getXML('<?xml version="1.0" encoding="UTF-8"?><ActiveMessages>AAA5518<Community id=".ee6b2b0" title="Networking Professionals">  <Forum id=".ee6e1f6" title="Security"><Topic id=".ee6e1fe" private="" title="AAA"><Conversation id=".2cd4f1ba" messages="3" subscribed="yes" title="ACS 4.2 vs ACS 5.1"><Message attachment="no" canreply="yes" id=".2cd4f1ba" level="">      <Author authinfo="Implementation Engineer, World Wide Technology">ncharaipotra</Author><Timestamp>Nov 16, 2009, 1:09pm PST</Timestamp><Msgbody>If you wanted to stand up a ACS solution in your environment, which is the better choice at this time?  Is 4.2 going to be around, or is it going away for 5.x in the near future?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4f1ba/0" level="1." new="yes">            <Author authinfo=" Cisco Systems, Inc.">fasehbai</Author><Timestamp>Nov 16, 2009, 6:00pm PST</Timestamp><Msgbody>4.x will be around for quite some time, but if you have the option, go to 5. Very flexible and powerful!&lt;br /&gt;&lt;br /&gt;Faisal</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4f1ba/1" level="1.1" new="yes"><Author authinfo=" extraxi.com (reporting &amp; audit compliance solutions for CiscoSecure ACS)">darpotter</Author><Timestamp>Nov 17, 2009, 1:46am PST</Timestamp><Msgbody>I would urge caution.&lt;br /&gt;&lt;br /&gt;Carefully assess what 4.x features you need and check they are available in 5.x. &lt;br /&gt;Not only that, but check for outstanding bugs on those features.&lt;br /&gt;&lt;br /&gt;If you depend on TACACS+ stick with 4.x. If you do large scale 802.1x or NAC consider 5.x&lt;br /&gt;&lt;br /&gt;We speak to a lot of Cisco users and 5.x does not have feature parity and hasn&apos;t reached maturity w.r.t bugs etc.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" editable="yes" id=".2cd4f1ba/2" level="1.1.1"><Author authinfo=" CISCO SYSTEMS">jrabinow</Author><Timestamp>Nov 17, 2009, 3:10am PST</Timestamp><Msgbody>ACS 5.1 has just been released that includes many of the missing 4.x parity features. This includes TACACS+ specific features such as custom attributes, change passwords and other features such as RSA, custom VSAs etc.&lt;br /&gt;&lt;br /&gt;ACS 5.1 also includes a built in monitoring and trubleshooting module and the need for an additional license for these features has been dropped.</Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4f191" messages="0" subscribed="yes" title="PIX Management Access via IAS"><Message attachment="no" canreply="yes" id=".2cd4f191" level="">            <Author authinfo=" EastLink">eastlinkit</Author><Timestamp>Nov 16, 2009, 11:58am PST</Timestamp><Msgbody>Hello,&lt;br /&gt;&lt;br /&gt;I have a PIX 515E running Cisco PIX Firewall Version 6.3(5)123. I am looking to have Management users connect to the PIX with their Active Directory credentials to manage the PIX. I have been successful in configuring this for all my switches, (2950s, 2960s 3350s etc.) but it does not work with the PIX.&lt;br /&gt;&lt;br /&gt;Here is the AAA info I have:&lt;br /&gt;&lt;br /&gt;aaa-server TACACS+ protocol tacacs+ &lt;br /&gt;aaa-server TACACS+ max-failed-attempts 3 &lt;br /&gt;aaa-server TACACS+ deadtime 10 &lt;br /&gt;aaa-server RADIUS protocol radius &lt;br /&gt;aaa-server RADIUS max-failed-attempts 3 &lt;br /&gt;aaa-server RADIUS deadtime 10 &lt;br /&gt;aaa-server RADIUS (inside) host 172.18.1.1 mykey timeout 5&lt;br /&gt;aaa-server LOCAL protocol local &lt;br /&gt;aaa authentication ssh console RADIUS LOCAL&lt;br /&gt;aaa authentication telnet console RADIUS LOCAL&lt;br /&gt;aaa authentication serial console RADIUS LOCAL&lt;br /&gt;aaa authentication enable console RADIUS LOCAL&lt;br /&gt;aaa authorization command LOCAL&lt;br /&gt;&lt;br /&gt;Anyone have any clear documents or examples of a setup like this?&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;&lt;br /&gt;Craig</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4f054" messages="2" subscribed="yes" title="ACS SE multiple windows databases"><Message attachment="no" canreply="yes" id=".2cd4f054" level="">            <Author authinfo=" CLOUNET AG">dominicstalder</Author><Timestamp>Nov 16, 2009, 12:07am PST</Timestamp><Msgbody>Hi there&lt;br /&gt;&lt;br /&gt;is it possible to have multiple windows databases on an ACS SE? The problem is, that we need access to two differen domains, that are not trusted and have no super domain.&lt;br /&gt;&lt;br /&gt;Thanks a lot and best regards&lt;br /&gt;Dominic</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4f054/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 16, 2009, 8:49am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;We would require two way external/transitive trust between the two domains.&lt;br /&gt;&lt;br /&gt;There are 2 ways to work around our problem:&lt;br /&gt;&lt;br /&gt;1. Install another ACS at the remote site/domain and forward all the&lt;br /&gt;requests for the users of remote domain to that ACS.&lt;br /&gt;&lt;br /&gt;2. Configure partner domain as LDAP on the ACS (at corp site), this should not require domain trust. The only problem we will have certain authentication methods will not be supported when using ldap.&lt;br /&gt;&lt;br /&gt;Here is the complete list of stuff which is supported with LDAP:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server&apos;)"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server&lt;/A&gt;​_for_windows/4.1/user/Overvw.html#wp824733​&lt;br /&gt;&lt;br /&gt;Hope that helps!&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts </Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4f054/1" level="1.1" new="yes">            <Author authinfo=" CLOUNET AG">dominicstalder</Author><Timestamp>Nov 16, 2009, 9:20am PST</Timestamp><Msgbody>Hi JG&lt;br /&gt;&lt;br /&gt;thanks for your feedback. We now installed two more ACS&apos; on virtual machines and forward all the domain.xx suffix requests to the remote domain.&lt;br /&gt;&lt;br /&gt;Regards&lt;br /&gt;Dominic</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4efc6" messages="1" subscribed="yes" title="Switch/Router can only use PAP to communicate with IAS"><Message attachment="no" canreply="yes" id=".2cd4efc6" level=""><Author authinfo=" West Clark Community School">jbarrettwc</Author><Timestamp>Nov 15, 2009, 6:39am PST</Timestamp><Msgbody>I was securing my switches to allow users to login using radius and notice that I have to set the IAS server to PAP for the Cisco equipment to authenticate. Is there an alternative to this since PAP is clear text.&lt;br /&gt;&lt;br /&gt;[ PC ]__SSH__[Switch]___PAP___[ IAS ]</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4efc6/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 16, 2009, 9:17am PST</Timestamp><Msgbody>When using SSH to the switch for switch based authentication you need to &lt;br /&gt;enable PAP on the Radius policy. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Telnet/SSH work on PAP only. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ee7a" messages="5" subscribed="yes" title="As I see the  &quot;Command denied&quot; in Failed Attempts report"><Message attachment="no" canreply="yes" id=".2cd4ee7a" level=""><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 13, 2009, 9:52am PST</Timestamp><Msgbody>Hello.&lt;br /&gt;&lt;br /&gt;In Failed Attempts report, under "Author-Failure-Code" I get "Command denied". Is there any way to record the commands that the user wanted to enter?&lt;br /&gt;&lt;br /&gt;Thanks!.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ee7a/0" level="1." new="yes"><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Nov 13, 2009, 10:39am PST</Timestamp><Msgbody>Hi kevin,&lt;br /&gt;&lt;br /&gt;What command are you trying to execute?&lt;br /&gt;&lt;br /&gt;Do you have accounting enabled on the devices? If yes, then look under the tacacs administration logs and copy the command that is not working.&lt;br /&gt;&lt;br /&gt;Looks like the command you are trying to execute is not allowed under the command set.&lt;br /&gt;&lt;br /&gt;Configuration example:&lt;br /&gt;======================&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ee7a/1" level="1.1" new="yes"><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 13, 2009, 12:27pm PST</Timestamp><Msgbody>Thanks for your reply. I Shell Command Authorization Sets configured to only allow commands: show, ping, traceroute.&lt;br /&gt;	&lt;br /&gt;when a user executes a command that is not possible in the Failed Attempts report log is generated "Command denied", as I know which command the user try to run?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ee7a/2" level="1.1.1" new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 14, 2009, 7:34am PST</Timestamp><Msgbody>Kevin,&lt;br /&gt;You should see something like this in the&lt;br /&gt;failed attempts:&lt;br /&gt;&lt;br /&gt;Command denied service=shell cmd=interface FastEthernet 0 21 &lt;cr&gt;&lt;br /&gt;&lt;br /&gt;By this we can see that the argument that is being sent by the switch command parser is actually &apos;FastEthernet 0 21&apos;&lt;br /&gt;&lt;br /&gt;So user tried to execute command " interface FastEthernet 0\\21.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful post.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ee7a/3" level="1.1.1.1" new="yes"><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 14, 2009, 8:39am PST</Timestamp><Msgbody>Thanks for responding.&lt;br /&gt;&lt;br /&gt;failed in the report do not show me the Command denied . attached configuration. &lt;br /&gt;&lt;br /&gt;I am using &lt;br /&gt;CiscoSecure ACS&lt;br /&gt;Release 4.2(0) Build 124 Patch 13&lt;br /&gt;&lt;br /&gt;***Tacacs+ Configuration &lt;br /&gt;aaa new-model&lt;br /&gt;aaa authentication attempts login 1&lt;br /&gt;aaa authentication login default group tacacs+ local&lt;br /&gt;aaa authentication enable default group tacacs+ enable&lt;br /&gt;aaa authorization console&lt;br /&gt;aaa authorization config-commands&lt;br /&gt;aaa authorization exec default group tacacs+ local&lt;br /&gt;aaa accounting exec default start-stop group tacacs+&lt;br /&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;br /&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;br /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;br /&gt;aaa accounting connection default start-stop group tacacs+&lt;br /&gt;aaa accounting system default start-stop group tacacs+&lt;br /&gt;tacacs-server directed-request&lt;br /&gt;tacacs-server key Presharedciscoxx&lt;br /&gt;tacacs-server host 192.168.1.10&lt;br /&gt;ip tacacs source-interface Loopback0 &lt;br /&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) ACS1.JPG&lt;br /&gt;2) ACS2.JPG&lt;br /&gt;3) ACS3.JPG&lt;br /&gt;</Msgbody><Attachment><Document><FileName>ACS1.JPG</FileName><DocID>123587</DocID><ContentType>image/jpeg</ContentType><InternalType>image</InternalType><Size>50155</Size><ExpirationDate>11/14/2014</ExpirationDate><IsExpired>no</IsExpired></Document><Document><FileName>ACS2.JPG</FileName><DocID>123588</DocID><ContentType>image/jpeg</ContentType><InternalType>image</InternalType><Size>59211</Size><ExpirationDate>11/14/2014</ExpirationDate><IsExpired>no</IsExpired></Document><Document><FileName>ACS3.JPG</FileName><DocID>123589</DocID><ContentType>image/jpeg</ContentType><InternalType>image</InternalType><Size>15988</Size><ExpirationDate>11/14/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ee7a/4" level="1.1.1.1.1" new="yes"><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 16, 2009, 7:01am PST</Timestamp><Msgbody>Greetings.&lt;br /&gt;had an error in the configuration of the report, had not enabled the option Author-Date .. thanks for your help! ..</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4f095" messages="0" subscribed="yes" title="Identify certificate from the LOCAL-CA-SERVER ASA 5520 (8.2-1)"><Message attachment="no" canreply="yes" id=".2cd4f095" level="">            <Author authinfo=" SEM-NUMERICA">vpancisco</Author><Timestamp>Nov 16, 2009, 2:58am PST</Timestamp><Msgbody>I succed to setup a LOCAL-CA-SERVER&lt;br /&gt;&lt;br /&gt;I would like to generate an Identify certificate from the LOCAL-CA-SERVER&lt;br /&gt;&lt;br /&gt;so i generated a CSR so as to submit from the the LOCAL-CA-SERVER&lt;br /&gt;&lt;br /&gt;it&apos;s possible ?? what&apos;s the way to</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4dd53" messages="5" subscribed="yes" title="ASA 8.2(1) /+CISCOA+/enroll.html authentication failed"><Message attachment="no" canreply="yes" id=".2cd4dd53" level="">            <Author authinfo=" SEM-NUMERICA">vpancisco</Author><Timestamp>Nov 4, 2009, 1:10am PST</Timestamp><Msgbody>I&apos;m trying to setup a LOCAL CA SERVER&lt;br /&gt;for an ASA 5520.&lt;br /&gt;&lt;br /&gt;i&apos;m stoppped to the authentification page&lt;br /&gt;/+CISCOA+/enroll.html from IE7&lt;br /&gt;&lt;br /&gt;the server return authentication failed&lt;br /&gt;&lt;br /&gt;even if i use the correct user One-time Password received by mail&lt;br /&gt;&lt;br /&gt;Does anyone could help me ?&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4dd53/0" level="1." new="yes"><Author authinfo=" ICZ AS" ccie="yes">vchepikov</Author><Timestamp>Nov 11, 2009, 4:46am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;if you do &apos;debug http 255&apos;, you&apos;ll see something like that:&lt;br /&gt;&lt;br /&gt;HTTP: file not found:  CSCOCA /enroll.html</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4dd53/1" level="2." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 11, 2009, 10:30am PST</Timestamp><Msgbody>Not sure if you are accessing CA server or ASDM?&lt;br /&gt;&lt;br /&gt;One time password does not work for http connection.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4dd53/2" level="2.1" new="yes"><Author authinfo=" ICZ AS" ccie="yes">vchepikov</Author><Timestamp>Nov 11, 2009, 12:18pm PST</Timestamp><Msgbody>He is accessing CA server running locally on ASA in order to enroll. But he couldn’t get authenticated against CA user database (LOCAL AAA method is used instead). That&apos;s why OTP doesn&apos;t work for him.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4dd53/3" level="2.1.1" new="yes">            <Author authinfo=" SEM-NUMERICA">vpancisco</Author><Timestamp>Nov 12, 2009, 3:01am PST</Timestamp><Msgbody>Thanks for interest&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So i can&apos;t get authenticated against CA user database because LOCAL AAA method is used instead&lt;br /&gt;&lt;br /&gt;How to set auth against CA user database ??&lt;br /&gt;</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4dd53/4" level="2.1.2" new="yes">            <Author authinfo=" SEM-NUMERICA">vpancisco</Author><Timestamp>Nov 16, 2009, 2:17am PST</Timestamp><Msgbody>thanks for all&lt;br /&gt;&lt;br /&gt;i succed to enroll&lt;br /&gt;&lt;br /&gt;the way is enable webvpn so as to&lt;br /&gt;query the correct data-base&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;regards&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4ef6a" messages="0" subscribed="yes" title="Shell Command Authorization Sets for device using NDGs??"><Message attachment="no" canreply="yes" id=".2cd4ef6a" level=""><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 14, 2009, 10:10am PST</Timestamp><Msgbody>Hello. I NDGs configured, there is a group called "GR1" with 30 switch.&lt;br /&gt;&lt;br /&gt;This group is set up a Shell Command Authorization set called "Monitoring", in which only show commands, ping and traceroute are allowed.&lt;br /&gt;&lt;br /&gt;I want to let users switch in only 10 of the group "GR 1" to configure certain interfaces and IP addresses, switch to the other not. ! Note: The number of interface is not the same for each switch, one can be FA0 / 1, but for others it may fa0/3.etc.&lt;br /&gt;&lt;br /&gt;I want to retain these 10 switch within the group "GR1", it is possible to make this configuration?&lt;br /&gt;&lt;br /&gt;- Thanks</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4ef2c" messages="1" subscribed="yes" title="How to restrict user in vpn remote access using external database in acs4.2"><Message attachment="no" canreply="yes" id=".2cd4ef2c" level=""><Author authinfo=" PT MASTERSYSTEM INFOTAMA">Charles_Chi4</Author><Timestamp>Nov 14, 2009, 12:05am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;I&apos;ve got ACS 4.2 windows installed in domain member server n run well. I can authenticate using users in AD. I use this ACS for authenticating user for routers &amp; switches access, VPN access and wireless access.&lt;br /&gt;&lt;br /&gt;The question is how could i restrict certain person for VPN acess and routers / switches access? But allowed all users in AD for wireless access?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ef2c/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 14, 2009, 7:27am PST</Timestamp><Msgbody>Charles,&lt;br /&gt;You need to set up NARs to control the device access on the group membership basis.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a0080858d3c.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a0080858d3c.shtml&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Now since we are using windows AD, we need to map AD group with specific ACS group.&lt;br /&gt;&lt;br /&gt;Example &lt;br /&gt;&lt;br /&gt;Wireless Group ACS &lt;----&gt; Wireless group AD&lt;br /&gt;&lt;br /&gt;NAR would be configured on ACS wireless group.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ef3a" messages="1" subscribed="yes" title="Remote Agent installation windows 2003 issue."><Message attachment="no" canreply="yes" id=".2cd4ef3a" level=""><Author authinfo=" MANNAI CORPORATION Q S C">subashmbi</Author><Timestamp>Nov 14, 2009, 2:24am PST</Timestamp><Msgbody>Dear Team,&lt;br /&gt;&lt;br /&gt;I am facing a issue in RA agent installation in win2003.&lt;br /&gt;Details:-&lt;br /&gt;&lt;br /&gt;1.windows 2003 server r2 service pack 2&lt;br /&gt;2.Remote agent 4.1.4.13.16&lt;br /&gt;3.OS 32 bit version&lt;br /&gt;&lt;br /&gt;Kindly advice&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Subash.c</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ef3a/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 14, 2009, 7:21am PST</Timestamp><Msgbody>Hi Subash,&lt;br /&gt;This is a patch for release 4.1.4. Acs 4.1.4 must be installed before installing this patch.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Instructions on how to install the patch&lt;br /&gt;========================================&lt;br /&gt;1. Make sure for Cisco Secure ACS Agent 4.1.4.13 is installed.&lt;br /&gt;2. Extract files NTlib.dll , CSLogAgent.exe , CSAgent.exe,CSWinAgent.exe , NAS.dll,ConsoleDLL.dll , csvLog.dll , EndPoint.dll &amp; odbcLogger.dll from Acs-4.1.4.13.16-RA.zip&lt;br /&gt;3. Stop Cisco Secure ACS Agent service.&lt;br /&gt;4. Locate CiscoSecure ACS Agent\\bin and save a copy of current NTlib.dll , NAS.dll,CSAgent.exe,CSLogAgent.exe , CSWinAgent.exe &amp; EndPoint.dll&lt;br /&gt;5. Copy NTlib.dll , CSLogAgent.exe , CSAgent.exe,NAS.dll,CSWinAgent.exe &amp; EndPoint.dll files extracted from zip to CiscoSecure ACS Agent\\bin&lt;br /&gt;6. Locate CiscoSecure ACS Agent\\Support and save a copy of current ConsoleDLL.dll , csvLog.dll &amp; odbcLogger.dll&lt;br /&gt;7. Copy ConsoleDLL.dll , csvLog.dll &amp; odbcLogger.dll extracted files from zip to CiscoSecure ACS Agent\\Support&lt;br /&gt;6. Start Cisco Secure Agent Service.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ee8b" messages="1" subscribed="yes" title="ACS 4.2 does User-level overwrite Group-level NAR"><Message attachment="no" canreply="yes" id=".2cd4ee8b" level="">            <Author authinfo=" Familiprix">netadmincsm</Author><Timestamp>Nov 13, 2009, 10:22am PST</Timestamp><Msgbody>Hi all.&lt;br /&gt;&lt;br /&gt;I want to know if there&apos;s a way for the User-level NAR to overwrite the Group-level NAR in ACS 4.2.&lt;br /&gt;&lt;br /&gt;Presently both of them seems to be added to each other.&lt;br /&gt;&lt;br /&gt;Thank you very much for your help.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ee8b/0" level="1." new="yes"><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Nov 13, 2009, 10:34am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;If you configure NAR on the user level, this will always take precedence over group.&lt;br /&gt;&lt;br /&gt;NAr white paper:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ec31" messages="2" subscribed="yes" title="ACS 4.1 (1.3) for windows CRL problem"><Message attachment="no" canreply="yes" id=".2cd4ec31" level="">      <Author authinfo="Presales Engineer, TECNOCOM">e.bayon</Author><Timestamp>Nov 12, 2009, 9:40am PST</Timestamp><Msgbody>I´ve configured new CA in the Certification trusted list, when I go to the CRL configuring menu, and I check the "CRL in use" and I push over the "submit" label to activate it, I always receive the same message: Failed to retrieve or verify CRL. Verify the CRL Distribution URL.&lt;br /&gt;&lt;br /&gt;The message from de ADM.log is the next:&lt;br /&gt;CRL: CRL: failed to find an issuer&apos;s certificate for crl C:\\Archivos de programa\\CiscoSecure ACS v4.1\\CRL\\acs1(12-11-2009@16-30-14).crl&lt;br /&gt;&lt;br /&gt;The CRL Distribution URL is:&lt;A HREF="javascript:newWin(&apos;http://10.252.252.4/crl.crl&apos;)"&gt;http://10.252.252.4/crl.crl&lt;/A&gt;&lt;br /&gt;Nevertheless, If I do a Remote terminal session to the 2K3 windows server where the Cisco ACS software is installed, and try to open an I.e. session to the same URL where the crl file is allocated, I can download perfectly.&lt;br /&gt;This procedure needs to be OK,in order to perform a EAP-TLS session with wireless client against external LDAP data base.&lt;br /&gt;&lt;br /&gt;Where is my mistake?&lt;br /&gt;Regards</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ec31/0" level="1." new="yes">            <Author authinfo=" CISCO SYSTEMS">ansalaza</Author><Timestamp>Nov 12, 2009, 11:45am PST</Timestamp><Msgbody>"Might" be hitting:&lt;br /&gt;CSCsg61729  -  ACS fails to find an issuer&apos;s certificate for CRL list uploaded from CDP &lt;br /&gt;&lt;br /&gt;ACS will sometimes take the CRL pointer from the root certificate, even if the CRL URL is configured to point to a different system.&lt;br /&gt;&lt;br /&gt;Do you already have the CA installed in ACS?&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ec31/1" level="1.1" new="yes">      <Author authinfo="Presales Engineer, TECNOCOM">e.bayon</Author><Timestamp>Nov 13, 2009, 1:33am PST</Timestamp><Msgbody>Yes I have installed the certificate in ACS application (CTL) and the W2k3 server I.e content tools menu. &lt;br /&gt;The CA is not a Microsoft Certs Server is a Autonomous server wich is istalled a software to generate certificates&lt;br /&gt;I want to use this certificate only for EAP-TLS connections purpose, because the ACS web page is certicated with Cisco ACS self signed certificate. Could it be the problem?</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4ed30" messages="0" subscribed="yes" title="ACS 4.3 Policies and procedure"><Message attachment="no" canreply="yes" id=".2cd4ed30" level="">            <Author authinfo=" Networks">adhityakarthik</Author><Timestamp>Nov 12, 2009, 10:07pm PST</Timestamp><Msgbody>I&apos;m wondering if anyone would be willing to share their experiences in&lt;br /&gt;creating polices and procedures for a NOC, engineering  and architectural&lt;br /&gt;group as it relates to TACACS+/privilege levels.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Adhitya</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4eca2" messages="1" subscribed="yes" title="ACS 4.1 Evaluation Copy..."><Message attachment="no" canreply="yes" id=".2cd4eca2" level=""><Author authinfo=" CompuCom Systems">lrm001c474</Author><Timestamp>Nov 12, 2009, 12:23pm PST</Timestamp><Msgbody>Hi,&lt;br /&gt;  Can any one provide me with a link on the Cisco website where I can download the 90-day evaluation copy of Cisco Secure ACS?  I can&apos;t seem to locate it on the download page.&lt;br /&gt;&lt;br /&gt;Thanks.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4eca2/0" level="1." new="yes">            <Author authinfo=" CISCO SYSTEMS">ansalaza</Author><Timestamp>Nov 12, 2009, 12:43pm PST</Timestamp><Msgbody>I think I am seen double, but here is the link for ACS 4.1 and ACS 4.2:&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-eval&apos;)"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-eval&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;:D</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ec7c" messages="5" subscribed="yes" title="ACS 4.1 Evaluation Copy..."><Message attachment="no" canreply="yes" id=".2cd4ec7c" level=""><Author authinfo=" CompuCom Systems">lrm001c474</Author><Timestamp>Nov 12, 2009, 11:34am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;  Can any one provide me with a link on the Cisco website where I can download the 90-day evaluation copy of Cisco Secure ACS?  I can&apos;t seem to locate it on the download page.&lt;br /&gt;&lt;br /&gt;Thanks.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ec7c/0" level="1." new="yes">            <Author authinfo=" CISCO SYSTEMS">ansalaza</Author><Timestamp>Nov 12, 2009, 11:35am PST</Timestamp><Msgbody>ACS 4.2&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/cgi-bin/Software/Tablebuild/doftp.pl?ftpfile=cisco/crypto/3DES/ciscosecure/acs/win/90-dayeval/eval-ACS-4.2.0.124-SW.zip&amp;app=Tablebuild&amp;status=showC2A%3E&apos;)"&gt;http://www.cisco.com/cgi-bin/Software/Tablebuild/doftp.pl?ftpfile=cisco/crypto/3DES/ciscosecure/acs/win/90-dayeval/eval-ACS-4.2.0.124-SW.zip&amp;app=Tablebuild&amp;status=showC2A%3E&lt;/A&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ec7c/1" level="1.1" new="yes"><Author authinfo=" CompuCom Systems">lrm001c474</Author><Timestamp>Nov 12, 2009, 11:44am PST</Timestamp><Msgbody>I&apos;m sorry, I forgot to mention that I am looking for version 4.1.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ec7c/2" level="1.1.1" new="yes">            <Author authinfo=" CISCO SYSTEMS">ansalaza</Author><Timestamp>Nov 12, 2009, 11:47am PST</Timestamp><Msgbody>That was in your initial request, but I don&apos;t think we have an Evaluation Version for ACS 4.1.&lt;br /&gt;</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4ec7c/3" level="1.1.2" new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 12, 2009, 11:48am PST</Timestamp><Msgbody>Here is the link to download ACS eval software ver 4.1&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-eval&apos;)"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-eval&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ec7c/4" level="1.1.2.1" new="yes">            <Author authinfo=" CISCO SYSTEMS">ansalaza</Author><Timestamp>Nov 12, 2009, 11:56am PST</Timestamp><Msgbody>Nice!</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4ebb3" messages="1" subscribed="yes" title="ACS 3.3 Migration to 4.2 or 5.1 Appliance"><Message attachment="no" canreply="yes" id=".2cd4ebb3" level="">      <Author authinfo=", PHOENIX IT">nigelb</Author><Timestamp>Nov 12, 2009, 6:13am PST</Timestamp><Msgbody>Hi&lt;br /&gt;I’m currently looking to migrate a customer from ACS 3.3 on a Win2K server to an Appliance.&lt;br /&gt;The current ACS server provides AAA for approx 1000 routers/switches etc to provide authentication for interactive logon (via Novell LDAP) and scripted maintenance logon (via local DB). ACS also provides accounting for logon/configuration changes etc.&lt;br /&gt; Q1. Will both 5.1 and 4.2 ACS appliance engines provide these facilities (local db/ldap etc), if so then 5.1 would be the best choice?&lt;br /&gt;Q2. Can the data (AAA clients/users etc) be exported from 3.3 and imported to 4.2 or 5.1, as ideally I want to keep the original server untouched for rollback.&lt;br /&gt;Thanks in advance.&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ebb3/0" level="1."><Author authinfo=" CISCO SYSTEMS">jrabinow</Author><Timestamp>Nov 12, 2009, 9:00am PST</Timestamp><Msgbody>Both 5.1 and ACS 4.2 ACS appliance support authentication against LDAP and local DB.&lt;br /&gt;&lt;br /&gt;ACS 5.1 is the next generation ACS platform and provides a policy based mechanism for defining authorizations; as opposed to the user/group based mechanisms in ACS 4.2. &lt;br /&gt;&lt;br /&gt;To migrate the system from ACS 3.3 requires a two stage process:&lt;br /&gt;1) upgrade to ACS 4.2&lt;br /&gt;2) migrate data from ACS 4.2 to ACS 5.1&lt;br /&gt;The second migration process can extract all user/device definitions from the ACS 4.2 to ACS 5.1 and then need to create the appropriate policies that define the user access&lt;br /&gt;&lt;br /&gt;The ACS 5.1 DVD set should include all the required software versions to perform this upgrade although I am not familiar with the specifics of upgrade of ACS 3.3 to ACS 4.2. The original 3.3 system could be kept in place and the upgrade/migration be performed on a parallel system.&lt;br /&gt;&lt;br /&gt;ACS 5.1 does have capability to import user/device data from a csv file and so if can get the data in this format can avoid all the upgrade/migration related activities&lt;br /&gt;&lt;br /&gt;Hope this helps</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4eb86" messages="1" subscribed="yes" title="ACS-SE on a virtual box"><Message attachment="no" canreply="yes" id=".2cd4eb86" level=""><Author authinfo=" NEC BRASIL S/A - CISPRO">alvaro.motta</Author><Timestamp>Nov 12, 2009, 4:24am PST</Timestamp><Msgbody>Folks, greetings.&lt;br /&gt;&lt;br /&gt;We have a customer that needs to install a patch on his ACS-SE, but since this is a very big and productive environment, he is very concerned in doing so without testing on a lab in advance.&lt;br /&gt;&lt;br /&gt;As we don&apos;t have an appliance to run the tests, I was wondering if we could install an ACS-SE image onto a virtual machine (VMWare, Sun Virtual Box or MS Virtual PC).&lt;br /&gt;Does anybody out there has any experience in trying this kind of lab?&lt;br /&gt;&lt;br /&gt;Thanks in advance,&lt;br /&gt;&lt;br /&gt;AL</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4eb86/0" level="1." new="yes"><Author authinfo=" NEC BRASIL S/A - CISPRO">alvaro.motta</Author><Timestamp>Nov 12, 2009, 4:25am PST</Timestamp><Msgbody>BTW, the patch was not designed to run on ACS For Windows. That&apos;s why this is not a solution.&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;&lt;br /&gt;AL</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".1de01d10" messages="2" subscribed="yes" title="ACS SE - Multiple Windows AD Domains"><Message attachment="no" canreply="yes" id=".1de01d10" level="">      <Author authinfo="Technical support engineer, PINACL COMUNICATIONS SYSTEMS LTD">ihill</Author><Timestamp>Oct 16, 2007, 4:01am PST</Timestamp><Msgbody>Can I use the ACS Network Device Groups to have a single ACS apliance acting as the authenticator for two Windows domains for 802.1x for a single switch?&lt;br /&gt;&lt;br /&gt;Hope the question makes sense but to put a little more meat on the question:&lt;br /&gt;i have a single ACS Appliance which I am trying to use for 802.1x authentication on a switch. The issue comes as I want to have the VLAN allocation part of the set-up allocated through the ACS server dependant on checking the users against a domain account but we have two domains with no trust between them. the ACS remote agent specifically states it should not be installed on servers in different domains and that the two available agents are for resiliance only, so this unfortunatley doesn&apos;t fit.&lt;br /&gt;&lt;br /&gt;this is why i have ended up with looking at using multiple device groups.&lt;br /&gt;&lt;br /&gt;anyone any ideas if this will work or if there is another way of making this work.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".1de01d10/0" level="1.">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Oct 16, 2007, 5:28am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;ACS cannot "natively" authenticate to 2 different domains that don&apos;t have a trust relationship defined. If that is not possible then you need to have 2 ACS servers, one in each domain.  Configure the "primary" ACS to proxy requests to the "secondary" server based on the provided domain.&lt;br /&gt;&lt;br /&gt;This would require a second ACS server be set up (you would likely have to pay an additional fee for the second ACS server).  You would want to configure a proxy distribution table . This would require user explicitly provide the domain name with their user name.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Please rate helpful posts</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1de01d10/1" level="1.1" new="yes">            <Author authinfo=" CLOUNET AG">dominicstalder</Author><Timestamp>Nov 12, 2009, 2:24am PST</Timestamp><Msgbody>But this means that, for 2 domain and ACS redundancy, I would need 4 ACS appliances?&lt;br /&gt;&lt;br /&gt;Because if one ACS goes down, the proxy function won&apos;t work anymore.</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e828" messages="1" subscribed="yes" title="Problem whit port console for ACS in switch 2950-XL!"><Message attachment="no" canreply="yes" id=".2cd4e828" level=""><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 10, 2009, 10:02am PST</Timestamp><Msgbody>I set a Catalyst 2950 switch to the console port authentication is THROUGH the ACS, in case of failure to use the local user base, works well.&lt;br /&gt;&lt;br /&gt;	&lt;br /&gt;the problem is with a 2950-XL switch, which does not support the command aaa authorization console, I can do?&lt;br /&gt;&lt;br /&gt;the configuration is:&lt;br /&gt;&lt;br /&gt;username admin privilege 15 password 0 123456&lt;br /&gt;&lt;br /&gt;aaa authentication login default group tacacs+ local&lt;br /&gt;aaa authentication login CONSOLE local&lt;br /&gt;aaa authorization config-commands&lt;br /&gt;aaa authorization exec default group tacacs+ local&lt;br /&gt;aaa authorization exec CONSOLE local&lt;br /&gt;aaa authorization commands 0 default group tacacs+ if-authenticated&lt;br /&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;br /&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;br /&gt;aaa accounting exec default start-stop group tacacs+&lt;br /&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;br /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;br /&gt;aaa accounting connection default start-stop group tacacs+&lt;br /&gt;aaa accounting system default start-stop group tacacs+&lt;br /&gt;&lt;br /&gt;line con 0&lt;br /&gt; authorization exec CONSOLE&lt;br /&gt; login authentication CONSOLE&lt;br /&gt;&lt;br /&gt;i try to access the switch:&lt;br /&gt;&lt;br /&gt;Username: admin&lt;br /&gt;Password: ******&lt;br /&gt;&lt;br /&gt;SWAdmin5&gt;en&lt;br /&gt;Password: &lt;br /&gt;% Access denied&lt;br /&gt;&lt;br /&gt;SWAdmin5&gt;&lt;br /&gt;&lt;br /&gt;suggestions friends "</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e828/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 11, 2009, 12:38pm PST</Timestamp><Msgbody>I guess you have 2900XL switch. CAT 2950 do support this command.&lt;br /&gt;&lt;br /&gt;The problem is that the XL switches do not support this command.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ea11" messages="1" subscribed="yes" title="ACS with Sidewinder G2"><Message attachment="no" canreply="yes" id=".2cd4ea11" level="">            <Author authinfo=" BAE Systems">xayavongp</Author><Timestamp>Nov 11, 2009, 8:21am PST</Timestamp><Msgbody>I am trying to implement Radius (using ACS v3.2) on Secure Computing&apos;s Sidewinder G2. It appears I need a VSA (vendor specific attribute) to make it work properly.  I have tried it with Radius (IETF) but no luck.  Any suggestions on how I might go about this ?  Or is this even possible ?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ea11/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 11, 2009, 10:24am PST</Timestamp><Msgbody>If G2 Sidewinder firewall vendor has/require vendor specific attributes to be sent by authentication server, then we would require the VSA definition from the vendor.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;On the other hand I have seen it working (basic authentication)with Radius IETF.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4e22b" messages="4" subscribed="yes" title="ACS&apos;s replication"><Message attachment="no" canreply="yes" id=".2cd4e22b" level=""><Author authinfo=" ANECT AS">jozef.cmorej</Author><Timestamp>Nov 6, 2009, 3:21am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;I need an advice about ACS&apos;s replication. I have 2 independent ACSs, The first one ACS1 is for routers/switches, remote VPN and some servers using MS-CHAP v1/2, EAP-TLS and PEAP-GTC. The second one ACS2 is only for Wifi APs using EAP-TLS and PEAP-GTC.&lt;br /&gt;I&apos;d like to make a replication between them. As I read, the one should be a primary ACS and the other one should be as secondary ACS.&lt;br /&gt;If I understood well I should move Wifi authentication to ACS1 and authenticate all devices (routes/switches/VPN/wifi) to this ACS1 (with all methods MS-CHAP v1/2, EAP-TLS and PEAP-GTC) as primary. ACS2 will be as secondary ACS2 with the same configuration (routes/switches/VPN/wifi) but authenticates them only in case of its failure.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e22b/0" level="1." new="yes"><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Nov 6, 2009, 5:19am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;This is actually a right practice. I would also suggest you to let primary ACS authenticate all kind of session including Wi-Fi and use secondary ACS as a standby.&lt;br /&gt;&lt;br /&gt;ABOUT DB REPLICATION&lt;br /&gt;====================&lt;br /&gt;&lt;br /&gt;Database replication creates mirror systems of ACSs by duplicating parts of the primary ACS setup to one or more secondary ACSs. You can configure your AAA clients to use these secondary ACSs if the primary ACS fails or is unreachable. With a secondary ACS whose ACS internal database is a replica of the ACS internal database on the primary ACS, if the primary ACS goes out of service, incoming requests are authenticated without network downtime, provided that your AAA clients are configured to fail over to the secondary ACS.&lt;br /&gt;&lt;br /&gt;I am sending you one link for Setting Up Replication for Cisco Secure ACS, I am sure this example with screen shots gives you better understanding.&lt;br /&gt;&lt;br /&gt;Please visit the below suggested ULR:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00800e518a.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00800e518a.shtml&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e22b/1" level="1.1" new="yes"><Author authinfo=" ANECT AS">jozef.cmorej</Author><Timestamp>Nov 11, 2009, 1:25am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;thanks for reply. I have another issue. Lets imagine I have done replication described above. Can I set up specific authetication methods for particular AAA client. If yes, where?&lt;br /&gt;Because I guess, it&apos;s possible only in global mode for all AAA clients through "System Configuration &gt; Global Authentication Setup".&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e22b/2" level="1.1.1" new="yes"><Author authinfo=" ANECT AS">jozef.cmorej</Author><Timestamp>Nov 11, 2009, 4:12am PST</Timestamp><Msgbody>I&apos;ve found "Network Access Profiles" which could probably figure out my issue. I would create particular profiles for separate bundle of AAA clients (wifi vs VPN, routers) and assign them their authentication methods.&lt;br /&gt;And important information - I&apos;m using ACS v4.1.&lt;br /&gt;Am I right?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e22b/3" level="1.1.1.1" new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 11, 2009, 10:18am PST</Timestamp><Msgbody>Yes, you need to use NAP feature inorder to achieve it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Do rate helpful posts</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e8fd" messages="1" subscribed="yes" title="Defining services in TACACS Server"><Message attachment="no" canreply="yes" id=".2cd4e8fd" level="">            <Author authinfo=" Logica PTY LTD">mshahzad@hotmail.com</Author><Timestamp>Nov 10, 2009, 5:29pm PST</Timestamp><Msgbody>I have to define the following IPSO-specific service in your TACACS+ server:&lt;br /&gt;service = nokia-ipso {&lt;br /&gt;Nokia-IPSO-User-Role = "role_name_on_IPSO"&lt;br /&gt;Nokia-IPSO-SuperUser-Access = &lt;0|1&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;How can I do it?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e8fd/0" level="1." new="yes"><Author authinfo=" extraxi.com (reporting &amp; audit compliance solutions for CiscoSecure ACS)">darpotter</Author><Timestamp>Nov 11, 2009, 3:21am PST</Timestamp><Msgbody>To add a custom service to ACS...&lt;br /&gt;&lt;br /&gt;Goto "Interface Configuration" then "TACACS+ (Cisco IOS)" and in the "New Services" section enter your new service "nokia-ipso" plus tick the user &amp; group checkboxes. You might need to add "ip" as the protocol depending on what the  actual T+ requests look like.&lt;br /&gt;&lt;br /&gt;When you next edit a user or group you&apos;ll see a new TACACS+ service into which you can enter your custom attributes:&lt;br /&gt;&lt;br /&gt;Nokia-IPSO-User-Role=role_name_on_IPSO&lt;br /&gt;Nokia-IPSO-SuperUser-Access=&lt;0|1&gt;&lt;br /&gt;&lt;br /&gt;Note that only very basic syntax checks are applied, basically as long as eahc line has somehing=something ACS will not complain, so its up to you to make sure the values are correct.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4e86a" messages="1" subscribed="yes" title="Cisco ACS v5.0 with PEAP-MSCHAPv2"><Message attachment="no" canreply="yes" id=".2cd4e86a" level="">      <Author authinfo="COMPUTER TECH, NISD">mbohler</Author><Timestamp>Nov 10, 2009, 11:31am PST</Timestamp><Msgbody>I am have problems setting up the Cisco ACS server with PEAP-MACHAPv2. Does any one have a step by step guide to help with this issue..</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e86a/0" level="1."><Author authinfo=" CISCO SYSTEMS">jrabinow</Author><Timestamp>Nov 10, 2009, 12:34pm PST</Timestamp><Msgbody>I do not have a step by step guide to hand. A few things that come to mind are&lt;br /&gt;1) Define netwrok device&lt;br /&gt;2) Set allowed protocols in service definition and select identity store&lt;br /&gt;3) Install server certificate&lt;br /&gt;&lt;br /&gt;One good way to trouble shoot such issues is to Monitoring &amp; Reports: &gt;  Reports &gt;  Catalog &gt;  AAA Protocol &lt;br /&gt;and then select "RADIUS_Authentication"&lt;br /&gt;&lt;br /&gt;You will see pass/fail records. For each fail record see failure reason. Also select magnifying glass icon under "Details" and will get step-by-step details so that should see step where processing was stopped and failure returned. Will give input to see what configuration is missing&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4e7e6" messages="4" subscribed="yes" title="Question about service CSTacacs and delete AAA Client?"><Message attachment="no" canreply="yes" id=".2cd4e7e6" level=""><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 10, 2009, 8:21am PST</Timestamp><Msgbody>I am running the ACS and all this good, I delete a AAA client of the ACS, try logging in again and let myself go! .. I had to restart the service CSTacacs to not allow access to the AAA client is well removed ..this is correct? or is there some way to correct this? .. Thanks!</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e6/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 10, 2009, 8:32am PST</Timestamp><Msgbody>Yes, when ever you make any changes it is recommend to reload the services.&lt;br /&gt;&lt;br /&gt;Use Delete+Restart option instead of Delete.&lt;br /&gt;&lt;br /&gt;Incase Delete+Restart does not makes any difference then try updating Java or try with different browser.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e6/1" level="1.1" new="yes"><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 10, 2009, 8:51am PST</Timestamp><Msgbody>I change the IP to the Client AAA, and restart the service CSTacacs and will not let me login with the user..</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e6/2" level="1.1.1" new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 10, 2009, 10:40am PST</Timestamp><Msgbody>Please provide more details...you are not able to login to that aaa-client or acs itself?&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e6/3" level="1.1.1.1" new="yes"><Author authinfo=" EDIFICIO ALFANUMERIC">Kevin.Morales</Author><Timestamp>Nov 10, 2009, 11:05am PST</Timestamp><Msgbody>if you change the IP to the AAA client, this lets me log into the user configured in ACS. I have to restart the service CSTacacs not let me log into the user of ACS and local users can use the router.</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e83e" messages="3" subscribed="yes" title="Stop ACS 5.0 upgrade in progress"><Message attachment="no" canreply="yes" id=".2cd4e83e" level=""><Author authinfo=" State of Idaho">webbcorey</Author><Timestamp>Nov 10, 2009, 10:36am PST</Timestamp><Msgbody>How do I stop an FTP upgrade if it is pointed to an incorrect FTP location.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e83e/0" level="1."><Author authinfo=" CISCO SYSTEMS">jrabinow</Author><Timestamp>Nov 10, 2009, 10:54am PST</Timestamp><Msgbody>Was this operation done from the GUI? If so I think can go to: &lt;br /&gt;System Administration &gt; Operations &gt; Distributed System Management &gt; Edit: "hostname"&lt;br /&gt;If a software update is in progress for this server should see a "cancel software update" button</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e83e/1" level="1.1"><Author authinfo=" State of Idaho">webbcorey</Author><Timestamp>Nov 10, 2009, 10:55am PST</Timestamp><Msgbody>Thank you this has solved my issue!</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e83e/2" level="1.1.1"><Author authinfo=" CISCO SYSTEMS">jrabinow</Author><Timestamp>Nov 10, 2009, 11:00am PST</Timestamp><Msgbody>Perfect. Can you mark the thread accordingly?</Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e7e4" messages="4" subscribed="yes" title="Authorization Set Not Working Properly"><Message attachment="no" canreply="yes" id=".2cd4e7e4" level="">            <Author authinfo=" Lowe&apos;s Companies, Inc.">jason.williams@lowes.com</Author><Timestamp>Nov 10, 2009, 8:17am PST</Timestamp><Msgbody>I&apos;m trying to set up an authorization set to restrict users to certain commands.  However, it seems like it works for some commands, but not for others.&lt;br /&gt;&lt;br /&gt;In ENABLE mode, the auth set seems to work properly.  However, once I get into CONFIG mode, it no longer works.  I can run any command.&lt;br /&gt;&lt;br /&gt;What am I missing that could be causing this?&lt;br /&gt;&lt;br /&gt;Also, note that I have this auth set assigned to a group.&lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;&lt;br /&gt;Jason</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e4/0" level="1." new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 10, 2009, 8:23am PST</Timestamp><Msgbody>It seems that you are missing this command,&lt;br /&gt;&lt;br /&gt;aaa authorization config-command&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e4/1" level="1.1" new="yes">            <Author authinfo=" Lowe&apos;s Companies, Inc.">jason.williams@lowes.com</Author><Timestamp>Nov 10, 2009, 8:43am PST</Timestamp><Msgbody>That might be it, the command isn&apos;t there.&lt;br /&gt;&lt;br /&gt;I&apos;ll try it and let you know if that was it.&lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;&lt;br /&gt;Jason</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e4/2" level="1.2" new="yes">            <Author authinfo=" Lowe&apos;s Companies, Inc.">jason.williams@lowes.com</Author><Timestamp>Nov 10, 2009, 10:37am PST</Timestamp><Msgbody>Adding &lt;br /&gt;&lt;br /&gt;aaa authorization config-command &lt;br /&gt;&lt;br /&gt;worked.&lt;br /&gt;&lt;br /&gt;However, I&apos;ve got another issue (I think).&lt;br /&gt;&lt;br /&gt;Other groups have "none" selected for the auth sets.  When I log in as a user in one of those groups, I get an access denied error when I enter ANY command.&lt;br /&gt;&lt;br /&gt;The only way that I&apos;ve been able to work around this is to set the group to use group based command sets and permit everything.&lt;br /&gt;&lt;br /&gt;Is there something else that I missed or is this necessary?&lt;br /&gt;&lt;br /&gt;Here are my current AAA settings:&lt;br /&gt;&lt;br /&gt;aaa new-model&lt;br /&gt;aaa authentication login default group tacacs+ local&lt;br /&gt;aaa authentication login no_tacacs local&lt;br /&gt;aaa authentication enable default group tacacs+ enable&lt;br /&gt;aaa authorization exec default group tacacs+ none&lt;br /&gt;aaa authorization exec no_tacacs none&lt;br /&gt;aaa authorization config-command&lt;br /&gt;aaa authorization commands 0 default group tacacs+ if-authenticated&lt;br /&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;br /&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;br /&gt;aaa accounting exec default start-stop group tacacs+&lt;br /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;br /&gt;aaa accounting system default start-stop group tacacs+&lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;&lt;br /&gt;Jason&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e7e4/3" level="1.2.1" new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 10, 2009, 10:45am PST</Timestamp><Msgbody>Expected behavior, since we have seleted none in the authorization set...that is = no access.&lt;br /&gt;&lt;br /&gt;You need to make a new set for limited group allowing certain commmands.&lt;br /&gt;&lt;br /&gt;Check this link,&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts </Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e814" messages="0" subscribed="yes" title="IAS to NPS"><Message attachment="no" canreply="yes" id=".2cd4e814" level=""><Author authinfo=" MULTISUPORTE INFORMATICA LTDA">joao@multisuporte.com.br</Author><Timestamp>Nov 10, 2009, 9:26am PST</Timestamp><Msgbody>Hi&lt;br /&gt;I change my Radius from MS IAS to MS NPS. The wired 802.1x works fine but the wireless 802.1x doesent work. AP1250&apos;s radius debug is attached. &lt;br /&gt;Obs: On IAS everything works fine&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) DebugRadius.txt&lt;br /&gt;</Msgbody> <Attachment><Document><FileName>DebugRadius.txt</FileName><DocID>123424</DocID><ContentType>text/plain</ContentType><InternalType>text</InternalType><Size>14934</Size><ExpirationDate>11/10/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message></Conversation><Conversation id=".2cd4e758" messages="0" subscribed="yes" title="set an ip unnumbered from radius"><Message attachment="no" canreply="yes" id=".2cd4e758" level="">      <Author authinfo="Network Administrator, KNET COMUNICACIONES S.L.">david.knet</Author><Timestamp>Nov 10, 2009, 3:48am PST</Timestamp><Msgbody>Hi all,&lt;br /&gt;&lt;br /&gt;I was reading a lot documentation and testing a lot of scenarios but i can not set template configuration from RADIUS…&lt;br /&gt;&lt;br /&gt;This it my configuration,&lt;br /&gt;&lt;br /&gt;aaa new-model&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;aaa authentication login admin local&lt;br /&gt;aaa authentication ppp default local group radius&lt;br /&gt;aaa authorization template&lt;br /&gt;aaa authorization network default group radius local&lt;br /&gt;aaa accounting delay-start&lt;br /&gt;aaa accounting update newinfo&lt;br /&gt;aaa accounting network default start-stop group radius&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;bba-group pppoe pruebavrf&lt;br /&gt; virtual-template 33&lt;br /&gt; sessions per-mac limit 48&lt;br /&gt; sessions per-vlan limit 1400&lt;br /&gt;!&lt;br /&gt;interface Loopback10&lt;br /&gt;ip address 192.168.44.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0.8&lt;br /&gt; description PRUEBAS&lt;br /&gt; encapsulation dot1Q 8&lt;br /&gt;pppoe enable group pruebavrf&lt;br /&gt;!&lt;br /&gt;interface Virtual-Template33&lt;br /&gt; no ip address&lt;br /&gt; no ip redirects&lt;br /&gt; no ip unreachables&lt;br /&gt; ip mtu 1480&lt;br /&gt; ip tcp adjust-mss 1400&lt;br /&gt; peer default ip address pool pool_local&lt;br /&gt; ppp authentication pap chap&lt;br /&gt;!&lt;br /&gt;radius-server attribute 44 extend-with-addr&lt;br /&gt;radius-server attribute 8 include-in-access-req&lt;br /&gt;radius-server attribute nas-port format d&lt;br /&gt;radius-server configure-nas&lt;br /&gt;radius-server host X.X.X.X auth-port 1812 acct-port 1813 key xxxx&lt;br /&gt;radius-server retransmit 2&lt;br /&gt;radius-server timeout 6&lt;br /&gt;radius-server vsa send accounting&lt;br /&gt;radius-server vsa send authentication&lt;br /&gt;&lt;br /&gt;ip local pool pool_local x.x.x.x&lt;br /&gt;&lt;br /&gt;And this is RADIUS configuration&lt;br /&gt;&lt;br /&gt;testvdsl@knetip      Auth-Type := local, User-Password == "xxxx"&lt;br /&gt;                Service-Type = Framed-User,&lt;br /&gt;                cisco-avpair += "template:ip-unnumbered=Loopback 10",&lt;br /&gt;                Framed-Protocol = PPP&lt;br /&gt;&lt;br /&gt;I think that with this configuration virtual-access would be take the ip of Loopback 10 as unnumbered but doesn’t work.&lt;br /&gt;&lt;br /&gt;Router#sh int Vi2.1&lt;br /&gt;Virtual-Access2.1 is up, line protocol is up&lt;br /&gt;  Hardware is Virtual Access interface&lt;br /&gt;  MTU 1492 bytes, BW 100000 Kbit/sec, DLY 100000 usec,&lt;br /&gt;     reliability 255/255, txload 1/255, rxload 1/255&lt;br /&gt;  Encapsulation PPP, LCP Open&lt;br /&gt;  PPPoE vaccess, cloned from Virtual-Template33&lt;br /&gt;  Vaccess status 0x0&lt;br /&gt;  Keepalive set (10 sec)&lt;br /&gt;     128 packets input, 1803 bytes&lt;br /&gt;     128 packets output, 1799 bytes&lt;br /&gt;  Last clearing of "show interface" counters never&lt;br /&gt;&lt;br /&gt;This is the RADIUS debug,&lt;br /&gt;&lt;br /&gt;.Nov 10 12:38:42: RADIUS(000E4E19): Send Access-Request to x.x.x.x:1812 id 1645/79, len 135&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  authenticator 3C 22 8C 1E AE 21 20 82 - B9 58 57 E3 16 6D C9 8B&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  Vendor, Cisco       [26]  41&lt;br /&gt;.Nov 10 12:38:42: RADIUS:   Cisco AVpair       [1]   35  "client-mac-address=xxxx"&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  Framed-Protocol     [7]   6   PPP                       [1]&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  User-Name           [1]   17  "testvdsl@knetip"&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  User-Password       [2]   18  *&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  NAS-Port-Type       [61]  6   Ethernet                  [15]&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  NAS-Port            [5]   6   8&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  NAS-Port-Id         [87]  9   "0/0/0/8"&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  Service-Type        [6]   6   Framed                    [2]&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  NAS-IP-Address      [4]   6   x.x.x.x&lt;br /&gt;.Nov 10 12:38:42: RADIUS: Received from id 1645/79 x.x.x.x:1812, Access-Accept, len 74&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  authenticator E5 D8 63 D4 D5 EE EC C8 - F7 BB 4A B9 6A C8 60 F6&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  Service-Type        [6]   6   Framed                    [2]&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  Vendor, Cisco       [26]  42&lt;br /&gt;.Nov 10 12:38:42: RADIUS:   Cisco AVpair       [1]   36  "template:ip-unnumbered=Loopback 10"&lt;br /&gt;.Nov 10 12:38:42: RADIUS:  Framed-Protocol     [7]   6   PPP                       [1]&lt;br /&gt;.Nov 10 12:38:42: RADIUS(000E4E19): Received from id 1645/79&lt;br /&gt;&lt;br /&gt;Somebody can help me?&lt;br /&gt;&lt;br /&gt;Thank you in advance.&lt;br /&gt;</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4e6f9" messages="1" subscribed="yes" title="Restricting Access to Group"><Message attachment="no" canreply="yes" id=".2cd4e6f9" level=""><Author authinfo=" DNET">joe.marcelo9</Author><Timestamp>Nov 9, 2009, 9:41pm PST</Timestamp><Msgbody>Hello&lt;br /&gt;I have ACS 4.0 authentication through external database Windows Active Directory. I want only support group created on ACS to have access rights to AAA client [Routers,Firewall,Switches] for telnet &amp; SSH all members of other group should be denied.&lt;br /&gt;&lt;br /&gt;Groups are created.&lt;br /&gt;AAA members are added to ACS&lt;br /&gt;but restricting to specific group not working</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e6f9/0" level="1." new="yes"><Author authinfo=" extraxi.com (reporting &amp; audit compliance solutions for CiscoSecure ACS)">darpotter</Author><Timestamp>Nov 10, 2009, 1:30am PST</Timestamp><Msgbody>Assuming you&apos;ve confirmed that T+ authentications are actually been sent to your ACS, then it should be just a case of adding Windows group mappings:&lt;br /&gt;&lt;br /&gt;Support -&gt; ACS Support Group&lt;br /&gt;Default -&gt; NO ACCESS&lt;br /&gt;&lt;br /&gt;Group mapping is applied after AD authentication, so even if correct credentials are supplied the user will be mapped to NO ACCESS (ie rejected) if they are not a member of the correct AD group.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ca0d" messages="13" subscribed="yes" title="Denying AAA Clients to a specific user group in ACS v4.1"><Message attachment="no" canreply="yes" id=".2cd4ca0d" level="">      <Author authinfo="Architect, Insight Enterprises" ccie="yes">dgenton</Author><Timestamp>Oct 23, 2009, 8:30am PST</Timestamp><Msgbody>Using 4.1 is there a "simple" method of simply denying a usergroup the ability to even login to specific AAA clients?  Customer has a telephony group that they want to allow them to telnet and check into all the voice routers, but no other routers, they have the command sets and all that setup but wanted to see if a way to push that group simply to voice routers only ??&lt;br /&gt;thanks in advance,&lt;br /&gt;dave</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/0" level="1.">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Oct 23, 2009, 8:44am PST</Timestamp><Msgbody>You can set it up using NAR in ACS.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a0080858d3c.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a0080858d3c.shtml&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts </Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/1" level="1.1">      <Author authinfo="Architect, Insight Enterprises" ccie="yes">dgenton</Author><Timestamp>Oct 23, 2009, 8:49am PST</Timestamp><Msgbody>I looked at that, but isn&apos;t that just simply "network restriction"  I want them to be able to login to all voice routers and execute the "allowed" commands we have listed, but if they login to a data only router, to get denied access altogether, make sense ?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/4" level="1.1.1"><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Oct 23, 2009, 9:02am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;Just checked your reply. &lt;br /&gt;&lt;br /&gt;Well, you need to go bit tricky, looks like that you have data and voice routers and you want no access to data routers and restricted access to voice routers.&lt;br /&gt;&lt;br /&gt;Check this::&lt;br /&gt;&lt;br /&gt;Create two NDG&apos;s one for voice routers and other for data router&apos;s.&lt;br /&gt;&lt;br /&gt;Go to the group &gt; apply NAR on data routers with action as denied. If we are getting anything apart from valid ip address than you have to use CLI/DNIS based NAR.&lt;br /&gt;&lt;br /&gt;since you have command set created with specific commands &gt; on the same group &gt; scroll down to the Shell Command Authorization Set&lt;br /&gt;&lt;br /&gt;Assign a Shell Command Authorization Set on a per Network Device Group Basis&lt;br /&gt;Here you can map VOICE router&apos;s NDG with respective command authorization set.&lt;br /&gt;&lt;br /&gt;So this way we can denied access to data routers and restricted access to voice router&apos;s.&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/2" level="2."><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Oct 23, 2009, 8:50am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;Why don&apos;t you use NAR (Network access restriction)&lt;br /&gt;&lt;br /&gt;Under the network config &gt; simply create one NDG and assign all the voice router under it.&lt;br /&gt;&lt;br /&gt;After that go to the group/user where you want to put this restriction&lt;br /&gt;&lt;br /&gt;You need to check that what are we getting in calling station id. If we are getting ip address then &lt;br /&gt;&lt;br /&gt;[1] To accomplish above we would configure the group with following &lt;br /&gt;NAR (network access restriction)&lt;br /&gt;&lt;br /&gt;Define IP based Network Access Restriction&lt;br /&gt;Permitted Calling Point&lt;br /&gt;AAA client: VOICE NDG created &lt;br /&gt;Port				*&lt;br /&gt;Src IP Address	*&lt;br /&gt;&lt;br /&gt;Subit the changes and try.&lt;br /&gt;&lt;br /&gt;Here is more on configuring Network Access Restriction:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4&apos;)"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4&lt;/A&gt;.&lt;br /&gt;2/user/guide/GrpMgt.html#wp478900&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/3" level="2.1">      <Author authinfo="Architect, Insight Enterprises" ccie="yes">dgenton</Author><Timestamp>Oct 23, 2009, 8:53am PST</Timestamp><Msgbody>Thanks I will give that a shot, that&apos;s what was hanging me up on the NAR was that it showed CLID/DNIS but they are local telnet users...</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/5" level="2.1.1" new="yes">      <Author authinfo="Network Engineer, SYNCON TECHNOLOGIES">kwillacey</Author><Timestamp>Nov 9, 2009, 12:32pm PST</Timestamp><Msgbody>What do the stars mean, is it a wild card?&lt;br /&gt;&lt;br /&gt;If I select deny access and all AAA clients and apply it to a group. Does that mean that they will not have access to the AAA client? ie they will not be able to authenticate and log on to a router.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/6" level="2.1.1.1" new="yes">            <Author authinfo=" Cisco Systems">jgambhir</Author><Timestamp>Nov 9, 2009, 12:45pm PST</Timestamp><Msgbody>Yes it is a wild card.&lt;br /&gt;&lt;br /&gt;Yes, if condition is deny for all aaa-client then that group will not have access to all clients.&lt;br /&gt;&lt;br /&gt;Access denied.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;~JG&lt;br /&gt;&lt;br /&gt;Do rate helpful posts</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/7" level="2.1.1.2" new="yes"><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Nov 9, 2009, 12:49pm PST</Timestamp><Msgbody>Hi Kelvin,&lt;br /&gt;&lt;br /&gt;You got it right. * means wildcard and if we use (*) for port and source address then it would assume any port/address.&lt;br /&gt;&lt;br /&gt;If you use action as deny for all aaa client then users of that group in ACS will not able to access any device.&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/8" level="2.1.1.2.1" new="yes">      <Author authinfo="Network Engineer, SYNCON TECHNOLOGIES">kwillacey</Author><Timestamp>Nov 9, 2009, 12:54pm PST</Timestamp><Msgbody>OK thanks that&apos;s what I was hoping. One more question, if I have remote access VPN on an ASA and authentication is provided via the ACS and I add the NAR as I described earlier would those users in the group still be able to authenticate?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/9" level="2.1.1.2.1.1" new="yes"><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Nov 9, 2009, 1:50pm PST</Timestamp><Msgbody>Hi kelvin,&lt;br /&gt;&lt;br /&gt;They will be able to connect if you are using ASA for VPN using radius protocol.&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/10" level="2.1.1.2.1.1.1" new="yes">      <Author authinfo="Network Engineer, SYNCON TECHNOLOGIES">kwillacey</Author><Timestamp>Nov 9, 2009, 1:54pm PST</Timestamp><Msgbody>I am guessing if it is using TACACS then it is going to be a problem, am i right?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/11" level="2.1.1.2.1.1.1.1" new="yes"><Author authinfo=" CISCO SYSTEMS">jkatyal</Author><Timestamp>Nov 9, 2009, 1:58pm PST</Timestamp><Msgbody>Kelvin,&lt;br /&gt;&lt;br /&gt;You are correct. If we are using tacacs for both the sessions then this would not work because rem_address would be same and that will not allow the vpn users because NAR is there.&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;&lt;br /&gt;JK&lt;br /&gt;&lt;br /&gt;Plz rate helpful posts-</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ca0d/12" level="2.1.1.2.1.1.1.1.1" new="yes">      <Author authinfo="Network Engineer, SYNCON TECHNOLOGIES">kwillacey</Author><Timestamp>Nov 9, 2009, 2:01pm PST</Timestamp><Msgbody>ACS 3.2 does not have device groups so I cannot separate the devices.... thanks a lot I&apos;m gonna have to think about it some more.</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Replies></Conversation></Topic></Forum></Community></ActiveMessages>')
