Windows domain account to view reports / manage the ACS server.

All,

We have a Cisco ACS 5.2 deployment (device).  It has existing integration with Active Directory.  We use it with RADIUS to authenticate our users wireless and GANYMEDE to manage our network equipment.

RAY reports are useful for other teams (except my own) in order to resolve account lockouts and password (everyone forgets to change the password on his phone).

I would like to allow this team and other access to the report of RADIUS authentications.

I want them to be able to use their domain account to do this.<-------  this="" is="" mandatory,="" based="" on="" our="" security="">

We tried using an account local and which works very well.

My system tells me that domain accounts cannot access the administrative parts of ACS.

Is this true?

We have the support to allow us to upgrade to the latest version of the ACS.

5.4 of the ACS, it is possible to authenticate and authorize the directors of external stores, including AD accounts

Tags: Cisco Security

Similar Questions

  • Creative cloud Office do not show App impossible to view and manage the app via the desktop, the wheel is idling

    Unable to view and manage the app via the desktop, the wheel is idling. Mac os 10.11.1

    Hello

    Please check the help below document:

    Does not open App | Wheels of progress turn continuously

    You can also view the nets below where this issue has been addressed:

    Adobe Creative Cloud / Desktop App / Home Screen: constant spinning wheel

    Creative Cloud Desktop App taped blue spinning wheel after update.

  • My XP PC clock does not have to be updated; error report is: "the RPC server is unavailable."

    Hi there u clvr g33ks. Wu can help me slve ths prblm? My XP PC clock does not have to be updated; error report is: "the RPC server is unavailable"? I have tried pretty much everything hv what is allocated to me.

    Hello

    You can view these steps

    a. Click Start, type CMD. EXE and press ENTER.
    b. run the following commands one by one. (Press ENTER after typing each command.)

    NET STOP W32TIME

    W32tm /Register

    NET START W32TIME

  • Configuring the ACS server on windows server

    Hello

    I started to prepare my CCNA security and tried to configure AAA using ACS 4.2 on windows server 2003.

    I have configured the router to use the AAA authentication with the laboratory of cbtnuggets from ACS server.

    I checked the accessibility of the ACS server to client router and vice versa and also configuration.

    The problem is I'm not able to authenticate using ACS server, the router uses local authentication and I have no why the router communicates not eith ACS server.

    Help PLZ.

    Configuration of my router from AAA.

    ===============================================

    AAA new-model
    !
    !
    AAA authentication login default group Ganymede + local
    exact AAA authentication login group Ganymede + local
    AAA authorization exec default local

    RADIUS-server host 192.168.1.25 single-connection key ciscoacs--> (192.168.1.25 ACS, the key configured on the ACS server server is also ciscoacs)

    line vty 0 4
    exact connection authentication

    ================================================

    I created a user on ACS server and I believe that when I'm trying to telnet to the router I should use the user name and password configured on the ACS server.

    When I try to use, authentication fails, and also if the router accepts locallly configured user details then I think there was no communication between the router and the other GANYMEDE ACS server + will be used for authentication and if no communication between the router and acs server then only it should be the responsibility of local user

    Please help me.

    reports and activity--> passed authentication

    reports and activity--> failed attempts

    Rating of useful answers is more useful to say "thank you".

  • local user name and password if the ACS server fails

    Hello

    I have every router and switch configuration for authentication of the connection via the ACS server.  I used these 12 lines below and it works very well.  Each engineer has their own account.

    AAA new-model
    AAA of default login authentication group Ganymede + activate
    the AAA authentication enable default group Ganymede + activate
    AAA authorization exec default authenticated if
    AAA authorization commands 15 default group Ganymede + authenticated if
    AAA accounting exec default start-stop Ganymede group.
    orders accounting AAA 15 by default start-stop Ganymede group.
    Default connection accounting AAA power Ganymede group.
    AAA - the id of the joint session

    RADIUS-server host x.x.x.x
    RADIUS-server application made
    radius-server key, regardless of

    ----------------------------------------------

    I would add to this a local username and password so that if the ACS server was offline engineers have yet to connect with a knowledge of username and default password

    username privilege 15 secret mypassword MYUSERNAME

    line vty 0 4
    local connection

    Q. How do I make ACS a first preference and connection server only local users username and password if the ACS server is down?

    Kind regards

    Kevin

    Now you have the password to enable as the fall back method:

    AAA of default login authentication group Ganymede + activate

    Change 'enable' for 'local' and the local (to the router) database of user names and passwords is used.

    The same works to activate authentication (the second line "authentication, aaa... ("in the config that you posted).

  • Whence the ACS server get the DNS Info for the IP pools?

    I'm changing the DNS servers that my VPN users are assigned from the pools of IP on the ACS server. Where IP pools Gets the DNS server information. I changed the IP addresses of the DNS on windows server and rebooted. But VPN clients are always assigned the old DNS servers.

    ACS ip pools do not grow the DNS server information

    It is either transmitted from the setup of group for the VPN concentrator or

    It is to be send to the setup of the user/group ACS > attributes Radius (VPN 3000) > [026/3076/005] primary DNS.

    I hope this helps.

    Concerning

    Rohit

  • I managed to fix an erronious in my new Windows 8 account e-mail address, but the app store, still has the old address and will not serve an order

    The title says pretty much all this. Microsoft Accounts has my wrong email address and it took a few days to correct, but when I tried to order in the games section of the app store, it still has the old address (which went nowhere) and would not be the service order.  How can I get the correct email in the app store?

    Hi EddySims,

    Thanks for posting your query in Microsoft Community!

    I understand that you are not able to download the app from the store Windows applications as it has the old email address.

    Please answer the question

    (1) have you tried to connect with the new email address?

    (2) did you get an error message?

    If this only happens in Windows Apps store, I suggest you follow the steps below to reset the cache to store and see if it works very well.

    (a) press the Windows key + R

    (b) type WSReset.exe and press OK

    See also,

    What to do if you have problems with a soft:

    http://Windows.Microsoft.com/en-in/Windows-8/what-troubleshoot-problems-app

    I hope this helps to solve the problem! If still persists, please do not hesitate to post. We will be happy to help you.

  • AAA GANYMEDE + accounting - CLI question by user not appear in the report of the ACS.

    Can I know why CLI cancelled by the user does not show on GANYMEDE ACS accounting report. The length of time is displayed, but I also wanted to connect what is the commands issued by the user.

    WHA is missing here?

    enable AAA authentication login VTY P1_ACS local group

    Group default AAA authorization exec local P1_ACS authenticated by FIS

    AAA authorization exec CONSOLE none

    AAA exec by default start-stop accounting P1_ACS group

    AAA commands 5 default start-stop accounting P1_ACS group

    AAA commands 15 arrhythmic default accounting P1_ACS group

    Accounting logs command is stroed in the newspapers of the administration of Ganymede.

    There is also a known issue on ver 4.1.1 and we must

    apply the ACS 4.1.1.23.5 patch to fix the problem.

    Patch for the unit is available on

    http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-Soleng-3DES

    The patch name: ACS SE 4.1.1.23.5 rollup

    Acs hotfix for windows is available on

    http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-win-3DES

    The patch name: ACS 4.1.1.23.5 rollup

    CCIE Security

  • How can Windows Picture and Fax Viewer - I specify the editing program?

    I set things up so that Windows Picture and Fax Viewer is the default program when I opened a variety of types of image files, which allowed me to get a quick overview without waiting for a program to load full image editing. What I need to be able to do is to specify which program is then launched by WP & FV when I click on the bottom right of the screen edit button - one with text that says "closes this program and opens the image in edit (Ctrl + E).

    If I click with the right mouse button and select 'Open with' and then I can select in the usual list of possible programs, but what I want is to set a default value for each file type so that a left click of the button automatically opens the appropriate program. I tried the "program to choose...". "and"Always use the selected program to open this type of file"route after a right-click on the button, but what is happening is that the selected program then becomes the global default and circumvents WP & FV altogether.

    Any ideas?

    I set things up so that Windows Picture and Fax Viewer is the default program when I opened a variety of types of image files, which allowed me to get a quick overview without waiting for a program to load full image editing. What I need to be able to do is to specify which program is then launched by WP & FV when I click on the bottom right of the screen edit button - one with text that says "closes this program and opens the image in edit (Ctrl + E).

    If I click with the right mouse button and select 'Open with' and then I can select in the usual list of possible programs, but what I want is to set a default value for each file type so that a left click of the button automatically opens the appropriate program. I tried the "program to choose...". "and"Always use the selected program to open this type of file"route after a right-click on the button, but what is happening is that the selected program then becomes the global default and circumvents WP & FV altogether.

    Any ideas?

    ====================================
    See the following article:

    Change the default image editor
    application, called from Windows
    Picture and Fax Viewer
    http://WindowsXP.MVPs.org/imgeditor.htm
    (download the free utility - Imgeditor.zip)

    More information:

    How to open your choice of image editors when
    by clicking on the button Edit in the Windows image
    and Fax Viewer screen.

    Proceed with caution and at your own risk *.

    (FWIW... it's always a good idea to create a system)
    Restore point before editing the registry)

    OK... go to... Start / run and type... "' regedit ' without
    the quotes. Then click on... OK... or press... Come in.

    In the registry... Editor drill down to:

    HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\edit\command

    In the data column, you should see:

    "% systemroot%\system32\mspaint.exe" "%1".

    (where you see * mspaint * in the example... you'll be)
    See your current default)

    Replace the key with the path to the program that will be
    being your default image editor. I tried to Picture It! 7 sort
    Here's what I changed to.

    "C:\Program Files\Microsoft Picture It! 7\pip.exe"'%1 '.

    Now, my images still open in the picture and Fax Viewer
    But if I left, click on the button Edit... Picture It! 7 opens.

    To replace the string...

    'Default' to select, left click.

    Reach... Edit / change...

    In the "Edit String" field...

    Copy / paste the path to your program choice:

    "C:\Program Files\? \???. "exe" '%1'

    Left click... Ok.

    Now, your images will always open in the picture and Fax
    Viewer, but if you left click on Edit button... your image
    editing program opens...

    Good luck.

    Volunteer - MS - MVP - Digital Media Experience J - Notice_This is not tech support_I'm volunteer - Solutions that work for me may not work for you - * proceed at your own risk *.

  • Install Adobe Application Manager: "the remote server does not appropriately."

    I am running Windows 7 and have signed today for the trial of the creative cloud.  I am trying to download my first application (InDesign).  When you try to install Adobe Application Manager I download a 1866 KB file, then when I try to run it I get this error message (again and again, throughout the day): "the remote server does not properly.  Please try after a few minutes. »

    The only other things I can think of that may be relevant are 1) I have a few other licensed Adobe products installed on my drive (Photoshop, Illustrator, and Acrobat). (2) I have a few programs running, such as Spotify background; and (3) I have tried this for a work computer and I wonder if the network firewall or my permissions to download which is streaked with this place.

    Thanks for any help you can give.

    Nate_unhappycloudman this error has actually been resolved for countless people once their computer or the network is correctly configured.  We'll find a good starting point for possible causes on a computer at individual sign in or activation errors. CS6, CS5.5, Perpetual CS6 subscriptions - http://helpx.adobe.com/x-productkb/policy-pricing/activation-network-issues.html.

    If your network is managed, please contact us and work with your I.T. Department as stated earlier in this thread.

  • Reports to the internal server - e-mail ID question

    Hi all

    I explore the possibility of using the "internal report to the server" to capture the results of quizzes.

    I used successfully the possibility of reports via acrobat.com, but try to avoid the fact that our students need an acrobat.com account. So, I explore the Server internal option.

    During the validation of the results, he asked for the learners name and email ID.

    So here's my question - actually must "email ID" be an e-mail address or don't do any unique identifier? Should be a real email or what their employee ID?

    Thank you

    From what I can see and have played with, the test Analyzer uses the email address to identify the different types of learners. But it doesn't have to be a real email address.

    For example, I am able to use the world 'TEST' as my email address and I'm still able to present my results and quiz Analyzer that will recognize in as long as learner. I hope this helps.

  • Windows XP service pack 1 fails with the error "server has not responded.

    After that a delay of a minute or two, running the SP1a update .exe (sp1aexpress_usa.exe) well failure I have an active Internet connection

    It does not work every time with a "the server has failed" after telling me that this error has occurred when trying to download files from XP Service Pack 1.

    I tried four times over a period of three hours is not an appearance of time.
    Thank you
    Jim

    Hi Jim,.

    If you already have the Service Pack 1 (SP1) is installed, we do not recommend to install SP1a. Instead, I you suggest to download and install the Service Pack 2 (SP2) and then update SP3 to continue to receive.

    For how to obtain the latest service pack, see How to obtain the latest Windows XP service pack

    See also: information about Windows XP Service Pack 3

    Note: The Support for Windows XP with Service Pack 2 (SP2) will end on July 13, 2010. If you are running Windows XP SP2 after support ends, you will not receive updates of security for Windows. To maintain your Windows XP computer up-to-date download Service Pack 3 via Windows update.

  • Is there a problem with accounting and 4.1 of the ACS

    Good day to all,

    I just installed a new server with ACS 4.1.

    This new installation 4.1 ACS is approved, I will retire my old server that ACS 3.1.

    At this point, the only problem I have with ACS 4.1 is with the accounting.

    For example:

    I used a test-router with all the necessary config pointing to my old 3.1 ACS. Everything works fine (authentication and accounting). If I enter a command on the router test it's journal on GBA 3.1.

    Now, if I change the test-router to point to the new 4.1 ACS, the ACS 4.1 will authenticate the router test correctly, but won't save any command that I enter the router test. I did a shot between the test-router and 4.1 of the ACS and the router test sends accounting statement ACS 4.1.

    There are many different configuration of ACS 3.1 4.1, but as far as I can see the config on the two ACS is as similar as possible.

    Y at - there anyone out there who could do 4.1 ACS to process accounting properly?

    Any idea will help you.

    Thank you

    Frank

    Here is my config:

    AAA new-model

    AAA authentication login default group Ganymede + local

    connection of AAA No.-AUTH authentication no

    AAA authorization exec default group Ganymede + local

    AAA authorization commands start-stop Group 1 Ganymede +.

    AAA authorization commands start-stop group 15 Ganymede +.

    AAA accounting exec default start-stop Ganymede group.

    orders accounting AAA 1 by default start-stop Ganymede group.

    AAA accounting command 15 by default start-stop Ganymede group

    !

    192.168.100.16 host key radius-server *.

    (the above command is the only command I change to point the finger 3.1 ACS or ACS 4.1)

    RADIUS-server application made

    Please use the following link. It has 4.1 cumulative patch that contains the hotfix for bug.

    http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-win-3DES

    Don't forget to download the readme text also.

    Rate me if it helps.

  • Can the ESXI 5.0 and Vmware View coexist on the same server blade

    Hi team, sorry for the basic question, but can I install the ESXI and Vmware View on the same server?

    Kind regards

    Ismail

    VMware view installs inside a server operating system and he can definitley be installed inside a server running on top of vSphere.

  • Cannot restore the ACS server

    Hi all

    I was trying to restore the configuration to a TFTP server, but it fails.

    VIC-acs01 / admin # repository restore ACE-Config-160922 - 1542.tar.gpg repository acs
    Restore requires a restart of the ACS services. Continue? (yes/no) Yes
    Start the restore. Please wait...
    % of ongoing restoration: from restoration... 10% have completed
    % of ongoing restoration: recover the repository backup file... 20% completed
    GPG: decrypt_message failed: unknown system error
    tar: this doesn't look like a tar archive
    tar: backup/appcomponent/db/acs.db: not found in archive
    tar: backup/appcomponent/db/acs*.log: not found in archive
    tar: leave with State failure due to previous errors
    % of current restore: backup data decryption... 25% completed
    % Error: unable to complete the restore of the ACS: the backup file decryption failed. Key encryption incorrect or corrupted download of the repository)

    VIC-acs01 / admin # sh historic restoration
    Thu Nov 10 20:06:16 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - acs script error
    Thu Nov 10 20:19:37 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - acs script error
    Thu Nov 10 20:28:36 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - decrypt failed
    Thu Nov 10 20:30:11 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - decrypt failed
    Thu Nov 10 20:34:00 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - decrypt failed
    VIC-acs01 / admin #.

    VIC-acs01 / admin # sh run | repo b
    repository repository
    URL of tftp://10.10.79.13/
    !

    VIC-acs01 / admin # repository repository sh
    % Protocol can't list directories
    VIC-acs01 / admin #.

    Any help would be appreciated.

    FC

    Hey FK,.

    Yes, you can add another repository.

    Kind regards

    Kanwal

    Note: Please check if they are useful.

Maybe you are looking for

  • How to add captions to the existing slide show in iphoto?

    How can I add captions to my slide show photos in iphoto? Slideshow already exists, I just want to add captions... I find no "add text" or settings and I don't see any 'touch gear' either.  Help?

  • How to view stereo channels separate on the timeline

    With the help of FCPX 10.2.3 I want to be able to equalize my chanel left and right separately.  But I can't find any way to separate the left and right channels on the timeline or edit them separately in Inspector audio. Thanks for your suggestions?

  • USB 2.0 Port Replicator II - need drivers Vista

    You have the drivers windows vista for usb port replicator?Thank you.

  • Dock/car driving mode - Possible problem

    So I got the Dock drive from Verizon a few days ago and when I connect it phone randomly takes a song from my library "play music" and starts playing - I then have to get in and out of the app for him to stop Also while driving when the phone detects

  • Local Settings\Temp

    -Properties foilder- Type: File folder Location: C:\Documents and owner Settings\Temp Size:                                                   3.71GB Size on disk: 3.78 GB Contains: 78, 981Files, 380 records Can q. I delete files (Temp folder)? Q. can