox Sync is not an option, because the use of an external server is not allowed.
    Use of third-party modules is not really an option.
    Import/export is inefficient because it is not put them in the same exact place in every browser.

    I am happy to be able to use the same favorites/bookmarks file if it is an option.

    Thank you

    You do not have.

    Sorry, IE and Firefox use different methods of storage Favorites / Bookmarks to data that are not compatible with the other program.

  • Impossible to listen to the music or sounds using internal and external speakers

    Original: connect external speakers

    I have an Acer Aspire Z5700 all-in-one computer.  I have two external speakers with an audio jack and a USB port that I can connect to the computer and I when it is connected to the computer, I hear out of them my question is how to get the sound of the computer system internal and external speakers at the same time?

    Hi Joseph,.

    I would keep informs you that it is not possible to play sounds or music using internal and external speakers at the same time.
    You can play music using any one option at a time, either the internal speakers or external speakers.
  • Best editing for Adobe Premiere Pro using laptop and external drive

    I'll confess that I'm not a particularly technical person. But I am learning!

    So I want to ask a simple question and hopefully get some good advice.

    I'm editing a feature-length documentary on Adobe Premiere Pro. I have a lot of HD footage, and I want to optimize my drives to optimize performance. To that end, I recently bought a StudioRAID 4 to glyph.

    I currently work for a Mac Book Pro. I use Mac OS 10.9.5.

    Processor: 2.66 Ghz Interl Core i7

    Memory: 4 GB 1067 Mhz DDR3 (2 GB 2 benches)

    I searched a bit on how to better implement my discs, getting some useful infor here: https://forums.adobe.com/thread/662972 and here: https://www.video2brain.com/en/lessons/optimizing-hard-disks

    But there is a little too much information - and I'm getting lost. Use a 2 disk configuration tips? Or should I partition my drive of new glyph and use the 3 disc mounting configuration.

    I'd appreciate certainly all of the tips!

    Thank you

    Rebecca

    partition the disks will not help and will not change readership by this ranking. better performance would use raid-0 on the StudioRaid of glyph and 2 disk configuration in the table. Make sure that there is a backup of the raid, in case something happens.

    also 4 GB of ram is dangerously low, you can upgrade to 16 gb.

  • How to display dynamic menu with the parent and the child using c# and sql server

    Hello

    Can you tell me

    What is menu given Dynamics example

    How can u use my dynamic menu added project in c#

    This menu is display with only the data from sql database.

    Menu with the help of a parent node and a child.

    check the element all in sql server and adding one by a dynamic menu.

    Hello

    Thank you for writing to Microsoft Communities.

    I recommend you post your query in the following forum.

    http://social.msdn.Microsoft.com/forums/en/category/SQLServer/

    Hope this information is useful.

  • PES and GSS server load

    The documentation States it is advisable to run 2 or more GSS and I wonder if I can just run 1 GSS on the same instance as my PES? I'm trying to understand what kind of work load a GSS and server PES takes in a production environment, not yet in production. We do not run awareness, research, CCS, or ACI and the only scenarios that we have configured are for individual events and actions, so it doesn't seem like the PES or GSS are facing a lot of load and should have no problem running on the same server. I realize that every site is different, so there is no clear answer, but maybe someone can help explain the expected load of these 2 servers when running workflows and STANDARD scenarios.

    PES and GSS servers can run on the same instance.
    If it has no flow of work or obtaining scenarios published frequently then PES server will have minimal use.
    And GSS server manage collective scenarios like sending promotional emails etc.
    If you don't have many collective scenarios with the GSS and PES on the same server will not impact lift.

    We used only GSS and a PSE configured on the same server on 120 server cluster and didn't find any problems.
    I used a setup similar to many customers.

    Peace
    Shaik

  • ACS 3.0 Windows, VPN, remote access and external databases

    I'm trying to implement a VPN solution, and most are very good.

    We have a VPN concentrator, which authenticates with CSACS and who, in turn, back off the coast of authentication with a Windows domain. Unknown user policy allows new users themselves create dynamically.

    The VPN uses the Cisco VPN client. The hub is visible on the internet, and the bit works fine.

    Bit difficult, but we are also trying to set up the access line by using a phone company for users who do not have their own internet access.

    I have problems which to authenticate to the Windows domain.

    If I manually create a user and add a chap password, this user can authenticate OK. If I manually add a password of chap user can authenticate.

    If the user does not exist I get "user CS unknown', if I did not add a password manually, but the user is I get"Invalid password CS CHAP", so it seems that the problem is is interrupting this authentication against the field, but I don't see why.

    The telephone company radius server in my network as a aaa client configuration and is almost the same configured as VPN concentrators (the difference is the Conc VPN is configured as 'RADIUS (Cisco VPN 3000)' and as 'RADIUS (IETF)' radius server)

    Any thoughts?

    You cannot use CHAP to authenticate a domain Windows, the way THAT CHAP requires the password must be stored is incompatible with the Windows passwords. You need to configure each connection Dial-Up Networking to dial-up users to use MSCHAP or PAP.

  • External hard drive suddenly cannot open it give the message error "you must format the disk in the drive until you can use it", and your hard disk is 0 bytes

    External hard drive can not suddenly open - fixed

    my external hard drive worked very well all the time, but suddenly I can't open it more, when I tried to open it, it gives the error message "You must format the disk in the drive until you can use it" and my hard drive is 0 bytes, average there is no file in the hard drive. Average, all the data inside hard disk are gone!

    Hello muhammad.

    Before you do anything with this player, you can search online for some data recovery utilities so that you can try to recover your data.

    What operating system do you use?

    Have you tried running chkdsk on the drive?

    Let us know.

    Best regards

    Matthew_Ha

  • My mouse pointer moves in the opposite direction, I intend when I use the touchpad on my laptop. It works fine when I use my docking station and external mouse. How can I fix it?

    I'm using Windows Vista with a Sony Vaio laptop.  At the office, I have a docking station with keyboard and external mouse.  Everything works fine with this Setup.  But when I unplug the docking station and use the touchpad on the laptop, my mouse pointer moves in the opposite direction, that is my intention.  I move my finger and the pointer down.  I move to the right and the pointer goes left.  How can I fix?

    Go to start /Control Panel, and then double-click the icon '' mouse. '' When this window opens, select the tab "Touch Pad" at the top. There's a box near the bottom called "Touch sensitivity", click on that. Change the settings a little bit lower than what they are currently at.

  • The extended and external use .c and .h class?

    Goal: Make main.c become smaller.

    Problem: When the .c file is created, eror show "implicit declaration of function 'show_dialog_message' [- Wimplicit - function-declaration]" on show_dialog_message

    Question: How to use class extended/external .c and .h? or something wrong in the following coding?

    Mini code: all the required classes are included.

    The main.c

    #include "helloworld.c".

    If (EXIT_FAILURE is {resize (event))}
    stop = true;
    }

    HelloWorld.c:

    int resize(bps_event_t *event) {}
    If {(event)
    snprintf (msg, MSG_SIZE, "Hello World!");
    show_dialog_message (MSG);
    }
    Return EXIT_SUCCESS;
    }

    HelloWorld.h

    int resize(bps_event_t *event);

    Thank you for your attention,

    Hello

    In main.c include helloworld.h, .c

    .c files are compiled independently.

    the .h files first implemented in .c files report.

    So when referencing functions implemented in other .c files, include .h file to before--declare variables and functions.

    It will work in this case, but generally it is better to guard multiple of inclusion in the .h file using the preprocessor commands:

    HelloWorld.h

    #ifndef HELLOWORLD_H
    #define HELLOWORLD_H
    
    int resize(bps_event_t *event);
    
    #endif // HELLOWORLD_H
    
  • design of huge cell MIMO 3 x 3 using splitters and antenna external omni

    Hello

    The requirements are the following:

    Offers complete coverage for a basement.

    Maximum number of users competitor is between 5-10

    VoIPoWlan

    Low bandwidth

    In the basement is distinguished from corridors and technicrooms isolated by thick walls brick and metal doors.

    In order to ensure full cogerage voip would require a large number of AP they are quire expensive and high flow is not required.

    Is it a good idea to use only a few AP with dividers and external antennas?

    For example:

    1 x dual band AP 3 x 3 mimo

    3 x dispatchers dual band, each of them has 3 output ports

    3 dual-band 3 x 3 mimo antennas 2 omni and a directional

    The basement has 2 rooms and a corridor.

    Each of the rooms has an omni antenna installed, corridor has one directional.

    Antennas are connected by separators.

    Given that the cable lengths are not the same, I may need to use amplifiers also. Is this correct?

    What about the problem of the node that is hidden, when 2 wlan stations are connected to the same access point can not hear each other?

    This cell can be huge. I gave a small example, but in our project, we need cover a basement of a square that contains many rooms and corridors. Obviously, you must use several AP + combos splitter basically repeat this small example, I gave.

    The main goal is to save money by reducing the number of AP and switches. We did the sitesurvey we found that 40-45 AP is needed. My idea is to use up to 10 AP + battery separator.

    Has anyone done a similar deployment?

    The disadvantages?

    Thank you!

    István

    MIMO radios are filled with a lot of very complex mathematics.  It phase shifts handels, changes of time, reflections, roaming, etc..  You are wanting to fundamentally change the design of their operation.

    It will be terribly.

    If it were me, I would correctly, based on the your wireless site survey, or not at all.  I don't want to be associated with a design that works badly.  I would walk first of employment.  But that's me.

    It is your reputation and your choice.

  • VCAC 6.0 when and why to use an external server for Orchestration

    When and why use an external server orchistrator and not that which is incorporated into the VCAC

    Hello

    generally, we recommend to use a server external vCO, for the following reasons:

    (if apply current vCAC 6.0.1 version only, I hope not for future versions) the built-in vCO has a build number slightly less than version 5.5.1 vCO GA so a few new plugins only install & works correctly.

    An instance separate vCO is more weakly coupled to the vCAC device, so you can for example develop, operate and maintain the systems independently of each other.

    You can more easily multiple instances of vCO in cluster mode.

    If you use vCO not only in the context of vCAC, but for tasks of automation / operational General, you are not "bound" in the vCAC environment.

    Overall: more flexibility for the modest sum of just having an additional device.

    See you soon,.

    Joerg

  • Cisco ACS 4.1 for external advertising for authentication

    Hello

    We have just configured Cisco ACS 4.1 solution engine and using a Windows 2003 domain controller as a remote agent.we use as Protocol Ganymede.

    Users that are created in ACS himself are able to connect to various network devices. but users in domain (active directory) can not connect. We get the access denied message. same time we get external DB is not operational message in ACS.

    Active directory server where agent that runs in CSWINAgentlog, we get the following error 'NDLIB'... FOUND 0 TRUSTED DOMAIN.

    Could you please help us to isolate the problem.

    Thank you & best regards

    Make sure that the worm of acs and remote agent software is the same. And also execution of remote agent account must have special domain administrator rights, like the act as part of operating system and log in as a service.

    Kind regards

    ~ JG

  • 5.1 ACS is not supported ODBC and Oracle

    Hi Netpro

    Train my familiar and careless with the old version of the ACS, ACS unit I bought two 5.1 device to work in the HA function. After installation and did ' t tried configured for use with the external database with ORACLE, I see nothing. I tried to read the paper and I saw no keyword that said this support the ODBC or Oracle version. If anyone can help me what is the workaround for ACS work with ODBC and Oracle.

    Thank you

    Pitcher

    This pitcher,

    4.2 the CSA can be installed on the CSACS-1120-K9 unit simply re-Imaging it (so not really a downgrade) with a dedicated DVD.

    You can get such a DVD through an official TAC case:

    http://Tools.Cisco.com/ServiceRequestTool/create/launch.do

    Kind regards

    Fede

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • IOS VPN on 7200 12.3.1 and access-list problem

    I'm in IOS 12.3 (1) a 7200 and have configured it for VPN access. I use the Cisco VPN client. Wonder if someone has encountered the following problem, and if there is a fix.

    The external interface has the access-list standard applied that blocks incoming traffic. One of the rules is to block the IPs private, not routable, such as the 10.0.0.0 concern, for example.

    When I set my VPN connection, none of my packets get routed and I noticed that outside access list interface blocks the traffic. When I connect to the router through VPN, the router attributes to the client an IP address from a pool of the VPN as 10.1.1.0/24. But normal outside the access list denies this traffic as it should. But as soon as I have established a VPN connect, it seems that my encrypted VPN traffic must ignore the external interface access list.

    If I change my external access list to allow traffic from source address 10.1.1.0/24 my VPN traffic goes through correctly, but this goes against the application to have an outdoor access list that denies such traffic and have a VPN.

    Anyone else seen this problem or can recommend a software patch or version of IOS which works correctly?

    Thank you

    R

    That's how IOS has always worked, no way around it.

    The reasoning is to do with the internal routing on the router. Basically an encrypted packet inherits from the interface and initially past control of ACL as an encrypted packet. Then expelled the crypto engine and decrypted, so we now have this sitting pouch in the cryptographic engine part of the router. What do we with her now, keeping in mind users may want political route she is also, might want to exercise, qos, etc. etc. For this reason, the package is basically delivered on the external interface and running through everything, once again, this time as a decrypted packet. If the package hits the ACL twice, once encrypted and clear once.

    Your external ACL shall include the non encrypted and encrypted form of the package.

    Now, if you're afraid that people can then simply spoof packets to come from 10.1.1.0 and they will be allowed through your router, bzzzt, wrong. The first thing that the router checks when it receives a packet on an interface with a card encryption applied is that if the package needs to be encrypted, it is from his crypto ACL and its IP pools. If he receives a decrypted packet when it knows that it must have been encrypted, it will drop the package immediately and a flag a syslog something as "received the decrypted packet when it should have been."

    You can check on the old bug on this here:

    http://www.Cisco.com/cgi-bin/support/Bugtool/onebug.pl?BugID=CSCdz54626&submit=search

    and take note of the section of the security implications, you may need to slightly modify your configuration.

Maybe you are looking for

  • 2800-400 BIOS update will allow LAN wireless 802.11 g?

    I recently bought a Belkin 54 G cardbus wireless adapter for use with my Satellite 2800-400, which has a Windows ME OS.The installer would not install a driver, even if I was told to be supported. I wrote to Belkin and they told me that it was becaus

  • HP Pavilion notebook pc network pilot g6 help

    I have recently upgraded to windows 7 ultimate, but I couldn't find a network driver that works, the only thing that miss me is my wifi. Here's my hardware ID: PCI\VEN_10EC & DEV_8176 & SUBSYS_1629103C & REV_01PCI\VEN_10EC & DEV_8176 & SUBSYS_1629103

  • Enumeration assimilating types?

    Hi, in C, you can define enumerations for different types of say base16, I have a need to create an enumeration %valeurs hexa% against only the basic base10 values. Is this possible with labview somehow. I relize I can pump the enumeration of basic i

  • Generation of signals to the NI PXI-6713, on different channels

    Dear community LabVIEW, anyone could help me please, I beg you, by the following. I want to generate sine wave using NI PXI-6713, with the same frequency of sampling, but in different times. Let's, first of all, I need to launch the generation on cha

  • disable disk automatic check at startup in Windows Vista

    How can I disable disk automatic check at startup of windows vista?