ISE with per-windows 2000 domain

Hi
I am experiencing a problem with AD authentication.
I have joined the ISE appliance to the windows AD and I can browse the groups and attributes.
But the problem I am experincing is that the users logon to the domain using the pre-windows 2000 domain name.
FQDN format : ab.cdef.com       - ISE is joined to this
pre-windows 2000 name : abcd  - Users logon with this
So wen the users authenticate I get the following error : 22056 Subject not found in the applicable identity store.
Also tried to logon with [email protected] with no luck.
Does someone have any suggestions?
Thanks

The 802.11 Mac Layer is a bit longer than the ethernet mac layer. This sometimes cause problem with domain login because they are done using UDP by default. The frame are sometime drop. To test if this is your problem, I recomand changing the MTU on the 2000server(DC) and the host to something lesser than the actuel MTU on the interface. (configure the DC and host @1300 leaving the network @1500)
A Windows 2003 server as a default mtu of 13?? something to get around this problem. I usaully tell my users to install the cisco vpn client if they want to use domain in wireless because the installation of this client lower the MTU of every interface to 1300.
Another path you can look into is forcing kerberos to use TCP insted of UDP. (look on MS TechNet for method)

Similar Messages

  • Adding mac in Windows 2000 domain

    Hello, I need add a mac OS 10.3.9 in a windows 2000 domain,
    for sharing files and printers. Is possible??
    Thanks, Diego

    Hi dbeihswingert try these documents
    http://www.wazmac.com/wazza/networking/networkpages/basic_sharing/networkintegration.html
    especially
    Macs to a Win Domain (pdf - 250k)
    Configure OSX 10.3.3 so Macs can authenticate with Active Directory, and store their home folders on a Windows 2000/3 server.
    I have found this to be a good resource.
    Cheers.

  • Joining a Windows 2000 domain

    Can I join my Sun Solaris 8 server running Samba to a Windows 2000 domain so that all the users that logon or use shares will authenticate thru the domain controllers with their Win accounts?
    I dont want to create 1500 Solaris accounts.

    there is a sun product called Sun PC Net Link that could help you
    synchronazing user accounts in Windows env. and Solaris
    you can map the accounts from one env. to the other.
    we use this product since many years and have migrate fm
    windows NT to Windows 2000 Terminal Server without major
    problems, including user maps.
    good luck ...
    [email protected]

  • Different Pre-Windows 2000 domain and FQDC.

    I have a SBS 2003 box that was originally migrated from SBS2000. i just finished install new 2012 standard server and installed AD service on it, but when i trying promote to DC, it won't do it until functional level raise to least 2003 level.
    My question is following:
    when user login, user uses pre-windows 2000 login name.  
    For example, DC11\user but FQDC is DC1.local.  we have no DC11 exist. 
    When user trying login as DC1\user, it won't able to login. even Administrator has to login as DC11\administrator not DC1\administrator. 
     When i look user properties account login name user @dc1.local and pre-Windows 2000 name DC11\ user are listed. 
    if i raised to Windows 2003 function level, did user can't login? or any effect? 
    Thanks

    DC11 is the NetBIOS name of your domain and it can be changed using Active Directory Domain rename tools -
    http://technet.microsoft.com/en-us/windowsserver/bb405948.aspx - if you don't want to use DC11 in your environment. However, this could have impact other applications like Exchange,
    as Exchange doesn't support domain rename.
    Another option for you would be to deploy a new Forest or domain with the names that you desire and migrate stuff - Users/Workstations/Servers/Application and get rid of old domain.
    UPNs ([email protected]) is easy to change but changing NetBIOS is a complex process and needs to be done with extreme care.
    - Sarvesh Goel - Enterprise Messaging Administrator

  • New Ipod nano not working with my Windows 2000

    I have just bought an ipod nano 8GB, and tried to install it. The latest itunes I can put on my computer is 7.3.2 as it is a Windows 2000 not an XP. Unfortunately the nano is saying it needs 7.4 and above. can anyone help please?

    I wish you would have asked or checked on the tech specifications for the Nano prior to purchase. These are the required tech specs, copied directly from the Nano page. I'm sorry there's nothing you can do.
    # PC with USB 2.0 port
    # Windows Vista or Windows XP Home or Professional with Service Pack 2 or later
    # iTunes 7.6 or later

  • How to download and use iTunes 7.4 with only Windows 2000

    I have a brand-new iPod Nano (1st generation) with 4 GB capacity, given to me in 2007. I am just getting around to trying to install and use it, but when I try to download the iTunes 7.4 software, I get a message that I need at least Windows XP or Vista to install and use the software with the iPod Nano. I only have Windows 2000 on my computer, which is company owned (so I am not allowed to update my Windows software). Anyone have a solution so that I can get some level of iTunes software in order to use the iPod Nano?? PS I tried to download iTunes 6 software, but I got a message that my iPod nano needed a more recent version of the iTunes software. Same thing happened when I tried to download the iTunes 8 version of the software.

    download and install http://www.mediamonkey.com/ its free
    I just bought a 4th gen nano today, and running windows 2000.
    This was my first ever Apple product, and i was pretty angry when i ran into the same problem as you. with some frustrating research I found MediaMonkey and listening to my new iPod as i type this

  • Weblogic Server 6.1 with MS Windows 2000 Cluster

    Hello everybody,
    following situation:
    We want to implement a Microsoft Cluster (Failover) with MS Cluster Service and
    2 nodes (maybe later we try the Weblogic Software clustering with load balancing
    as a part of an documentum and infotehna DMS). On both nodes we made the same
    test installation of the Weblogic Server 6.1 and started it with services (instead
    of cmd-file).
    It's working fine seperate on every node, than we started to implement the MSCS
    on these machines and only one node is working. On the other node (after a failover
    to this node) the service started but break down only a few seconds later.
    Now, my question is: Can we use the Weblogic Server 6.1 in an Windows 2000 Advanced
    Server Failover Cluster with 2 nodes? Or do we need a special Add-on to do this???
    Best regards,
    Ronny

    Ronny,
    I'm don't know the specifics of MS Cluster Service but given that it works like
    other common HA frameworks (assumption on my part) you may need to use the MS
    cluster framework in isolation from the 'software-based' clustering approach that
    WLS 6.x currently provides. For example, in other HA Frameworks there is typically
    a heartbeat mechanism that informs the framework that a node is dead and the framework
    in turn calls scripts that migrate the failed node 'applications' over to the
    healthy node. In WLS, you could mimic the same approach where a single admin
    server fails over to a backup server not using the WLS 'software' admin/mgd server
    cluster value-add. In others words, you would need to script a heartbeat mechanism
    for the single WLS server and also script failover to a backup node when the heartbeat
    indicates 'failure'. This technique would be used in isolation (not using the
    current WLS software-based cluster configuration).
    My 2 cents,
    Chuck Nelson
    DRE
    BEA Technical Support

  • JAAS - Kerberos - windows 2000 domain - groups

    I need to find out if a user is in 2 different groups. If they are in group a, I display results a.m. If they are in group b, I display results b.n. If they are in a and b, then I display a.m union b.n. Any ideas?
    I am validating the user through kerberos already. Windows NT domain says they are valid if correct username/domain/password are enterted. Now I need to find out if they are part of a group on a domain. Any ideas? Am I making sense. Mail me at perry2of5 at yahoo.com if you need clarification or have ideas and don't want to post here.
    I suspect i need to use the subject from the original login and ask for access to the group, but I don't know how to do this. Help!

    I've a very simular problem (maybe even simpler).
    My webapp (Struts) is running on a Tomcat and the user login has to be proofen against a Win2000 active directory server. If login is successfull I'll need the users roles from the W2k ADS. That's it.
    What I know till know:
    - authentication uses Kerberos
    - communication with ADS uses LDAP
    Has anybody an easy solution (example). I've already read all the JAAS stuff from Sun, but I'm still not sure how to implement it.
    Thx, Chrise

  • WRT54G2 connection issues with a windows 2000 laptop, HELP!!! please?

    Ok, at my house I have a newer version of a wireless router (I can't remember which). The old windows 2000 laptop that I have connects perfectly there, but when I installed a WRT54G2 router at my grandma's house it wouldn't connect to the router. My vista laptop and my grandma's vista desktop both are connecting to the router fine (as is evident in my typing this right now), but not the windows 2000.
    It is registering that the signal exists, however, it says that it is out of range and it can't connect every time I try. Which makes no sense at all because the laptop in question is sitting no more than 4 ft away from the router.....
    It's driving me insane! Does anyone have any suggestions on fixing this problem? Plus I'm not even sure if it's an issue with the computer or if it's an issue with the router itself......
    Any ideas would be GREATLY appreciated!
    Thanks,
    illueia
    P.S. sorry if I was too rambley...... or I wasn't clear enough....

    Download and install the latest driver for your wireless card...
    I aaume the security on the WRT54G2 wireless router must be WPA/WPA2 and that's the reason your Laptop(win2000) does not connect to it...
    What error do you get when you attempt to connect to the Wireless Network ?
    If it connects to your wireless network then what IP Address do you get for your Wireless Connection ?

  • 10.4 and Windows 2003 Domain

    Hello,
    We're a 40% Mac environment where all the Macs are bound to our domain and users log in with Mobile accounts. When we first decided to do this, all the Macs played very nicely with our Windows 2000 domain.
    About three months ago, we upgraded our Windows 2000 domain to a Windows 2003 domain and began enforcing stronger password security. Now all of the Mobile accounts on all of our 10.4 machines refuse to let the users change their passwords. Doing so through the Log In window when a password expires does not work. Neither do the controls in System Preferences/Accounts. Neither do the controls in the Kerberos app. It sits and pinwheels for a few minutes, then returns an error about not being able to change the user's password to the password specified.
    I tried adding myself to a few of these computers as a Mobile user and then changing my password, but that didn't work either. So it isn't something held over in the user accounts from the old domain, and it isn't a permissions thing since I'm an administrator on the domain.
    I've dumped all the Directory Access preferences files. Doesn't help.
    Sometimes this behavior can be fixed by unbinding a machine from the domain, deleting the computer's account in Active Directory, then rebinding it to the domain. Lately, that fix has stopped working, and if I remove a machine from the domain, I cannot rebind it to the domain unless I do so using a different computer name - even though the computer account in Active Directory has been deleted.
    Mobile accounts on all of our 10.5 machines can change their passwords without a problem.
    I'm stumped. Anybody got any brilliant ideas? Information on Macs interacting with Windows domains is pretty scarce.

    Hi Scott, and a warm welcome to the forums!
    What Workgroup do you have set on the Mac in Directory Access Utility?
    See if these 2 links help also...
    http://www.macosxhints.com/article.php?story=20050302023720578
    http://allinthehead.com/retro/218/accessing-a-windows-2003-share-from-os-x

  • Windows 2000 user account migrate to new Windows 2012 R2 domain

    Hi all
    I have a customer using Windows 2000 domain with many user accounts and file share service.
    Now they want to use a new Windows 2012 domain without upgrade from old 2000 domain due to some hidden problem.
    Customer requested to keep user name, password, uid for existing file share access.
    May I know any tools for migrate user account from Windows 2000 domain to Windows 2012 domain?
    thx
    Q K

    Hi,
    Can you please confirm your requirement, that is you will be using a new Windows 2012 domain with only the user accounts from Windows 2000 domain. 
    If the above text matches your requirement, I would suggest you the following steps,
    1. You can use CSVDE - command line tool to export the AD user information as CSV file from  Windows 2000 domain,
    http://www.techrepublic.com/blog/data-center/simplify-admin-tasks-by-exporting-active-directory-data-with-csvde/
    2. Then, you can import the CSV file with required user attributes (domain details modified according to the target domain) to Windows 2012 domain using PowerShell as
    shown in the link given below,
    http://blogs.technet.com/b/bettertogether/archive/2011/01/09/import-bulk-users-to-active-directory.aspx
    Regards,
    Gopi
    www.jijitechnologies.com

  • PDF conversion with windows 2000 not working

    Hello all, I have a BSP application that is up and running.  When I print with an XP machine, I have no problems.  When I print with a windows 2000 machine, I am looping and never getting to the PDF open screen.  It just keeps looping but if I try from a XP machine, everything works.
    Any help would be appreciated.  i have included some of the code.
    * Conversion of output format OTF into PDF format
    * now convert the final document (OTF format) into PDF format
      call function 'CONVERT_OTF'
           exporting
             format                      = 'PDF'
    *         MAX_LINEWIDTH               = 132
    *        ARCHIVE_INDEX               = ' '
    *        COPYNUMBER                  = 0
           importing
             bin_filesize                = l_pdf_len
             bin_file                    = l_pdf_xstring       " binary file
           tables
             otf                         = ls_output_data-otfdata
             lines                       = lt_lines
           exceptions
             err_max_linewidth           = 1
             err_format                  = 2
             err_conv_not_possible       = 3
             err_bad_otf                 = 4
             others                      = 5
      if sy-subrc <> 0.
    *   error handling
    *    message id sy-msgid type sy-msgty number sy-msgno
    *            with sy-msgv1 sy-msgv2 sy-msgv3 sy-msgv4.
      endif.
    * Fill HTTP request
      response->set_header_field( name  = 'content-type'
                                  value = 'application/pdf' ).
    * response->delete_header_field( name = 'pragma' ).
    * response->delete_header_field( name = 'expires' ).
    * response->delete_header_field( name = 'cache-control' ).
    * some Browsers have caching problems when loading PDF format
    response->set_header_field(
                        name  = 'cache-control'
                        value = 'max-age=0' ).
    * start PDF viewer either in the Browser or as a separate window
      if pdf_in_browser is initial.
         response->set_header_field(
                            name  = 'content-disposition'
                            value = 'attachment; filename=BenConf.pdf' ).
      endif.
    * finally display PDF format in Browser
      l_pdf_len = xstrlen( l_pdf_xstring ).
      response->set_data( data   = l_pdf_xstring
                          length = l_pdf_len ).
      navigation->response_complete( ).

    You must remove all the no-cache headers and definitely disable GZIP compression for PDF files.
    Look at <a href="https://wiki.sdn.sap.com/wiki/display/BSP">BSP Wiki</a>:
    Handling Binary Data
    PDF

  • Page truncated when printing a transparent color with Windows 2000

    Hi,
    We use the JDK 1.5.0_11 in a Windows 2000 SP4 platform with 2GB of RAM.
    When printing a transparent color on a large page with a Windows 2000 platform,
    - The printed page is unexpectedly truncated (the bottom of the page is not printed) or
    - Even worse, the operating system crashes with a blue screen.
    Notice that we neither have any exception thrown nor any log written !
    Notice that this problem never occurs with a Windows XP platform !
    The problem can be reproduced as follows:
    1. Run the sample below,
    2. The "Page Setup" dialog is opened,
    3. Select a large paper size such as A2 or A1,
    4. Press the "Ok" button,
    5. The "Print" dialog is opened,
    6. Select a printer which can handle this paper size,
    7. Press the "Ok" button,
    8. The printed page is unexpectedly either truncated or the operating system crashes.
    If you do not have a printer handling such large paper sizes,
    the problem can still be reproduced using the latest version of "PDFCreator".
    Could anybody provide us with some hints ?
    Thank you very much for your help ...
    Xavier
    import java.awt.Color;
    import java.awt.Font;
    import java.awt.Graphics;
    import java.awt.Graphics2D;
    import java.awt.geom.Rectangle2D;
    import java.awt.print.PageFormat;
    import java.awt.print.Paper;
    import java.awt.print.Printable;
    import java.awt.print.PrinterException;
    import java.awt.print.PrinterJob;
    public class Main {
        public static void main(String[] args) throws Exception {
            PrinterJob job = PrinterJob.getPrinterJob();
            job.pageDialog(job.defaultPage());
            job.setPrintable(new MyPrintable());
            if (job.printDialog()) {
                try {
                    job.print();
                } catch (PrinterException exception) {
                    System.out.println(exception);
    class MyPrintable implements Printable {
        public int print(Graphics g, PageFormat format, int pageIndex) {
            if (pageIndex != 0) {
                return NO_SUCH_PAGE;
            Graphics2D g2 = (Graphics2D) g;
            g2.setFont(new Font("Serif", Font.PLAIN, 36));
            g2.setPaint(new Color(255, 0, 0, 127));
            for (long i= 0; i<format.getImageableWidth(); i++) {
                g2.drawString("www.java2s.com", (long) format.getImageableX() + i*18, (long) format.getImageableY() + i*18);
            Rectangle2D outline = new Rectangle2D.Double(
                    format.getImageableX(),
                    format.getImageableY(),
                    format.getImageableWidth(),
                    format.getImageableHeight());
            g2.draw(outline);
            return PAGE_EXISTS;
    }

    I did this with the Windows de-installer and it did not work. Is there something more I need to do? Does Mozilla have a program for removing its software that is more complete?

  • Trouble installing iDS 5.1 on Windows 2000

    I'm having real trouble getting iPlanet Directory Server installed on a Windows 200 Server machine. Every time I install it, no matter what options I choose, I get this series of popup boxes at the end:
    - Setup is unable to store configuration data in the LDAP directory
    - Unable to create Administration Server configuration
    - Could not authenticate ldap connection, "Unknown error"
    - Unable to set ACI in Configuration Directory Server
    I've spent quite a bit of time looking on this Forum, and the only suggestion I've found that I can't implement is to remove all the iPlanet-related entries from the registry. Every time I try to delete the associated keys, it gives me an error.
    I think the DNS settings are correct... I have a static IP address, I have a DNS server specified... The options "Append primary and connection specific DNS suffixes" and "Append parent suffixes of the primary DNS suffix" are selected, and also "Register this connection's address in DNS". I don't have a WINS server defined, but I wouldn't think that would make a difference.
    Any suggestions?
    Thanks,
    Jeff

    Hi Jeff,
    I've experienced the same problem with my Windows 2000 box. All the normal spots were configured for correct DNS and everything functioned great on the box, but the Admin Server couldn't be started. Here's
    what you'll need to do, to set the Hostname on the
    Windows 2000 box.
    It's in a seperate area then you would setup the TCP/IP properties, which is probably why it is commonly missed.
    1. Right Click on "My Computer" and select "Properties"
    2. Click on "Network Identification" Tab
    3. Click on "Properties" button
    4. Verify that the correct Computer Name is listed.
    I have "happysoul".
    5. click on Properties
    6. This is where the Domain Name suffix is specified.
    I have "sfbay.sun.com", which wasn't there by default.
    This is for my box "happysoul.sfbay.sun.com". Once setting this, it may ask you to reboot and from there
    you can install the iDS server and the Admin Server will install correctly.

  • OS authentication w/ 10.2 database and Windows 2000

    Not a new issue - but still not too easy for me...
    Got a Windows 2000 domain, a 10g enterprise database server on Windows 2003 as part of this domain and a client machine running a 10.2 client on Windows 2000 in the same domain.
    remote_os_authent is FALSE.
    OS_AUTH_PREFIX_DOMAIN is not set.
    On both sides sqlnet.ora contains the line SQLNET.AUTHENTICATION_SERVICES= (NTS)
    A database account exists as <domainname>\<username> with create session priviledge granted. <domainname> is the same as Windows' %USERDOMAIN%. <username> is the ID to which one logs into that domain on the client machine.
    But still "sqlplus /" raises exception 01017. Password authenticated connects do work. What am I missing?
    Thanks a lot..

    Assuming it still doesn't work: sorry no, as I recall this info from a Metalink note, and the Metalink note worked for me. The only thing I can remember right now is one needs to enclose the Oracle account in double quotes, or it wouldn't work, due to the \. If that also doesn't help, I'm stuck.
    Sybrand Bakker
    Senior Oracle DBA

Maybe you are looking for

  • Firewall service not permitting as it should

    The firewall services in OS X Server 10.5.1 are not permitting traffic as expected. Any ideas here to help me understand why would be appreciated. IP address block 11.22.33.0/26 has been changed from the original but should have no effect on the exam

  • Query regarding sys_context function

    Hello I have created report with custom folder and parameters are passed using sys_context function. I have few queries regarding this. 1) How to see actual sql query executed by report. I can see from discover administorator - sql inspector. But it

  • What is the best practice concerning View Objects and List of values

    Hi, Let's take these two tables : Market_Descriptions Id Name Desc Language_Id Languages Id Code Desc Now, if I am generating these business components with the help of the wizard, I will be having two entities and two views. If I am creating a list

  • How to verify "security authentication failure rate" command

    i type "security authentication failure rate 2 log" in global configuration mode,then  login authentication failed many times but no the 15-second delay. why?Thanks.

  • Companion CD Installation

    I installed Oracle RAC 10g database (10.2.0.1) and upgraded the patch 10.2.0.4....Can we Installed the companion CD after installing the Patch 10.2.0.4.... When we are trying to install my application component it is asking some schemas which will co