How to authenticate a Non domain member laptop with AAA

Dear all,
I do have problem in resolving issue for AAA, the scenario is like if a user connect his laptop with a cisco Switch, and the computer is not a member of domain, we do like to allow internet and get an ip from DHCP server only to those users who;s computers are member of active directory. do let me know how is it possible? support will be appreciated.
Regards
Ibrahim

Hi Ibrahim,
Do you use CiscoSecure ACS?
If so, this is possible, using AAA/dot1X on the switch and configuring ACS to authenticate against Active Directory.
There are lots of configuration examples available here:
http://www.cisco.com/en/US/products/sw/secursw/ps2086/prod_configuration_examples_list.html
Specifically the wired dot1x; nac: ldap integration with acs; cisco secure acs for windows with eap-tls machine authentication.
Although some of these are for wireless, I can't see why the principle can not be applied to wired.
Also there are posts on the learning network:
https://learningnetwork.cisco.com/thread/2221
https://learningnetwork.cisco.com/thread/12897
Regards, Ash.

Similar Messages

  • Am in france how can i install itunes in my laptop with english lenguoges

    am in france how can i install itunes in my laptop with english lenguoges

    Set your computer language to english.
    Cotrol panel > Region and language.

  • How do I use ITunes on my laptop with 2 different accounts and keep music etc separate

    We have one lap top and now have 2 separate ITunes accounts.  We want our own (different) music on our own devices.  How do we keep music library separate?  Until now it was just one library, but we have downloaded from CD's my husbands old county music (loaded outside of iTunes into folder on desktop). But ifnitnis imported it will show up in the main iTunes.  How do we keep things separate?  Too bad you can't have multiple iTunes downloaded, or can you for separate accounts?

    There's a few ways of managing multiple devices (and keeping seperate content on each). The following document is worth checking through:
    How to use multiple iPods, iPads, or iPhones with one computer

  • How to invoke a non-static member from a static reference?

    Hello JDC
    My program consist of several classes. I find it more readable,logic and useful to declare all the methods in all the classes �static� and get access by Class.member().
    The problem showed up when I must use a java biuld-in method( as Component.remove ) within my static method , then I receive compile error.
    The first alternative is to create the class instance inside the static my static method , the second is to use interface which declare its member as static final. The two ways doesn�t fit to my needs , do anyone know another way?
    Thanks in advance
    Shay

    Hi
    im sorry but im not sure what you mean by "OO desgin". i'll appreciate if you'll link me some sources about this , its sound very interesting .
    It may be that you are moving to Java from COBOL or >FOTRAN or something and you are not comfortable with >OO philosophy
    For example, you can never have two instances of >the same class have different properties. What's the >point of having classes at all if you are going to do it >this way? Java is my first language , you sound very unhappy about the way i ignore the OOP , i think you right in some terms but i need to exam my thinking again and think how can i implements the same ideas in a form of OOP. whenever all those information will come i'll be able to response.
    thanks for your reply
    Shay Gaghe

  • Windows 7 -How to authenticate to WiFi (home or public) with AnyConnect NAM installed

    Hello,
    We are deploying ISE and connecting to the company's WiFi using a "machine" login (active directory laptop) works fine on Windows 7 or 8 - both wired and wireless. But, here is a scenario that I can't seem to find a good answer for. All my searches result in answers for corporate wifi; but not what I need.
    So, an employee checks out a laptop to use on a trip. It has AnyConnect 4.0.x VPN and NAM installed (SBL - GINA needs to be added). Windows 8 allows a user who has never used a Win8 laptop to connect to WiFi and authenticate before attempting to login and get their desktop. If the Win 7 or 8 laptop is connecting to a corporate AP, ISE automatically authenticates the "machine" so when they enter their user credentials, they will be logging into the Windows domain (GPO's, drive mappings, etc.). Once a Windows 7 laptop has been authenticated with ISE, it doesn't matter which user logs in, the device will already have a connection. Essentially, the user does not have to log in while within the corporate network in order to get their profile created (locally cached credentials).
    But, what if the user has no local profile and tries to use a Windows 7 laptop from their home? They need to be able to connect and authenticate to their home WiFi before AnyConnect can automatically bring up the VPN tunnel. The GINA module will do an SBL for a VPN connection but that's not going to work if they don't have a WiFi connection. This scenario is possible in my environment.
    So, can AnyConnect GINA also manage a WiFi login before a user tries to get to a desktop for the first time?
    The perfect scenario would be where we hand out emergency laptops to first time users, they connect to whatever WiFi they have access to (non-corporate), the VPN tunnel comes up and when they login, they login into the Windows domain, not locally.
    Thanks!

    Just so everyone knows...
    Please take note of the specific processor which is included with your HP Pro 3130 MT.
    HP Pro 3130 MT motherboards with specific processors do not have any onboard (integrated) graphics, although they still have the VGA and DVI connectors. This means that although you may remove the PCIe Graphics Card, you will not be able to be able to use a monitor with the onboard VGA or DVI (because there is no integrated graphics).  This also means that you will not be able change your bios to onboard graphics (because there is no integrated graphics).
    "NOTE: HP Pro 3130 with Intel Core i5 750 processor or any Intel i7 processor has no integrated
    graphics."(1)
    (1) Source: http://h18000.www1.hp.com/products/quickspecs/13640_ca/13640_ca.PDF
    If you would like to know why, let me know. Thanks!
    -Dave

  • How do I sync user 2 of laptop with my netbook without syncing user 1 of laptop to either of the others?

    I want the bookmarks and as much of the stuff on my laptop to also be on my netbook. User 1 is the original user account of the laptop. I created another account since other user didn't want my bookmarks, etc, Both users are administrators. So I want to sync the bookmarks, etc. from the second created user account (user 2) to my netbook without changing anything on user 1's bookmarks, etc.

    Hi,
    Usually this wouldn't be a problem because Firefox stores the personal data/settings in separate [http://kb.mozillazine.org/Profile_folder Firefox Profile Folders] inside each user account. You can [https://support.mozilla.org/en-US/kb/how-do-i-set-up-firefox-sync set up Sync] on the user 2 account and the netbook. To avoid problems you can make sure that you don't use this same email to set up Sync in the user 1 account, or try to Sync/Pair a Device etc. with the created user 2_netbook account from the user 1 account.
    [https://support.mozilla.org/en-US/kb/firefox-sync-take-your-bookmarks-and-tabs-with-you?redirectlocale=en-US&redirectslug=what-firefox-sync Firefox Sync]
    [https://support.mozilla.org/en-US/kb/how-do-i-manage-my-firefox-sync-account Managing Sync]
    [https://support.mozilla.org/en-US/kb/topic/sync QA]

  • How do I reformat a windows 8 laptop with a 24gb SSD properly? (ideapad u310 touch)

    I wanted to reinstall windows on my laptop so that I have a clean install (no bloatware) but I didn't want to ruin anything because i'm not too familiar with how express cache works and the other features on my laptop,
    Also, windows 8 came preinstalled and I have no CD incase I wipe the hardrives. However, I backuped some drivers that I found in a folder on the SSD onto an external harddrive.
    Please help me clean install windows especially when it comes down to settings up partitions and how to properly configure the express cache features to work with the SSD properly for best performace. Thanks

    Also why is the ssd split up into these sizes? I thought the entire drive is supposed to be used for expresscache. Or am I wrong?
    Link to picture
    Moderator comment:Please don't post the same thread(s) in multiple places as it splinters the discussion. Duplicate(s) removed. Picture(s) totalling >50K converted to link(s) Forum Rules

  • How to authenticate Out of Browser Silverlight application with SharePoint O365 site using SharePoint Web Service (.asmx) ?

    I have Silverlight Out of Browser application which uses SharePoint Lists Service (Lists.asmx). Currently when I trying to communicate to SharePoint O365 site, I am getting  the exception as below -
    Communication Exception -
    The remote server returned an error: NotFound.
    How do I authenticate the user?
    Amol C kadam

    Hi,
    You could follow below article to make sure your application configuration is correct.
    http://www.silverlighthack.com/post/2011/07/19/Office-365-Using-Silverlight-in-the-SharePoint-Team-Site.aspx
    Besides, below article could also give you some help:
    http://www.silverlightshow.net/items/Silverlight-and-Sharepoint-2010-getting-started.aspx
    Best Regards,
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • How do I set non standard print size with Epson SX515 and iMac

    I have an Epson SX515w printer and can't find any software on Epson that lets me set non standard print sizes.  From my PC Laptop I can print all Avery sizes as well as any size I want.  I want to print images to fit into small square frames.

    OS X Lion: Create a custom page size
    http://support.apple.com/kb/PH3861
    Mac OS X 10.6: Creating a custom page size
    http://support.apple.com/kb/PH6406
    OS X Lion: Page Setup dialog
    http://support.apple.com/kb/PH4606
    Mac OS X 10.6: Page Setup dialog
    http://support.apple.com/kb/PH6693
    OS X Lion: Set print options
    http://support.apple.com/kb/PH4381

  • How to transfer IPod songs to Mac Laptop with no songs?

    Songs are on my desktop and were downloaded to my I Pod mini. I want to transfer all the songs from either source to my laptop.
    How do I do that without all the songs being erased on my laptop when I connect the IPod?

    Connecting the iPod will not delete any songs on the laptod or on your desktop.
    Enable disk mode on the iPod.
    Drag them to the ipod and then the laptop.

  • HT1107 Since Mobile Me is moving to iCloud, how do you publish a domain in iweb with iCloud?

    Hello,
    I am trying to set up iWeb to publish to my own domain, and see info about doing that with Mobile Me, but since Mobile Me is moving to iCloud, how do you set it up with iCloud?  I just want to be able to publish my website directly to my own domain with iWeb.  Thanks!

    As you now know iWeb and iDVD have been discontinued by Apple. This is evidenced by the fact that new Macs are shipping with iLife 11 installed but without iWeb and iDVD.
    On June 30, 2012 MobileMe will be shutdown. HOWEVER, iWeb will still continue to work but without the following:
    Features No Longer Available Once MobileMe is Discontinued:
    ◼ Password protection
    ◼ Blog and photo comments
    ◼ Blog search
    ◼ Hit counter
    ◼ MobileMe Gallery
    Currently if the site is published directly from iWeb to the 3rd party server the RSS feed and slideshow subscription features will work. However, if the site is first published to a folder on the hard drive and then uploaded to the sever with a 3rd party FTP client those two features will be broken.
    All of these features can be replaced with 3rd party options.
    There's another problem and that's with iWeb's popup slideshows.  Once the MMe servers are no longer online the popup slideshow buttons will not display their images.
    Click to view full size
    However, Roddy McKay and I have figured out a way to modify existing sites with those slideshows and iWeb itself so that those images will display as expected once MobileMe servers are gone.  How to is described in this tutorial: iW14 - Modify iWeb So Popup Slideshows Will Work After MobileMe is Discontinued.
    NOTE: the iLife 11 boxed version Is no longer available at the online Apple Store.  To get a copy you'll have to try Amazon.com or eBay.com.
    This may be of interest to you: Life After MobileMe.
    OT

  • How do I set up my new Laptop with Time Machine?

    I just purchase a new Laptop and I want to use the Time Machine drive from my imac to set it up two questions are
    Can this be done and how?
    and
    My new machine comes with Mac OS X 10.6 Snow Leopard the imac is running Mac OSX 10.5.8 Can I do this "migration" but install the newer OS?
    Thanks for your help
    Barry

    Oh, but wait - maybe you want to migrate the settings from one machine to the other?
    You could do it from the time machine drive, again, just plug the time machine from the old machine into the new one and open migration assistant.

  • I have all my music on a external HD. How can I run iTunes on my laptop with out my EHD connected? when I open iTunes I get: Afolder containing "iTunes Library" cannot be found, and is required. Please chose or create a new iTunes library.

    It also tells me Choose iTunes Library
    iTunes needs a library to continue, you may choose an existing library or create a new one.
    I have all my music on an external hard drive (ehd) but would like to run itunes with out conecting my ehd. How can i do this? I'm

    You need the entire libary on the external, not just media.
    What are the iTunes library files? - http://support.apple.com/kb/HT1660
    More on iTunes library files and what they do - http://en.wikipedia.org/wiki/ITunes#Media_management
    What are all those iTunes files? - http://www.macworld.com/article/139974/2009/04/itunes_files.html
    Where are my iTunes files located? - http://support.apple.com/kb/ht1391
    iTunes 9 [and later]: Understanding iTunes Media Organization - http://support.apple.com/kb/ht3847
    Image of folder structure and explanation of different iTunes versions (turingtest2 post) - https://discussions.apple.com/message/13025536 and https://discussions.apple.com/message/17457605
    Once you get a complete iTunes folder on the external drive, start iTunes with the option/alt key held down and select the iTunes Library.itl file on the external drive.  You will also need to do this with your main computer or the libraries will become unsynchronized.
    Alternatively you can make a separate library using the same media on the second computer. Start as you have been doing, let iTunes create a new, blank library file which will be on hte internal drive, set the media folder location in preferences to be the one on the external drive, then add the files to the new iTunes library. Unless you are a super-organized individual, or you don't care if your libraries do not have the same content, you are better off using a single library file that is on the external, not setting up separate library files.

  • How to authenticate BPEL process to a PL with Client SSL Cerificate

    Hi,
    I need to invoke a partner link which requires authentication with Client SSL certificate. So, here is the use case:
    - The PL's endpoint is https://some.server.com/web_service;
    - I have a client SSL certificate supplied by the web service provider in the form of PKCS12 (PFX) file. I should use this certificate for authentication.
    I read carefully the BPEL Administration Guide, the part about SSL authentication (http://download.oracle.com/docs/cd/B31017_01/integrate.1013/b28982/security.htm#CHDHIBEG), but in this guide is described how outer services can be authenticated by the BPEL Process Manager with client SSL certificates, not the vice versa.
    So, I completed the following tasks:
    - I imported the server certificate of https://some.server.com/web_service into $ORACLE_HOME/jdk/jre/lib/security/cacerts file;
    - since I didn't find a way to import the client certificate as a PFX file, I converted it PEM file, using OpenSSL utilities and manage to import in cacerts client certificate's public key, but not the private key. Of course this didn't help me in any way to get authenticated.
    I would appreciate any help on this topic!
    Thank you!
    Simeon

    i get this action plan and works for me...
    1. Download the new Client Certificate.
    2. Convert the Client PFX to JKS as per:
    http://www.cb1inc.com/2007/04/30/converting-pfx-certificates-to-java-keystores
    3. Using firefox go to the WSDL site:
    * Add the exception, if Firefox ask for it.
    * Import the server certificate to Firefox following the instructions displayed
    4. Once you imported the certificate on Firefox, go to:
    * Tools -> Options
    * Select Advanced and click on "Encryption" tab
    * Click on View Certificates
    * Go to the Servers tab
    * Select the "servercfa" and click on "Export"
    * Save the certificate adding the .cer extention to the name.
    * Ensure that you select in Save as Type "X.509 Certificate with Chain (PEM)"
    5. Import using keytool the exported certificate from step 4 to the JKS obtained in step
    2:
    * i.e: keytool -import -alias servercert -file servercfa.crt -keystore client.jks -storepass welcome1
    6. Add both keyStore and trustStore properties to the jdev.conf pointing to the same JKS :
    AddVMOption -Djavax.net.ssl.keyStore=C:\jdevstudio10133\jdk\jre\lib\security\client.jks
    AddVMOption -Djavax.net.ssl.keyStorePassword=welcome1
    AddVMOption -Djavax.net.ssl.keyStoreType=JKS
    AddVMOption -Djavax.net.ssl.trustStoreType=JKS
    AddVMOption -Djavax.net.ssl.trustStore=C:\jdevstudio10133\jdk\jre\lib\security\client.jks
    AddVMOption -Djavax.net.ssl.trustStorePassword=welcome1
    7. Open Jdev and retest the issue.
    Tocarli.

  • How to setup new notebook from HP laptop with bad hard drive

    Got kids a new Hp laptop in June.  The hard drive has been getting progressively louder and is obviously about to go, with a blue screen error forcing a roll back of the computer.  I have done a full backup to an external hard drive and I am returning this for a replacement.  Should I make a recovery disc and reinstall from the disc when I get the new laptop, or should I just plug in the external hard drive and transfer the files over?  A guy at work says using the recovery disc is the way to go, because it would reinstall Norton and all the other programs we have installed., but I thought the external hard drive backup was supposed to be the way to do this
    This question was solved.
    View Solution.

    Not sure I understand the question. "Should I make a recovery disc and reinstall from the disc when I get the new laptop, or should I just plug in the external hard drive and transfer the files over?" Usually HP replaces only the hdd.
    If you are receiving a new hdd to put it the laptop, yes you need to burn the Recovery Disks to reinstall Windows & original software on it. You can then use your backup to restore files.
    IF the full backup you are referring to is a complete System Image, it can be used to restore Windows, programs and all files,etc on the new hdd. You do need to also burn the Repair CD to boot from and restore the System Image on the new hdd.(I would still burn a Recovery DVD set to have as a fallback)
    If you are receiving an entire laptop replacement it will have everything installed on it. You will just have to restore your personal files from the backup
    ******Clicking the Thumbs-Up button is a way to say -Thanks!.******
    **Click Accept as Solution on a Reply that solves your issue to help others**

Maybe you are looking for