Windows domain account to view reports / manage the ACS server.
All,
We have a Cisco ACS 5.2 deployment (device). It has existing integration with Active Directory. We use it with RADIUS to authenticate our users wireless and GANYMEDE to manage our network equipment.
RAY reports are useful for other teams (except my own) in order to resolve account lockouts and password (everyone forgets to change the password on his phone).
I would like to allow this team and other access to the report of RADIUS authentications.
I want them to be able to use their domain account to do this.<------- this="" is="" mandatory,="" based="" on="" our="" security="">------- >
We tried using an account local and which works very well.
My system tells me that domain accounts cannot access the administrative parts of ACS.
Is this true?
We have the support to allow us to upgrade to the latest version of the ACS.
5.4 of the ACS, it is possible to authenticate and authorize the directors of external stores, including AD accounts
Tags: Cisco Security
Similar Questions
-
Unable to view and manage the app via the desktop, the wheel is idling. Mac os 10.11.1
Hello
Please check the help below document:
Does not open App | Wheels of progress turn continuously
You can also view the nets below where this issue has been addressed:
Adobe Creative Cloud / Desktop App / Home Screen: constant spinning wheel
Creative Cloud Desktop App taped blue spinning wheel after update.
-
Hi there u clvr g33ks. Wu can help me slve ths prblm? My XP PC clock does not have to be updated; error report is: "the RPC server is unavailable"? I have tried pretty much everything hv what is allocated to me.
Hello
You can view these steps
a. Click Start, type CMD. EXE and press ENTER.
b. run the following commands one by one. (Press ENTER after typing each command.)NET STOP W32TIME
W32tm /Register
NET START W32TIME
-
Configuring the ACS server on windows server
Hello
I started to prepare my CCNA security and tried to configure AAA using ACS 4.2 on windows server 2003.
I have configured the router to use the AAA authentication with the laboratory of cbtnuggets from ACS server.
I checked the accessibility of the ACS server to client router and vice versa and also configuration.
The problem is I'm not able to authenticate using ACS server, the router uses local authentication and I have no why the router communicates not eith ACS server.
Help PLZ.
Configuration of my router from AAA.
===============================================
AAA new-model
!
!
AAA authentication login default group Ganymede + local
exact AAA authentication login group Ganymede + local
AAA authorization exec default localRADIUS-server host 192.168.1.25 single-connection key ciscoacs--> (192.168.1.25 ACS, the key configured on the ACS server server is also ciscoacs)
line vty 0 4
exact connection authentication================================================
I created a user on ACS server and I believe that when I'm trying to telnet to the router I should use the user name and password configured on the ACS server.
When I try to use, authentication fails, and also if the router accepts locallly configured user details then I think there was no communication between the router and the other GANYMEDE ACS server + will be used for authentication and if no communication between the router and acs server then only it should be the responsibility of local user
Please help me.
reports and activity--> passed authentication
reports and activity--> failed attempts
Rating of useful answers is more useful to say "thank you".
-
local user name and password if the ACS server fails
Hello
I have every router and switch configuration for authentication of the connection via the ACS server. I used these 12 lines below and it works very well. Each engineer has their own account.
AAA new-model
AAA of default login authentication group Ganymede + activate
the AAA authentication enable default group Ganymede + activate
AAA authorization exec default authenticated if
AAA authorization commands 15 default group Ganymede + authenticated if
AAA accounting exec default start-stop Ganymede group.
orders accounting AAA 15 by default start-stop Ganymede group.
Default connection accounting AAA power Ganymede group.
AAA - the id of the joint sessionRADIUS-server host x.x.x.x
RADIUS-server application made
radius-server key, regardless of----------------------------------------------
I would add to this a local username and password so that if the ACS server was offline engineers have yet to connect with a knowledge of username and default password
username privilege 15 secret mypassword MYUSERNAME
line vty 0 4
local connectionQ. How do I make ACS a first preference and connection server only local users username and password if the ACS server is down?
Kind regards
Kevin
Now you have the password to enable as the fall back method:
AAA of default login authentication group Ganymede + activate
Change 'enable' for 'local' and the local (to the router) database of user names and passwords is used.
The same works to activate authentication (the second line "authentication, aaa... ("in the config that you posted).
-
Whence the ACS server get the DNS Info for the IP pools?
I'm changing the DNS servers that my VPN users are assigned from the pools of IP on the ACS server. Where IP pools Gets the DNS server information. I changed the IP addresses of the DNS on windows server and rebooted. But VPN clients are always assigned the old DNS servers.
ACS ip pools do not grow the DNS server information
It is either transmitted from the setup of group for the VPN concentrator or
It is to be send to the setup of the user/group ACS > attributes Radius (VPN 3000) > [026/3076/005] primary DNS.
I hope this helps.
Concerning
Rohit
-
The title says pretty much all this. Microsoft Accounts has my wrong email address and it took a few days to correct, but when I tried to order in the games section of the app store, it still has the old address (which went nowhere) and would not be the service order. How can I get the correct email in the app store?
Hi EddySims,
Thanks for posting your query in Microsoft Community!
I understand that you are not able to download the app from the store Windows applications as it has the old email address.
Please answer the question
(1) have you tried to connect with the new email address?
(2) did you get an error message?
If this only happens in Windows Apps store, I suggest you follow the steps below to reset the cache to store and see if it works very well.
(a) press the Windows key + R
(b) type WSReset.exe and press OK
See also,
What to do if you have problems with a soft:
http://Windows.Microsoft.com/en-in/Windows-8/what-troubleshoot-problems-app
I hope this helps to solve the problem! If still persists, please do not hesitate to post. We will be happy to help you.
-
AAA GANYMEDE + accounting - CLI question by user not appear in the report of the ACS.
Can I know why CLI cancelled by the user does not show on GANYMEDE ACS accounting report. The length of time is displayed, but I also wanted to connect what is the commands issued by the user.
WHA is missing here?
enable AAA authentication login VTY P1_ACS local group
Group default AAA authorization exec local P1_ACS authenticated by FIS
AAA authorization exec CONSOLE none
AAA exec by default start-stop accounting P1_ACS group
AAA commands 5 default start-stop accounting P1_ACS group
AAA commands 15 arrhythmic default accounting P1_ACS group
Accounting logs command is stroed in the newspapers of the administration of Ganymede.
There is also a known issue on ver 4.1.1 and we must
apply the ACS 4.1.1.23.5 patch to fix the problem.
Patch for the unit is available on
http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-Soleng-3DES
The patch name: ACS SE 4.1.1.23.5 rollup
Acs hotfix for windows is available on
http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-win-3DES
The patch name: ACS 4.1.1.23.5 rollup
CCIE Security
-
How can Windows Picture and Fax Viewer - I specify the editing program?
I set things up so that Windows Picture and Fax Viewer is the default program when I opened a variety of types of image files, which allowed me to get a quick overview without waiting for a program to load full image editing. What I need to be able to do is to specify which program is then launched by WP & FV when I click on the bottom right of the screen edit button - one with text that says "closes this program and opens the image in edit (Ctrl + E).
If I click with the right mouse button and select 'Open with' and then I can select in the usual list of possible programs, but what I want is to set a default value for each file type so that a left click of the button automatically opens the appropriate program. I tried the "program to choose...". "and"Always use the selected program to open this type of file"route after a right-click on the button, but what is happening is that the selected program then becomes the global default and circumvents WP & FV altogether.
Any ideas?
I set things up so that Windows Picture and Fax Viewer is the default program when I opened a variety of types of image files, which allowed me to get a quick overview without waiting for a program to load full image editing. What I need to be able to do is to specify which program is then launched by WP & FV when I click on the bottom right of the screen edit button - one with text that says "closes this program and opens the image in edit (Ctrl + E).
If I click with the right mouse button and select 'Open with' and then I can select in the usual list of possible programs, but what I want is to set a default value for each file type so that a left click of the button automatically opens the appropriate program. I tried the "program to choose...". "and"Always use the selected program to open this type of file"route after a right-click on the button, but what is happening is that the selected program then becomes the global default and circumvents WP & FV altogether.
Any ideas?
====================================
See the following article:Change the default image editor
application, called from Windows
Picture and Fax Viewer
http://WindowsXP.MVPs.org/imgeditor.htm
(download the free utility - Imgeditor.zip)More information:
How to open your choice of image editors when
by clicking on the button Edit in the Windows image
and Fax Viewer screen.Proceed with caution and at your own risk *.
(FWIW... it's always a good idea to create a system)
Restore point before editing the registry)OK... go to... Start / run and type... "' regedit ' without
the quotes. Then click on... OK... or press... Come in.In the registry... Editor drill down to:
HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\edit\command
In the data column, you should see:
"% systemroot%\system32\mspaint.exe" "%1".
(where you see * mspaint * in the example... you'll be)
See your current default)Replace the key with the path to the program that will be
being your default image editor. I tried to Picture It! 7 sort
Here's what I changed to."C:\Program Files\Microsoft Picture It! 7\pip.exe"'%1 '.
Now, my images still open in the picture and Fax Viewer
But if I left, click on the button Edit... Picture It! 7 opens.To replace the string...
'Default' to select, left click.
Reach... Edit / change...
In the "Edit String" field...
Copy / paste the path to your program choice:
"C:\Program Files\? \???. "exe" '%1'
Left click... Ok.
Now, your images will always open in the picture and Fax
Viewer, but if you left click on Edit button... your image
editing program opens...Good luck.
Volunteer - MS - MVP - Digital Media Experience J - Notice_This is not tech support_I'm volunteer - Solutions that work for me may not work for you - * proceed at your own risk *.
-
Install Adobe Application Manager: "the remote server does not appropriately."
I am running Windows 7 and have signed today for the trial of the creative cloud. I am trying to download my first application (InDesign). When you try to install Adobe Application Manager I download a 1866 KB file, then when I try to run it I get this error message (again and again, throughout the day): "the remote server does not properly. Please try after a few minutes. »
The only other things I can think of that may be relevant are 1) I have a few other licensed Adobe products installed on my drive (Photoshop, Illustrator, and Acrobat). (2) I have a few programs running, such as Spotify background; and (3) I have tried this for a work computer and I wonder if the network firewall or my permissions to download which is streaked with this place.
Thanks for any help you can give.
Nate_unhappycloudman this error has actually been resolved for countless people once their computer or the network is correctly configured. We'll find a good starting point for possible causes on a computer at individual sign in or activation errors. CS6, CS5.5, Perpetual CS6 subscriptions - http://helpx.adobe.com/x-productkb/policy-pricing/activation-network-issues.html.
If your network is managed, please contact us and work with your I.T. Department as stated earlier in this thread.
-
Reports to the internal server - e-mail ID question
Hi all
I explore the possibility of using the "internal report to the server" to capture the results of quizzes.
I used successfully the possibility of reports via acrobat.com, but try to avoid the fact that our students need an acrobat.com account. So, I explore the Server internal option.
During the validation of the results, he asked for the learners name and email ID.
So here's my question - actually must "email ID" be an e-mail address or don't do any unique identifier? Should be a real email or what their employee ID?
Thank you
From what I can see and have played with, the test Analyzer uses the email address to identify the different types of learners. But it doesn't have to be a real email address.
For example, I am able to use the world 'TEST' as my email address and I'm still able to present my results and quiz Analyzer that will recognize in as long as learner. I hope this helps.
-
Windows XP service pack 1 fails with the error "server has not responded.
After that a delay of a minute or two, running the SP1a update .exe (sp1aexpress_usa.exe) well failure I have an active Internet connection
It does not work every time with a "the server has failed" after telling me that this error has occurred when trying to download files from XP Service Pack 1.I tried four times over a period of three hours is not an appearance of time.Thank youJimHi Jim,.
If you already have the Service Pack 1 (SP1) is installed, we do not recommend to install SP1a. Instead, I you suggest to download and install the Service Pack 2 (SP2) and then update SP3 to continue to receive.
For how to obtain the latest service pack, see How to obtain the latest Windows XP service pack
See also: information about Windows XP Service Pack 3
Note: The Support for Windows XP with Service Pack 2 (SP2) will end on July 13, 2010. If you are running Windows XP SP2 after support ends, you will not receive updates of security for Windows. To maintain your Windows XP computer up-to-date download Service Pack 3 via Windows update.
-
Is there a problem with accounting and 4.1 of the ACS
Good day to all,
I just installed a new server with ACS 4.1.
This new installation 4.1 ACS is approved, I will retire my old server that ACS 3.1.
At this point, the only problem I have with ACS 4.1 is with the accounting.
For example:
I used a test-router with all the necessary config pointing to my old 3.1 ACS. Everything works fine (authentication and accounting). If I enter a command on the router test it's journal on GBA 3.1.
Now, if I change the test-router to point to the new 4.1 ACS, the ACS 4.1 will authenticate the router test correctly, but won't save any command that I enter the router test. I did a shot between the test-router and 4.1 of the ACS and the router test sends accounting statement ACS 4.1.
There are many different configuration of ACS 3.1 4.1, but as far as I can see the config on the two ACS is as similar as possible.
Y at - there anyone out there who could do 4.1 ACS to process accounting properly?
Any idea will help you.
Thank you
Frank
Here is my config:
AAA new-model
AAA authentication login default group Ganymede + local
connection of AAA No.-AUTH authentication no
AAA authorization exec default group Ganymede + local
AAA authorization commands start-stop Group 1 Ganymede +.
AAA authorization commands start-stop group 15 Ganymede +.
AAA accounting exec default start-stop Ganymede group.
orders accounting AAA 1 by default start-stop Ganymede group.
AAA accounting command 15 by default start-stop Ganymede group
!
192.168.100.16 host key radius-server *.
(the above command is the only command I change to point the finger 3.1 ACS or ACS 4.1)
RADIUS-server application made
Please use the following link. It has 4.1 cumulative patch that contains the hotfix for bug.
http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-win-3DES
Don't forget to download the readme text also.
Rate me if it helps.
-
Can the ESXI 5.0 and Vmware View coexist on the same server blade
Hi team, sorry for the basic question, but can I install the ESXI and Vmware View on the same server?
Kind regards
Ismail
VMware view installs inside a server operating system and he can definitley be installed inside a server running on top of vSphere.
-
Hi all
I was trying to restore the configuration to a TFTP server, but it fails.
VIC-acs01 / admin # repository restore ACE-Config-160922 - 1542.tar.gpg repository acs
Restore requires a restart of the ACS services. Continue? (yes/no) Yes
Start the restore. Please wait...
% of ongoing restoration: from restoration... 10% have completed
% of ongoing restoration: recover the repository backup file... 20% completed
GPG: decrypt_message failed: unknown system error
tar: this doesn't look like a tar archive
tar: backup/appcomponent/db/acs.db: not found in archive
tar: backup/appcomponent/db/acs*.log: not found in archive
tar: leave with State failure due to previous errors
% of current restore: backup data decryption... 25% completed
% Error: unable to complete the restore of the ACS: the backup file decryption failed. Key encryption incorrect or corrupted download of the repository)VIC-acs01 / admin # sh historic restoration
Thu Nov 10 20:06:16 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - acs script error
Thu Nov 10 20:19:37 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - acs script error
Thu Nov 10 20:28:36 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - decrypt failed
Thu Nov 10 20:30:11 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - decrypt failed
Thu Nov 10 20:34:00 PST 2016: ACE-Config-160922 - 1542.tar.gpg the repository repository restore: error - decrypt failed
VIC-acs01 / admin #.VIC-acs01 / admin # sh run | repo b
repository repository
URL of tftp://10.10.79.13/
!VIC-acs01 / admin # repository repository sh
% Protocol can't list directories
VIC-acs01 / admin #.Any help would be appreciated.
FC
Hey FK,.
Yes, you can add another repository.
Kind regards
Kanwal
Note: Please check if they are useful.
Maybe you are looking for
-
How to add captions to the existing slide show in iphoto?
How can I add captions to my slide show photos in iphoto? Slideshow already exists, I just want to add captions... I find no "add text" or settings and I don't see any 'touch gear' either. Help?
-
How to view stereo channels separate on the timeline
With the help of FCPX 10.2.3 I want to be able to equalize my chanel left and right separately. But I can't find any way to separate the left and right channels on the timeline or edit them separately in Inspector audio. Thanks for your suggestions?
-
USB 2.0 Port Replicator II - need drivers Vista
You have the drivers windows vista for usb port replicator?Thank you.
-
Dock/car driving mode - Possible problem
So I got the Dock drive from Verizon a few days ago and when I connect it phone randomly takes a song from my library "play music" and starts playing - I then have to get in and out of the app for him to stop Also while driving when the phone detects
-
-Properties foilder- Type: File folder Location: C:\Documents and owner Settings\Temp Size: 3.71GB Size on disk: 3.78 GB Contains: 78, 981Files, 380 records Can q. I delete files (Temp folder)? Q. can