ACS 4.1 for Windows, command accounting.

ACS doesn't log the command into the csv file.
I have verified that device sends the acct message, the tacacs service (in full log mode) reports the message but there isn't an entry into the csv TACACS+ Admin.
Thanks.
Andrea

TACACS+ Administration logginig is enabled.
This is the service log with the cmd attribute.
TCS 19/01/2009 09:20:16 I 0043 1196 <<< RECEIVED FROM CLIENT:sw-core11 TYPE=ACCT, SEQ=1, FLAGS=1
TCS 19/01/2009 09:20:16 I 0043 1196 SESSIONID -424833774 (0xe6ad8d12), DATALEN 130 (0x82)
TCS 19/01/2009 09:20:16 I 0043 1196 ACCT, flags=0x4 method=6 priv_lvl=15
TCS 19/01/2009 09:20:16 I 0043 1196 type=1 svc=1
TCS 19/01/2009 09:20:16 I 0043 1196 user_len=7 port_len=4 rem_addr_len=10
TCS 19/01/2009 09:20:16 I 0043 1196 arg_cnt=6
TCS 19/01/2009 09:20:16 I 0043 1196 USER=ameconi
TCS 19/01/2009 09:20:16 I 0043 1196 PORT=tty1
TCS 19/01/2009 09:20:16 I 0043 1196 REM_ADDR=10.4.42.63
TCS 19/01/2009 09:20:16 I 0043 1196 arg[0](size=12)=task_id=2598
TCS 19/01/2009 09:20:16 I 0043 1196 arg[1](size=21)=start_time=1232353216
TCS 19/01/2009 09:20:16 I 0043 1196 arg[2](size=12)=timezone=MET
TCS 19/01/2009 09:20:16 I 0043 1196 arg[3](size=13)=service=shell
TCS 19/01/2009 09:20:16 I 0043 1196 arg[4](size=11)=priv-lvl=15
TCS 19/01/2009 09:20:16 I 0043 1196 arg[5](size=25)=cmd=terminal monitor
TCS 19/01/2009 09:20:16 I 0043 1196 END >>>
TCS 19/01/2009 09:20:16 I 0688 701436 Single Connect thread 1 allocated work
TCS 19/01/2009 09:20:16 I 0043 701436 <<< PACKET TO CLIENT:sw-core11 TYPE:ACCT, SEQ 2, FLAGS 1
TCS 19/01/2009 09:20:16 I 0043 701436 SESSIONID -424833774 (0xe6ad8d12), DATALEN 5 (0x5)
TCS 19/01/2009 09:20:16 I 0043 701436 ACCT/REPLY status=1
TCS 19/01/2009 09:20:16 I 0043 701436 msg_len=0 data_len=0
TCS 19/01/2009 09:20:16 I 0043 701436 End >>>
All logs seems to be ok!
Thanks for your help.
Andrea

Similar Messages

  • ACS 3.2 for Windows and MS Windows AD Directory Integration Problem

    Dear all,
    We have some issues while integrating Windows AD with ACS 3.2 for Windows.Currently we have done the following:
    1. Installed ACS 3.2 for Windows on Windows 2003 Enterprise with SP1
    2. ACS and Domain Controller are configured on the same server
    Checked and verified the following configurations
    1. created a domain user "csacs" selected Act as a part of operating system and log on as a service enabled for this user.
    2. Enabled all the CS services to log on as a user csacs.
    But I noticed CS services are not respdonding and gives the error as "Could not able to start the service with service specific error ..." while trying to start services manually on ACS.
    Kindly help me through this integration part
    An easy and handy Step wise procedure on configuring integration of AD with ACS 3.2 on both Domain Controller and on Member server will be of great help.
    Thanks
    Kind Regards,
    Ahmed

    I have no issues running Cisco ACS version 3.2 on Windows
    Server 2003 with SP2:
    1) create user test1 in MS Active Directory and put test1
    in users group with dial-in access granted,
    3) Create a group called "LDAP". Actually I renamed
    group name "group 1" to "LDAP".
    3) in ACS external user database configuration, I specified
    domain "CCIE" as for this. unknow user policy is to use
    Windows Database configuration,
    4) Configure the database configuration in ACS to point
    to "CCIE" windows domain,
    5) setup the ACS to authenticate one of your Cisco devices
    and log in using the MS windows account,
    By the way, mgurwara, you are wrong. I run Cisco
    ACS 3.2 on windows 2003 Enterprise Edition with Service
    Pack 2. I am running it on a Dell Optiplex Gx240
    (1.7 GHz with 512MB of RAM) and it is running fine.
    I use it to manage about 20 cisco devices and
    about 200 Wireless LEAP user(s). Furthermore, I am also
    running ACS 4.1 on another identical hardware. It has
    nothing to do with the hardware. I don't know where
    you get that information from.

  • CA and Certificate Issue in ACS 4.0 For Windows 2003 Enterprise Server

    Hi,
    I have configured Microsoft CA server on the same ACS 4.0 for Windows 2003 enterprise server which was configured earlier using the self generated certificates for EAP and PEAP authentications.
    After I change the certificate from self generated to the new CA certificate that can be viewed under install ACS certificate option on ACS server but having the following problems
    1. SSL is not functioning while internet browser access to the ACS server and going through http instead of https.
    2. Wireless clients are authenticated successfully even after the certificate is uninstalled.
    Any help on these problems will be appreciated.
    Thanks
    Best Regards,
    Ahmed

    Hi Rohit,
    Thanks for reminding the HTTPS option under Administration Control on ACS.
    I have some doubts pertaining to installation of certificates on Wireless clients though it is optional for Self Generated Certificates but what in case of Mirosoft CA as I tested wireless client authentications even after removing the certificate from microsoft supplicant WindowsXP SP2 having installed the patch KB885453 for PEAP. How the certificate on wireless client works.
    Is it mandatory or optional to keep certificate on Wireless Clients as they could able to get authenticated through ACS after removing the certificate.
    Thanks
    Best Regards,
    Ahmed

  • CiscoSecure ACS v2.4 for Windows NT Upgrade

    We still have two ancient instances of CiscoSecure ACS v2.4 for Windows NT running on our network. ACS1 (primary) and ACS2 (secondary). I would like to upgrade these, not only because of how old they are but because of an issue trying to replicate the user and group database from ACS1 to ACS2. When trying to replicate the user and group database the logs say it's successful but the databases don't match. ACS2 is missing some of the users that are in ACS1. I have successfully replicated the interface database. But for whatever reason, the user and group database will not replicate.
    First, is there any other way I can get the user and group database copied from ACS1 to ACS2? Other than using the built in database replication tool?
    Second, is there any way I can get these upgraded? I read that the recommended upgrade path is 2.4->2.6->3.0->3.2. But Cisco no longer has version 2.6 available for download. I really would like to upgrade rather than starting from scratch.
    Thanks!

    ACS 2.4 - wow! That hasn't been sold for over 11 years. (reference)
    Think about it - would you want to try to upgrade Windows 98 to Windows 7? That's about an equivalent span of software product timeline.
    The current product is so different that even if you could upgrade it would not be advisable to do so. While painful, it would be much better option to make a clean break with the old and move onto a current platform (e.g ACS 5.3).

  • Advice for Buying Cisco Secure ACS 3.3 for Windows

    Just need advice on what other things I NEED to order apart from the Windows server when I want to iplement ACS and I want to use CISCO SECURE ACS 3.3 FOR WINDOWS
    Hope someone will help

    Hi,
    This is all what you require:
    Supported Operating System
    Cisco Secure ACS for Windows Servers 3.3 supports the Windows operating systems listed below. Both the operating system and the service pack must be English-language versions.
    •Windows 2000 Server, with Service Pack 4 installed
    •Windows 2000 Advanced Server, with the following conditions:
    –with Service Pack 4 installed
    –without features specific to Windows 2000 Advanced Server enabled
    •Windows Server 2003, Enterprise Edition
    •Windows Server 2003, Standard Edition
    Note The following restrictions apply to support for Microsoft Windows operating systems:
    •We have not tested and cannot support the multi-processor feature of any supported operating system.
    •We cannot support Microsoft clustering service on any supported operating system.
    •Windows 2000 Datacenter Server is not a supported operating system.
    Please refer to the following link for more information:
    http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/win33sdt.htm
    Thanx & Regards

  • Cisco Secure ACS 4.2 for Windows web-based Admin Console log in problems

    To Whomever Can Assist,
          I am running two deployments of Cisco Secure ACS for Windows 4.2 and I can login into the admin web-console just fine.  However, when I create a new or test user that mirror my configuration that user cannot login to the admin web-console.  The user can login it to devices with the appropriate privileges, but can't administer his/her account within ACS.  This has proven very problematic and needs a remedy.  Thanks for the assistance.

    Bradbryant.dhs,
    Where are you creating the new admin user who should have access to ACS web gui under internal users or administration.
    Internal user and ACS administrator accounts are completely different. 
    Adding administrator account
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4-2/user/guide/ACS4_2UG/Admin.html
    Regards,
    Jatin Katyal
    ** Do rate helpful posts **

  • ACS 5.3 and Windows AD account lockout

    Currently on 5.3.0.40.2 when a invalid password is attempted via TACACS or RADIUS to the AD identity store is locks the account out on the first failed attempt. The AD policy is lockout after three attempts. Is there a way to fix this issue so the account is not locked out with only one failed attempt? I see options for local password policys in ACS but nothing for the identity store. For what its worth this happened also with ACS 4.X deployment before we moved to ACS 5.3.
    Just wanted to see if this is the expected behavior or if I should open a TAC case to see what is causing this.
    Thanks.

    Hi;
    Well, we got it working. Not sure of the exact fix, but allow me to ramble, perhaps it will help someone else.
    We think that a combinationof factors caused the problem. First, we had clock drift, and that resulted in clock skew messages in the logs like these:
    Sep 20 18:06:03 ecb-acs1 adclient[8322]: INFO  base.adagent start: Problem connecting to domain controller (KDC refused skey: Clock skew too great), will try again later.
    and
    ecb-acs1 adclient[1163]: WARN  base.bind.cache LDAP fetch CN=bubba,OU=staff,OU=edcenter,OU=edcenterarea,OU=episd,DC=episd,DC=org threw unexpected exception: SASL bind to ldap/[email protected] - GSSAPI Mechanism with Kerberos error ": Clock skew too great"
    Somehow the ACS lost the ntp config, very disturbing, because I know that one of the first things I did was setup NTP. So I re-did the ntp config, confirmed the time was accurate. Still failed. Then, because I was annoyed by the log entries comning out in UTC, I did a clock timezone to set it to local. That made the logs come out in local time, but might have caused other problems (I saw another forum entry for that) so I set it back to UTC.
    This begs the question - how to leave the timezone at UTC but fix the timestamps for the logs? This is easy on Cisco switches.
    Various reboots of the ACS after deleting the object in AD did not fix the problem. During these reboots I continued to use the original userid and password to authenticate. At all times, the "test connection" button showed that the credentials were OK.
    Because we had recently added our first Win2008 domain controller to our world (all ther other DCs are Win2k3), we started worrying about this:
    http://support.microsoft.com/kb/978055/en-us
    But, after some checking, it seems as if we already had the fix applied.
    Next, we created a dedicated user in AD for the ACS to use when authenticating. Deleted the ACS object, restarted the ACS, applied those new credentials. Still broken.
    Our AD admin looked in various logs and found some things, here is his summary:
    ----------- from Danny --------
    Checked the domain controller log under system.  Found the following:
    While processing an AS request for target service krbtgt, the account ecb-acs1$ did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of 1). The requested etypes : 17. The accounts available etypes : 23  -133  -128  3  1. Changing or resetting the password of ecb-acs1$ will generate a proper key.
    and
    While processing an AS request for target service krbtgt, the account stcrye did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of 2). The requested etypes : 18. The accounts available etypes : 23  -133  -128  3  1. Changing or resetting the password of stcrye will generate a proper key.
    This may be related to either clock scew between acs and the domain or introducing server 2008 domain controllers into an existing server 2003 domain. 
    On a desperate hunch, after yet again deleting the ACS object in AD and reloading the ACS, I used the new dedicated ACS user account, but gave it a wrong password. Hit save, watched it fail. Then I put in the correct password, hit save, and it worked! Finall we have re-joined and are connected to the domain.
    BUT ... I have now lost all confidence in ACS 5.3 . We are in the middle of a major rollout of WiFi clients using 802.1x authentitcation, replacing our previous pre-shared WPA setup. We are talking > 20,000 WiFi clients. If ACS <--> AD is not rock-solid, I need to try something else. Should we consider using LDAPS instead?
    Steve

  • Delete proxy config on Cisco Secure ACS 4.1 for Windows ?

    We have a pair of ACS 4.1 servers (Windows Server 2003 R2). Let's call them ACS1 and ACS2.
    We don't want either one of them to proxy to any AAA server, including each other. We're using mostly TACACS authentication.
    While troubleshooting a general problem, I'm guessing that one of us did this on ACS1:
    pressed the Network Configuration button,
    saw the Proxy Distribution Table
    clicked (Default)
    moved ACS1 from the AAA Servers column to the Forward To column.
    So, essentially, we're telling ACS1 to proxy all requests to itself, which doesn't seem to make sense. I don't know for sure whether it should work when configured to "self proxy," but in that state, it does not authenticate anyone and gives merely "Internal error" as the reason.
    If I change the configuration so that "ACS2" appears in the Forward To column, and I move "ACS1" back to AAA Servers and restart, ACS1 starts responding correctly to TACACS requests. Of course, ACS1 is just proxying all requests to ACS2, so having two servers isn't doing much good.
    I cannot simply remove ACS1 from the Forward To column and leave it empty. The interface complains that it can't forward to zero servers. Of course, on ACS2, there are no servers in the Forward To column, since we never touched the Proxy Distribution Table there.
    Is there any way to return the Proxy Distribution Table to its default setup, that is, no servers appear in the "Forward To" column?
    We're planning to upgrade to version 4.2 very soon, so this question is mostly academic, unless the same problem exists in 4.2.
    For full disclosure, I should mention that the problem we were troubleshooting was loss of connectivity to our Windows Domain Controllers from our ACS servers. We had missed adding some exceptions in our firewalls to allow for four new DCs. As far as we can tell from testing, connectivity to the DCs is now fine. The firewall rules group ACS1 and ACS2 together, so connectivity should be the same, and ACS2 authenticates users correctly.

    Hello Jeffrey,
    By default the ACS 4.x Proxy Distribution Settings should have the ACS entry for itself on the Forward To box. Your ACS1 entry should be on the Forward To box.
    The Internal Error message on the ACS should be highligthing a different issue on your ACS1. Also, the message stating that we cannot have zero servers on the "Forward To" box is expected.
    Set your ACS1 for Full Logging Detail (System Configuration > Service Control) and configure the ACS1 entry under the Forward To box. Recreate the authentication issue and collect a package.cab file. If you have an ACS for Windows, under the ACS Installation folder look for the CSAuth folder > Logs and share the auth.log file with a failure timestamp for us to review the ACS logs when failing with Internal Error.
    If this was helpful please rate.
    Regards.

  • Csutil.exe error in ACS 4.1 for Windows

    Hi,
    When I try to list VSAs created on the ACS by running csutil.exe -listUDV at the cmd prompt I get the error "can not initialize schemelayer".
    What could be the problem?

    Hi,
    It usually happens when the end-user is not logged into the machine with the local administrator account. The account you are using does not have full permissions on the server to run this utility.
    Could you please confirm that the Windows User account that you are using to logon to the ACS server and run csutil has full Administrative rights on the "local" machine.
    Are you using RDP/terminal server to do this? If so, Can you try from Console/VNC (type program) and let me know if you see the same thing? Upgrades/Installs/Backups and csutil processes are not supported via RDP sessions as they are untested and known to cause problems. It is highly possible that the RDP session account has privilege issues and hence the scheme layer is not initializing...
    HTH
    JK
    Plz rate helpful posts-

  • ACS 4.2 For Windows DB Replication

    Hi Folks.
    I have a pair of ACS for windows 4,2 and we also have a few mappings (ACS Group --> AD Group)
    The replication process was configured and it replicates all the seetings, but the Group Mappings.
    Is this the way it's supposed to be or it should replicate the group mappings as well?
    Best regards,
    AL

    The following items cannot be replicated:
    •IP pool definitions (for more information, see About IP Pools Server).
    •ACS certificate and private key files.
    •Unknown user group mapping configuration.
    •Dynamically-mapped users.
    •Settings on the ACS Service Management page in the System Configuration section.
    •RDBMS Synchronization settings.
    User guide
    http://www.ciscosystems.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/SCAdv.html#wp756078
    Regards,
    Jatin
    Do rate helpful posts-

  • ACS SE setup for windows authentication

    Dear All,
    I'm trying to install an ACS Solution Engine in My network for access control (AAA). I succeed in setting up authentication using the internal database and that works fine. Now My boss want users to be authenticated through an external database (windows AD). I tried achieving this but kept getting different errors.(like EAP-TLS or PEAP authentication failed during SSL handshake) or (Authen session timed out: Challenge not provided by client).
    Please I need someone who has done this setup successfully before to give Me a step by step procedure on how I can setup ACS SE for windows authentication using My domain windows authentication.
    Thanks

    Dear All,I'm
    trying to install an ACS Solution Engine in My network for access
    control (AAA). I succeed in setting up authentication using the
    internal database and that works fine. Now My boss want users to be
    authenticated through an external database (windows AD). I tried
    achieving this but kept getting different errors.(like EAP-TLS or PEAP
    authentication failed during SSL handshake) or (Authen session timed
    out: Challenge not provided by client).Please
    I need someone who has done this setup successfully before to give Me a
    step by step procedure on how I can setup ACS SE for windows
    authentication using My domain windows authentication.Thanks
    Hi,
    Check out the belwo link on your query,Hope that help !!
    https://supportforums.cisco.com/docs/DOC-5542
    If helpful do rate
    Ganesh.H

  • ACS 5.1 for Windows VM Ware

    Hello,
    Please help me...
    I want to know can we install ACS 5.1 in Windows VM Ware machine. I have downloaded it but it is giving me the option of installation in Linux.
    Please suggest.

    Ravi,
    This release of ACS 5.1 provides new architecture and functionality on a standard Cisco Linux-based. We would be requiring a new box all together for 5.0.
    Installing ACS on VMware virtual machine
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/installation/guide/csacs_vmware.pdf
    ACS 5.1 doesn't support windows OS.
    HTH
    JK
    -Do rate helpful posts-

  • ACS SE & CSACS for windows

    Hello Friends,
    If i order Access Control Server Solution Engine (ACS SE) CSACS-1120-K9, i should'nt order a CSACS for windows CD,????? Is it ACS server is built-in in ACS SE no need of installing windows OS and on top of that ACS server ,i m confuse regarding the product.
    Can anybody help me for this,i have been through the cisco web site but not pretty sure regarding these two product.
    Thanks

    CSACS-1120-K9 is an ACS appliance, and it supports both ACS version 5.0 and 5.1.
    Here is the release notes for both versions:
    5.0: http://cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.0/release/notes/ACS-50-releasenotes.html
    5.1: http://cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/release/notes/acs_51_rn.html
    FYI, ACS version 5.x onwards is completely different to the previous version of ACS 3.x and 4.x.

  • ACS 3.3 for windows - Win AD and eap-tls problem

    Hi,
    I have a problem with an ACS to authenticate users with certificate on MS AD.
    Working things:
    PEAP authentication with the MS AD;
    EAP-TLS authentication with the local DB.
    Not working things:
    EAP-TLS authentication with MS AD.
    Because I'm able to auth users with PEAP on MS AD, I guess my config on MS AD is correct.
    Because I'm able to auth users with certif in EAP-TLS, I guess my certif config is correct.
    So, why it's not working with the combination EAP-TLS and MS AD.
    I receive the error 'External DB Account Restriction'
    Thanks for your help.

    Hi,
    This is what is interesting,
    AuthenProcessResponse: process response for 'phd' against Windows Database
    Unknown User 'phd' was not authenticated
    Done RQ1027, client 50, status -2125
    The field that is being picked from certificate has the value 'phd', check you check which field is it.
    And was the logging at full?, I think something is missing in the logs.
    Lets do a sanity check, and go through following link again,
    http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a008068d45a.shtml
    Regards,
    Prem

  • Self Generated certificate validity issue in ACS 4.0 for Windows

    Hi,
    Is there any solution to extend the validity time of self generated certificate on ACS, by default the validity is set for one year.
    As the server certificate on one of the ACS which is CA has expired and need to renew it.
    Is it possible only one certificate from third party can be used both as a server certificate and certificate from CA for other ACS servers.
    Thanks in Advance
    Regards,
    Ahmed

    Other solution would be to create an in house(Microsoft probably) CA, and get a certificate for your ACS server. Go through the installation steps of Microsoft CA before, as the validity date for Server Certificate(i guess) is configured during initial install of CA.
    Regards,
    Prem

Maybe you are looking for

  • Transfer iTunes and Outlook data to a new PC

    I'm successfully logged into Homeshare with my old computer and I've tried the methods listed here, but can't get to the "import" button that is supposed to import selected items. Is there an easy way to just take my data (Music and Outlook data incl

  • How to delete albums off iphone

    I need to delete my photo albums off my iphone and I don't want them to load form my iphoto program in the future, how dod I do this?

  • Specify image for a pop-up LOV in a tabular form?

    Hi, I am using a tabular form for users to edit data. One of the fields has too many options to use a select list, so I have to use a pop-up lov (query based)... grrrr The lov shows up in my form as [Field value]List I would like to remove the text "

  • Web server works externally, but not internally

    Hi I'm kind of new to this. I got my web server working exteranlly, but within my internal network, the webserver only works if I input the actual ip address and not www.example.com. I have a Cisco RVS4000 set as a gateway and a Mac Mini with Server

  • ConvertTo-HTML Problem

    Hi, I'm writing my first script and everything is working ok.. except when i try to convert it to html. i have tried a few different ways but cant seem to get it right. the closest i have got is: Function BSValidate-PPServer {     Param (         [St