ACS appliance External Auth to NT 4.0

Hi
I am installing the ACS appliance to do external database authentication to NT 4.0 PDC. It appears with the appliance you have to install a remote agent to make this work. It is my understanding this agent must run on a win2k box. Does the agent have to be installed on the PDC or can it go on any windows server box?
Is there a work around if you do not have a win2k server. This network is still NT4 with now win2k boxes
Thanks

The remote agent was not tested on NT4 and probably wouldn't even install properly. Even if it did work, you would be very limited in the support you'd get if you had strange problems because it is an unsupported configuration.
It doesn't have to go on a PDC, but things just seem to work better if it is on a DC of some sort. At the very least it needs to be on a member server, but as I said, I'd recommend putting it on a BDC from experience.
The release notes/install guide for it is here:
http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/raig/index.htm

Similar Messages

  • For those having EAP auth issue using the ACS appliance

    Thought I'd pass along my config and resolution to an issue I was having concerning EAP-TLS auth on an ACS appliance.
    We have two ACS Solution Engines (3.2.2) running and doing a database synch and using Generic LDAP as the external database. We did the certificate walk through for the ACS and then turned on EAP-TLS auth. We are trying to use EAP-TLS auth for wireless access through our AP1200s and Windows XP laptops, but we kept getting errors.
    After digging for days I found out that when you request a certificate it pulls the CN name. Our CN name in Active Directory did not match our login name. I changed my CN name to match my login name and I was then able to grab a certificate and authenticate using EAP-TLS for our wireless.
    I am in the process of upgrading our ACSes to ver 3.3.2 so that I can run the Remote Agent for Windows on a Windos 2003 server and then use the Windows database as the external database and not Generic LDAP.
    I hope this helps someone!
    Jeff

    The document discusses the Extensible Authentication Protocol Transport Layer Security (EAP-TLS) authentication protocol deployment in wireless networks.
    http://www.cisco.com/warp/public/cc/pd/sqsw/sq/tech/acstl_wp.htm

  • Migrating from Windows to the ACS appliance

    I'm in the process of migrating ACS from Windows to an appliance. I did a recovery and I chose to restore the DBs and the system config. However, I'm getting emails from the appliance with the name of the old windows machine where ACS was running. I guess this a result of restoring the system config. Does anyone know how to configure the emails to be sent with the current appliance name? And it is not possible, how can I restore the appliance to factory defaults so I can do the recovery again only for the DBs? Many thanks,

    well ... the easy way out is to re-image the ACS appliance and then replicate between the Windows server and the appliance . This will replicate all your settings from the windows ACS to appliance except the external database configuration that you need to manually configure.
    Note : for replication both the ACS for windows and the appliance should be on the same version .

  • ACS appliance 4.1 - machine authentification from trusted Domain failed

    We have a acs appliance 4.1 with a agent running on a X domain controller to authenticate user's from the X domain active directory.
    User's and Computer's are able to authenticate without any issue on X domain.
    We have recently add a trusted Y domain on this X domain.
    User's from Y domain are able to authenticate on our ACS without any issue , but machine are not able to authenticate.
    03/14/2011
    10:44:32
    Authen failed
    host/FLADWS0072.Ydomain
    Default Group
    00-26-82-d6-9b-3f
    (Default)
    External DB user invalid or bad password
    Machine use is the following settings to authenticate :
    EAP type : EAP (PEAP) 
    Authentification method : EAP-MSCHAP v2
    On Y domain active directory :
    Remote access permission is ok for machine
    On ACS applicance :
    "Enable PEAP machine authentication" is select + the machine from X Domain are authenticate without any issue.
    Any idea where is should start to invetigate ?
    Tks in advance for your help

    Dear Valued Cisco Customer,
    I will be out of the office from 03/20/2010 until 04/04/2010. During
    this time, I will have no access to email or voicemail. If you require
    assistance during my absence, please contact Manivannan Srinivasan via
    phone at 469-255-4806 or via email at [email protected] and this
    engineer will continue to work any immediate concerns you may have at
    this time. If this issue can wait until my return on 04/05/2010, I will
    be glad to continue working with you. If you require assistance outside
    of our business hours (10:00am - 7:00pm CST), please contact the TAC by
    calling 1800-553-2447 or email [email protected] and request to have the
    service request re-assigned.
    Best Regards,
    Abhishek Neelakanata

  • ACS Appliance - Advance filtering

    Hi all
    Quick question about my NAC setup on the ACS appliance.
    I have create a number of Network Access Profiles from the templates that ACS provide. All is working fine but my question is in regards to the Advanced Filtering under the NAP.
    When I created a template to support L2-802.1x users it placed the following attributes into my advance filter
    [026/009/001]cisco-av-pair not-exist aaa:service
    [006]Service-Type != 10
    And when I created a template to support mac-auth-bypass it placed these following attributes into my advance filter
    [026/009/001]cisco-av-pair not-exist aaa:service
    [006]Service-Type = 10
    What does the following line do?
    [026/009/001]cisco-av-pair not:exist aaa:service
    And what do these 2 lines do exactly.
    [006]Service-Type != 10
    [006]Service-Type = 10
    Thanks
    Dale

    "cisco-av-pair not:exist aaa:service"
    means to match, the incoming request must NOT include a cisco-av-pair VSA attribute that contains the value "aaa:service=........"
    remembering that the cicso-av-pair is like a container for TACACS+ style attributes of the form "protocol:attr=value" eg "ip:addr=1.2.3.4"
    RADIUS Service-Type 10 is "Framed Routing" which has been reused for some purpose by the NAC people. Not sure what it denotes but your filters are looking this attribute != (not equal to) and equal to this value.

  • ACS appliance 3.2.2.5 Remote Agents for Windows DB disappear

    I have two ACS boxes: one is ACSNT and the other an ACS appliance. Both run 3.2.2.5 and have been in production for quite some time. The ACSNT box is the primary and replicates to the appliance as backup. These units authenticate to three different Windows domains: 2 NT domains and 1 AD.
    Recently I just added support for RSA 6.0 servers. Not wanting to mess with the client install on the ACSNT box, I set it up as a RADIUS token server as you do on the appliance. It works just fine on the ACSNT box. On the appliance, however, my Windows external DB quit working with "external db not operational" messages. I rebuilt the Windows external DB, recreated the group mappings, added the remote agents, etc. Things were working fine. I recreated the RSA config and still the Windows DB was working although the RSA config was not working (still working on that if TAC ever calls me back). A few hours later, I decided to check the Windows DB and it was broken again. I checked it out and the remote agents were somehow deleted. Nothing in the logs show it but they were gone. I recreated them and it worked again. This has happened twice now. Does anybody have any advice? The logs show nothing to indicate a problem on the appliance exists and of course the docs state that there should be no problem with both a RADIUS and Windows DBs living together on the same box. All comments welcome!
    Thanks,
    Rik

    Sorry it took so long to get back...I've been out of the office for a few days.
    I did check the the docs for issues like this but found nothing. The TAC Engineer escalated it and both engineers kept saying my new RSA servers were causing my issues. However, a simple reboot of the box (it is built on Win2K after all...) cleared up all of the strange issues.
    Thanks,
    Rik Guyler

  • ACS appliance setup help

    Network environment:
    - Windows 2003 with enterprise CA
    - Cisco ACS appliance 4.1.1.23
    - Cisco 1240 AG series APs
    Wireless clients:
    - Windows XP SP2
    Brief steps taken:
    - Installed Enterprise CA
    - Created copy of web server certificate with option “Mark keys as exportable” enabled. Certificate published.
    - Created global group in AD that contains test user and a single laptop that is a member of domain - for auto enrolment.
    - Generated certificate request from ACS (1024 key length).
    - Submitted server request from ftp server - Submit a certificate request using base 64…
    - Submitted CA certificate request from ftp server - Retrieve CA certificate or revocation list /base 64 encoded.
    - CA & server certificates installed in to ACS appliance (Domain certificate authority approved within ACS)
    Brief cofig of ACS appliance
    Global config
    - PEAP -Selected “Allow EAP-MSCHAPv2”.
    - LEAP - Allow LEAP (For Aironet only)
    - Selected “Allow MS-CHAP Version 1 & 2 authentication
    - Added AAA client (AP) with shared secret with authentication using “Radius (Cisco Aironet)
    - Under External user DB//DB config/windows database, “Enable PEAP machine authentication” selected.
    1240 series AP config
    - Under Server Manager, ACS IP with shared secret entered as a Radius server.
    - Selected EAP authentication.
    - Under SSID Manager selected open Authentication with EAP & selected network EAP.
    - Under Encryption Manager selected WEP Encryption & mandatory.
    - Selected key 1 and entered 128 bit key
    Client (windows XP SP2 domain member) config
    - Connected to Enterprise CA web site, base64 encoding/download CA certificate
    and installed it in local computer store.
    - Under Network authentication selected open with WEP EAP type “protected EAP (PEAP)
    - Authenticate as a computer selected
    - Selected my CA under “Trusted Certification Authorities
    - Authentication method (EAP-MSCHAP V2)
    Errors:
    Automatic certificate enrollment to local system failed to contact the AD. The specified domain does not exist or cannot be contacted.
    Or
    Computer doesn't have correct certificate
    Used 43486, 64067, 71929
    Any suggestions very much apretiated.

    ACS Agent is installed on two DC's as well and they are detected by ACS.
    Thanks

  • ACS appliance -- AD -- RSA Securid Server

    I have Cisco ACS appliance running version 3.3.2.2 and Windows Active Directory on Win2000 Advanced Server and RSA v5.2. I already installed successfully the remote agent in Active directory.
    Authentication using EAP-FAST from my wireless client going to ACS to AD is successful.
    But when authenticating going to RSA failed. I can't find logs that my ACS is communicating successfully with RSA.
    Here's more info:
    In Active Directory, remote agent for ACS installed succesfully. Agent for RSA is also installed succesfully.
    In ACS appliance, remote agent was already pointed to AD.
    No RSA SecurID Token Server found in my External User Database Configuration list. I think this is the problem.
    How can I manage to configure RSA SecurID Token Server in my ACS appliance?

    Hello,
    The configuration guideline for the ACS is described in "Configuring CiscoSecure ACS for Windows NT with ACE Server Authentication" at
    http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a0080094650.shtml
    I had this up and running with a customer. There was no AD involved though, so it is not entirely your case and there might be other obstacles on the way.
    ACS with ACE however works, though there were some nasty problems to be solved on the way to success.
    One thing to point out straight away also mentioned in the document mabove:
    Challenge Handshake Authentication Protocol (CHAP) cannot be used with the ACE tokens alone because of the requirement CHAP RFC (1994) that states:
    CHAP requires that the secret be available in plaintext form. Irreversibly encrypted password databases commonly available cannot be used.
    This precludes use of the ACE tokens for straight CHAP unless there is a separate CHAP password. For instance:
    username: xxxx
    password: xxxx
    Password Authentication Protocol (PAP) is a better choice here.
    This means the user has to enter "username*token" - the customer finally wrote a Java applet to construct the propper combination out of different clearly named input fields to simplify the input for unexperienced users.
    Hope this helps! Please rate all posts.
    Regards, Martin

  • No access to serial console in ACS appliance 111

    We have 2 Cisco ACS appliances running version ...
    Cisco Secure ACS 3.2.2.5
    Appliance Management Software 3.2.2.5
    Appliance Base Image 3.2.2.1
    The fact is that after initial setup, we have never used the console mainly because in a production environment we manage them through the Web Admin application. Now we have decided to upgrade both appliances to the latest version (3.3.3) and when we tried to connect to the serial console (115200,N,8,1, no flow control) we don't get any response from none of both ACS. It's quiet strange but we have found no way to make them work. We have tried several things I expose to you in case you can give us any hint:
    1. We have rebooted the appliance and we can see through the console all the start-up process but when it finally finishes the start-up, we see no login prompt.
    2. We have also shutdown the appliance properly and power it off and on again. Same results. The appliances boot normal but still we don't have console access.
    3. We have tried boot the appliance with the recovery CD-ROM and the console works fine. I can reset the Admin password, but when it restart from its own system ( I mean without the recovery CD_ROM), I can see all the starting messages but when it finish the start-up process ... no console access.
    4. Finally I have connected a monitor and a keyboard to the appliance ( I know Cisco dosn not recommned it but when in trouble....) and I see the full start-up process and it includes the base Windows 2000 server operating system startup. When Windows finishes loading, we get a lock screen in which the appliance informs you that it have started correctly and that we could access it for management through the serial console port or through the web console. 10 seconds later I see a pop up window stating that on or more services have not started correctly and that we shoulkd check the Event viewer, something we wished we could do but as you you, this is a secured system and I don't know if there is a back door method to verify windows services in this appliance.
    Any help would be appreciated, as the problem is identical in both the appliances and upgrading them without access to the admin console is difficult and risky.
    Kind regards.

    Hi
    I had similair problem being locked out of console after initial configuration wizard.
    I think there is a bug within the console session in that if you input a hostname of more than 15 characters, it locks up the ACS service when the server reboots. If you keep your hostname to less than 15 characters, the server reboots and you get console access. If you then access the GUI, you will see that 15 characters is the maximum, and you cannot enetr any more than this. This is not the case with the console, where you can enter more than 15 without getting an error message.
    I rescued the server by doing F8 and rebooting server with last known good configuration. from there, you can reset the hostname to something valid. You can check to see which CS services are running through console session, and start any services that may not be running..
    deliverance1> start CSAgent
    Starting service: CSAgent..
    CSAgent is starting
    CSAgent is running
    Regards
    Ian

  • Adding a Custom VSA to a Group - ACS Appliance

    Hi,
    Using a secure ACS Appliance 4.0
    I want to add a new RADIUS Vendor and its associated VSA to the ACS configuration. This will then be returned during Authorization.
    I have already added the new Vendor and the required VSA through RDBMS. I can now see the new vendor as RADIUS (vendor) in NAP Profile etc
    However I cannot seem to find a way that how would i set the Value of the Added VSA ? And assign it to a particular group ? I cannot seem to find that VSA anywhere.

    Add a AAA client with "Authenticate using" Radius(vendor)
    then go to Interface Configuration and enable VSA for Group/User
    ~Rohit

  • New ACS appliance not showing FQDN hostname in GUI

    I've installed two new ACS appliances in our environment running 5.3.  I've just configured the basics to get it on the network (ie DNS, default GW, IP address).  Looking at both running configs, they are identical with exception to the IP addresses.  On one appliance in the GUI next to the user name in the top right hand corner, the hostname is "acs01".  In the GUI on the other appliance, it shows "acs02.corp.mycompany.com".  This is a minor issue but its bugging me.  Anyone have an idea what is going on?
    In both appliances, this statement is identical in the show run:
    ip domain-name corp.mycompany.com

    Hi,
    So you are using a hardware RAID5 in storage pool as a hard disk. Now you added one more hard disk to the RAID5 with the tool "Dell Server Administrator" but it is not recognized in storage pool.
    I think it will not work as hard disk size cannot be changed after storage pool is created. It is by default.
    However why you use the hardware RAID in a storage pool? A hardware RAID seems enough for your storage requirement.
    If you have any feedback on our support, please send to [email protected]

  • Apply patch to acs Appliance

    I was wondering if someone can help me to upgrade my ACS Appliance with patch 4.1.1.23.4-SW. It was simple to apply this one in a normal server 2000. The ACS appliance I think is different because that we can access by normal terminal, keyboard and mouse.
    Some were I read that is necessary a tomcat server?
    Please help
    adi

    Hi,
    ACS v4.1.1.23 patch 5 is available so go for this new patch.
    You should have a pc which can access ACS through web interface. Keep the patch file on the PC.
    Follow the steps below on the PC:
    [1] Extract zipped file
    [2] Look for ?autorun.exe? file and double click on it
    [3] It will start a tomcat server on your desktop and you?ll see a web page asking for ACS
    SE ip address :
    Provide in the ACS SE ip address and press ?Install?
    [4] It will prompt for ACS admin username and password as shown below :
    Provide in the username and password and login.
    [5] Then it bring up ACS GUI, then go to
    System Configuration > Appliance Upgrade Status > Download,
    Then we?ll get a screen where it will ask for ip address of Install Server :
    Provide in ip address of system from where we are applying this patch, in our case our
    desktop ip address, then click connect.
    [6] It will show us following screen :
    Click on ?Download Now?
    Then it?ll show us this screen :
    Press ?Refresh? Till we see following screen :
    [7] Now press ?Apply Upgrade?. Then it?ll ask for confirmation :
    Press ?Upgrade?, then we?ll get information regarding the patch.
    Click ?Yes?.
    It?ll take few minutes to apply that patch on appliance.
    Then it?ll show us a confirmation message :
    Press ?Done?, then system will reboot.
    To confirm that patch has been applied successfully, goto
    System Configuration > Appliance Upgrade Status
    After everything is fine stop the tomcat server by clicking on ?stop distribution server? or
    if you want to apply this patch on some more appliance click on ?Install Next?
    Hope this helps.
    ~Rohit

  • RDBMS Synchronization problem in ACS Appliance 3.3

    Hi,
    I was adding multiple AAA Clients on ACS Appliance using RDBMS Synchronization option I followed the complete steps but failed to synchronize accountActions.csv file on ACS my ftp server is working fine and returned the logs saying "accountActions.csv file read recieved file successfully size 0 bytes 0.00 kbps" and RDBMS synchronization logs ACS reported as "No import CSV file on ftp server - nothing to process" I have attached related screen shots. Any help on this issue will be highly appreciated.
    Thanks in advance
    Best Regards,
    Ahmed

    The format of the accountsaction.csv file is incorrect as a result of which the RDBMS Synchronization is not executed correctly.
    I have attached a sample accountsAction.csv file for you.
    (i) The AAA Client C7609-X with the ip address 10.10.10.10 has been added with the shared secret key as mikey and is is registered with TACACS+
    (ii) The NDG michasisX has been added.
    (iii) The device C7609-X has been added to the NDG michasisX
    Place the file in the FTP and try performing an RDBMS synchronization. Restart the ACS services.
    Then you can add the devices as per the sample file attached.
    Also check if the file name is exactly the same in the RDBMS Synchronization page in the ACS
    Hope this helps,
    Soumya

  • Can a single ACS appliance be integrated with a diff OU in the AD (maybe with a diff IP address range).

    Hello Everyone,
    Can a single ACS appliance be integrated with a diff OU in the AD (maybe with a diff IP address range). If yes, how?
    Thanks,
    Rishi

    Rishi,
    Are you looking to leverage certain group in AD to be assigned to a specific subnet? If yes, then this can be done through dynamic vlan assignment.
    Thanks,
    Tarik Admani

  • ACS Appliance configuration issue.

    When I attempt to configure the ACS IP address I am getting the following error:
    "Error; Failed to get NIC configuration: <null> <FFFFFFFF>"
    The device is connected to a working ethernet port and the the physical layers have been eliminated. Aside from starting from scratch, can anyone suggest a way out of this problem?

    you need to reimage the ACS appliance.

Maybe you are looking for

  • ALV Grid Total Text (OOPS)

    Hi All, I have a simple ALV Grid Report(OOPS), I would like to give a Text for Total Row. In REUSE_ALV_GRID we have the option of giving this text, but i am not able to figure it out how to get the same in OOPS. Regards Anup

  • Enable 'CLOSE' po option

    Hi, I need your help. In my project there is a requirement to display both Cancel po and close options in the purchase summary control action but currently only the Cancel po options is coming. I am following the below navigation: Purchaning-->Purcah

  • Send html email

    Hello... Tow html email quesiotns: 1) I want to start sending promotional emails to my clients in html format. I believe that Entourage does not support this, but wondered if Mac Mail does. 2) Is there a forum that gives instructions on how to create

  • Stuck on "connect to itunes" screen after trying to update

    Update was interupted because of "unknown error" Now my Ipad is stuck on "Connect to Ituns" Have tried to reset by holding both buttons for a long time but still only returns to Connect to Itunes sceen. Itunes does not recognize the ipad. Anyone any

  • HT5071 We are mandated by another company to create an ibook for them, do we have to sell the .ibook through iBookstore if they plan on giving it to their employee?

    Basically we need to know if we offer our services in designing the ibook are we considered as distributing it to our client or is our client is the distributor as they are giving it to their employees.