VPN Login first with RSA and then AD?
I've run in to a situation I hadn't considered when we stood up our RSA 2-factor authentication for VPN. We use AnyConnect clients to hit our Cisco VPN concentrators which then passes off authentication responsibilities to ISE and ISE knows which Identity Store to use based on where the authentication request is coming from and what group(s) a person belongs to.
We now have a service provider that that will reach right in to a product they manage for us when we call and say there is a problem. However, the tech/engineer assigned to the issue could be one of many from their pool of available resources. The service provider only wants 1 token which will be "locked up" and the PIN "locked up" separately as well so when we report a problem they can connect and resolve it.
I won't issue a single token to them because they are associated with AD accounts but I could create a generic account local to RSA they could authenticate against if they could then auth with their AD creds before connecting.
So my question is has anyone done this? Is it possible to have AnyConnect ask for SecurID authentication and then come back with a prompt for AD authentication?
Thanks
Hi Darren,
should be no problem, using double authentication:
aaa-server myLDAP protocol ldap
aaa-server myRSA protocol sdi
tunnel-group foo general-attributes
authentication-server-group myRSA
secondary-authentication-server-group myLDAP [use-primary-username]
This will prompt for 2 usernames & 2 passwords, unless you add "use-primary-username" but I guess in your case you do need 2 different usernames.
hth
Herbert
Similar Messages
-
when i open up computer the login screen comes up and then goes dark right away. can't do anything with it. close lid and open up and it comes up again and then goes dark. i have to shut off and restart to get through the login page. then seems to work untill i close lid again. just started this today. software is up to date. using a month old mbp 15. any suggestions? thanks.
You could try wiping the hard drive and reinstalling the OS and all your programs.
Did you install any programs yesterday?
If not it may be best to take it to an Apple care center and have it checked out. Take it in while it is asleep so you ccan show then what is happening. -
ISE first authorization sucess and then fail (MAB)
Hi,
Using ISE 1.1.1 and Switch 3650 12.2(55)SE6.
I have a client (computer) that should be authenticated with MAB and then the switch port should be asigned a DACL and VLAN 90. I do get
"Authorization succeeded" but directly after it fails and I can't figure out why. ISE only shows the successful authentication under "Live Authenticaions".
As you can se from the log below 802.1x fails, as it should, and then MAB succeed, asigns the VLAN and then fails:
0002SWC002(config)#int fa0/13
0002SWC002(config-if)#shut
0002SWC002(config-if)#
Jan 7 13:26:59.640: %LINK-5-CHANGED: Interface FastEthernet0/13, changed state to administratively down
Jan 7 13:27:00.647: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/13, changed state to down
0002SWC002(config-if)#no shut
0002SWC002(config-if)#
Jan 7 13:27:19.689: %LINK-3-UPDOWN: Interface FastEthernet0/13, changed state to down
Jan 7 13:27:22.063: %LINK-3-UPDOWN: Interface FastEthernet0/13, changed state to up
Jan 7 13:27:22.776: %AUTHMGR-5-START: Starting 'dot1x' for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0A0005FC00000
020D7C192D1
Jan 7 13:27:23.070: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/13, changed state to up
Jan 7 13:27:51.054: %DOT1X-5-FAIL: Authentication failed for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID
Jan 7 13:27:51.054: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (f04d.a223.8f43) on Interface Fa
0/13 AuditSessionID 0A0005FC00000020D7C192D1
Jan 7 13:27:51.054: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0
A0005FC00000020D7C192D1
Jan 7 13:27:51.054: %AUTHMGR-5-START: Starting 'mab' for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0A0005FC0000002
0D7C192D1
Jan 7 13:27:51.088: %MAB-5-SUCCESS: Authentication successful for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0A0005
FC00000020D7C192D1
Jan 7 13:27:51.088: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0A0005FC00000020D7C192D1
Jan 7 13:27:51.088: %AUTHMGR-5-VLANASSIGN: VLAN 90 assigned to Interface Fa0/13 AuditSessionID 0A0005FC00000020D7C192D1
Jan 7 13:27:51.096: %EPM-6-POLICY_REQ: IP 0.0.0.0| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000020D7C192D1| AUTHTYPE DOT1X| EVENT APPLY
Jan 7 13:27:51.096: %EPM-6-IPEVENT: IP 0.0.0.0| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000020D7C192D1| AUTHTYPE DOT1X| EVENT
IP-WAIT
Jan 7 13:27:51.255: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0A00
05FC00000020D7C192D1
Jan 7 13:27:52.027: %EPM-6-IPEVENT: IP 10.90.5.1| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000020D7C192D1| AUTHTYPE DOT1X| EVENT IP-ASSIGNMENTReplacing duplicate ACE entry for host 10.90.5.1
Jan 7 13:27:52.036: %AUTHMGR-5-FAIL: Authorization failed for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0A0005FC00
000020D7C192D1
Jan 7 13:27:52.036: %EPM-6-POLICY_REQ: IP 10.90.5.1| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000020D7C192D1| AUTHTYPE DOT1X| EVENT REMOVE
After this the proces starts over again.
This is the switch port config:
interface FastEthernet0/13
description VoIP/Data
switchport mode access
switchport voice vlan 20
switchport port-security
switchport port-security violation restrict
ip access-group ACL-ALLOW in
srr-queue bandwidth share 1 70 25 5
srr-queue bandwidth shape 3 0 0 0
priority-queue out
authentication event fail action next-method
authentication event server dead action authorize voice
authentication host-mode multi-auth
authentication open
authentication order dot1x mab
authentication priority dot1x mab
authentication port-control auto
mab
snmp trap mac-notification change added
no snmp trap link-status
dot1x pae authenticator
dot1x timeout tx-period 10
storm-control broadcast level 2.00 1.00
storm-control multicast level 2.00 1.00
storm-control action shutdown
storm-control action trap
spanning-tree portfast
service-policy input ax-qos_butnet
ip dhcp snooping limit rate 5
end
Is there a problem with the client (computer) or in ISE/Switch?Hi Tarik,
First off; thank you for helping me troubleshoot this problem.
I think the "IP-" part of "IP-ACL-IWMAC" is beeing added automaticly (in the switch maby?). I see this behaviour on other dACL too. I did not change the name of the ACL.
You seem to have a valid theory about the icmp statement. I changed it to "permit icmp any any" and it seems to work. But I can't explain why this is happening.
When I look at the debugs I see this difference
With the original ACL I get this:
%EPM-6-POLICY_REQ: IP 0.0.0.0| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000053E70733F4| AUTHTYPE DOT1X| EVENT APPLYReplacing duplicate ACE entry for host 10.90.5.1
%EPM-6-IPEVENT: IP 10.90.5.1| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000053E70733F4| AUTHTYPE DOT1X| EVENT IP-RELEASE
%EPM-6-IPEVENT: IP 10.90.5.1| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000053E70733F4| AUTHTYPE DOT1X| EVENT IP-WAIT
%AUTHMGR-5-FAIL: Authorization failed for client (f04d.a223.8f43) on Interface Fa0/13 AuditSessionID 0A0005FC00000053E70733F4
When using "permit icmp any any" i get this:
%EPM-6-POLICY_REQ: IP 0.0.0.0| MAC f04d.a223.8f43| AuditSessionID 0A0005FC00000055E70B8E7D| AUTHTYPE DOT1X| EVENT APPLY
%EPM-6-AAA: POLICY xACSACLx-IP-ACL-IWMAC-50eea905| EVENT DOWNLOAD-REQUEST
I tried googeling but can't find what "Replacing duplicate ACE entry for host xxx" means.
I have added debugs in attachment.
device1_orig_acl - the none working device with original ACL
device1_any_any - the none working device with permit icmp any any
working_device_orig_acl - the device that works with the original ACL
Do you have an answer to why this is happening?
Regards,
Philip -
I just downloaded a song and it only plays the first 50 seconds and then moves to the next song in the list. How can I get it to play the rest of the song?
If your country's iTunes Store allows you to redownload purchased tracks, I'd delete your current copy of the track and try redownloading a fresh one. See the following document for instructions:
Downloading past purchases from the App Store, iBookstore, and iTunes Store
Otherwise, I'd report the problem to the iTunes Store.
Log in to the Store. Click on "Account" in your Quick Links. When you're in your Account information screen, go down to Purchase History and click "See all".
Find the item that is not playing properly. If you can't see "Report a Problem" next to the item, click the "Report a problem" button. Now click the "Report a Problem" link next to the item. -
My daughter used her friends apple account to login on her ipad and then the mother of her friend thought it was being hacked and consequently tracked the ipad and my daughter lost all her photos. Can we get these back?
Your iOS device backup only includes data and settings stored on your device. It doesn’t include data already stored in iCloud, for example contacts, calendars, bookmarks, mail messages, notes, shared photo albums, iCloud Photo Library beta, My Photo Stream, and documents you save in iCloud using iOS apps and Mac apps.
-
so i bought the 9.99 a month photoshop (with lightroom) and then installed CC when i went to the app tab both PS and LR said "try" instead of install is that how setup usually goes? or well it ask me later for serial numbers?
Oscarf16161909 for information on how to resolve the connection error preventing the active membership from authorizing please see Sign in, activation, or connection errors | CS5.5 and later. If you have any questions regarding the steps listed in the document you are welcome to update this discussion.
-
When I have headphones plugged into my iphone it says warning'' high volume'' and becomes first a red and then plop a number of red pops but it will not be so for someone else I know. My sound will be much lower than anyone else in the music, and when I talk by phone headset
Hi! I have the same problem when I use my headphones .
iPhone 4s England, iOS 6.1.2 -
I downloaded the 09 version without deleting the 08 (didn't know), and now I am having some problems : when I open a document, it opens with 09, and then when I try to re-open it with 08 it is not possible ! I have a message saying tha "the fichier index xml is absent" (my computer is in French. I want to work with pages 08 until I get familiar with the 09 version. What shall I do ? What does this happen?
Once you open the files in the new version you can't open them in the old version. Pick one version to use (have to be 9 now as you already have converted files)
-
hi guys, I was presented with iPhone and then I rewrote the program, but right now, the ability to such a problem ..... want username and password
I don't understand. What "program" do you mean, and what do you mean by "rewrote"? If you mean that the iPhone has Activation Lock - that is, you restored the iPhone and now it's asking for the previous owner's Apple ID and password to activate the device - then you will need that information, or you'll need to get the previous owner to remove the device from his/her iCloud account:
http://support.apple.com/kb/PH2702
If you can't reach the previous owner or he/she is unwilling to cooperate, then the device is unusable by you.
Regards. -
grandaughter has locked i pad 2 with passcode and then forgotten number how do you reset i pad to get it to work again
If You Are Locked Out Or Have Forgotten Your Passcode or Just Need to Restore Your Device
1. iTunes 10 for Mac- Update and restore software on iPod, iPhone, or iPad
2. iPhone, iPad, iPod touch: Wrong passcode results in red disabled screen
3. iOS- Understanding passcodes
If you have forgotten your Restrictions code, then follow the instructions
below but DO NOT restore any previous backup. If you do then you will
simply be restoring the old Restrictions code you have forgotten. This
same warning applies if you need to restore a clean system.
A Complete Guide to Restore or Recover Your iDevice (if You Forget Your Passcode)
If you need to restore your device or ff you cannot remember the passcode, then you will need to restore your device using the computer with which you last synced it. This allows you to reset your passcode and re-sync the data from the device (or restore from a backup). If you restore on a different computer that was never synced with the device, you will be able to unlock the device for use and remove the passcode, but your data will not be present. Refer to Updating and restoring iPhone, iPad and iPod touch software.
Try restoring the iOS device if backing up and erasing all content and settings doesn't resolve the issue. Using iTunes to restore iOS devices is part of standard isolation troubleshooting. Restoring your device will delete all data and content, including songs, videos, contacts, photos, and calendar information, and will restore all settings to their factory condition.
Before restoring your iOS device, Apple recommends that you either sync with iTunes to transfer any purchases you have made, or back up new data (data acquired after your last sync). If you have movie rentals on the device, see iTunes Store movie rental usage rights in the United States before restoring.
Follow these steps to restore your device:
1. Verify that you are using the latest version of iTunes before attempting to update.
2. Connect your device to your computer.
3. Select your iPhone, iPad, or iPod touch when it appears in iTunes under Devices.
4. Select the Summary tab.
5. Select the Restore option.
6. When prompted to back up your settings before restoring, select the Back Up
option (see in the image below). If you have just backed up the device, it is not
necessary to create another.
7. Select the Restore option when iTunes prompts you (as long as you've backed up,
you should not have to worry about restoring your iOS device).
8. When the restore process has completed, the device restarts and displays the Apple
logo while starting up:
After a restore, the iOS device displays the "Connect to iTunes" screen. For updating
to iOS 5 or later, follow the steps in the iOS Setup Assistant. For earlier versions of
iOS, keep your device connected until the "Connect to iTunes" screen goes away or
you see "iPhone is activated."
9. The final step is to restore your device from a previous backup. If you do not have a
backup to restore, then restore as New.
If you are restoring to fix a forgotten Restrictions Code or as a New device, then skip Step 9 and restore as New. -
my ipod wont connect to my itunes and an error message keeps popping up. how do i connect it to itunes, even after deleting everything to do with itunes and then reinstalling?
What does the error message say? Complete wording of the message is required
-
I downloaded some apps for my ipho in the apptrackr site, the apps are shown in my itunes library but when i try to sync those apps at first it works and then it says an error occured (0xE8008001). How can I sync them without the error?
If your phone is jailbroken, we can't help you, as already stated.
If you're new to this and you're trying to download apps to put on your phone and it is NOT jailbroken, you can't do that.
You must go through the iTunes app store. -
How to I sync my 10.6.8 ical with icloud and then to my ipad
How to I sync my 10.6.8 ical with icloud and then to my ipad
I find that I can sync fine with Entourage and I cal under Leopard. I can also subscribe to the Leopard I-calendar on another computer (running Tiger). However, the calendar will not go onto a web page as it used to; this is very frustrating for my colleagues! We need a fix here I think.
-
First time editing a project with HD, and then burning it to Blu-ray
Hey there everyone.
*Newbie to HD editing alert.
I have two problems regarding HD editing/export.
I've been scouring the forums for several days, and I can't find a specific answer to what I need/want to know. Some things are understandable to a degree, and then there are things that seem way over my head.
(One thing, I've read about third-party programs like Cineform, and such, and was told that those programs aren't really necessary. So, if there's some way to stay away from them, I'd like your suggestions on that. However, if in the end, that's the way I need to go for this to work, then I guess I will have to go that route).
This is my first attempt at capturing and editing in HDV, so please excuse my ignorance if I refer to something in the wrong context.
My main goal:
To edit an HD wedding, shot with Sony FX-1 HD camera, and burn it to a Blu-ray disk.
Here is the computer system that I'm working with:
Dell Precision M6300; Intel Core 2 Duo T7700; 2.40 GHz 800Mhz; 4MB L2 Cache; Dual Core
Operating System: Windows XP PRO SP3;
- 4.0GB, DDR2-667 SDRAM, 2 DIMM Dell Precision M4300
- NVIDIA QUADRO FX1600M 512MB TurboCache (256 dedicated) Dell Precision M6300
- Hard Drive: 200GB Free Fall Sensor Hard Drive 9.5MM, 7200RPM, Dell Mobile Precision MX300 Factory Install
- 8X DVD+/-RW, Data Only, Dell Precision M6300
- NTFS file system
I have been editing with Premiere Pro CS3 for the past year now.
I used a Sony FX-1 when capturing my footage.
I believe that I captured all the footage in HDV ok. (I made a new project and used the Load Preset of "HDV 1080i30(60i)"; and then captured all the footage thru CS3)
My clip properties (when highlighted in the Project Panel) say that the clip is: an mpeg; and 1440x1080 (1.333).
1. My first problem: I captured 4 clips (Clips 1-3 are 1 hour each; and Clip 4 is 16 mins long). When I place Clip 1 into the timeline . . . the only way I can describe how the audio plays in this clip is . . . the audio looks like it's looping the same 5 to 6 minutes of audio throughout the whole 1 hour clip. (ie: the video is one, long, flowing 1 hour of continuous video; but the audio connected to this same clip, seems to be playing the first 5 mins of the clip, and then repeats it at the 6th minute). You can 'visually' see this problem when you view the audio waveform in the timeline.
The other three clips have no problem with audio at all.
2. My second question is a bit more lengthy:
I wanted to run a test of burning a Blu-Ray of this project's raw footage, to see how the workflow would go after I've edited the wedding.
When I go to Export my timeline to Encore, on the Encoding Settings area, it seems to only let me use the Preset of NTSC Widescreen, with a 720x480 video. I don't see anywhere where it mentions that this project will be HD (which I thought would keep my 1440x1080 dimensions on export).
The Format and Range areas are greyed out; and I can only choose a few things off the Preset dropdown.
Am I missing a step? Or is this what will be exported, but once in Encore, it will be able to burn correctly on Blu-ray?
Again, please excuse my naivety in understanding and/or mis-speaking my problem.
Also on the Export Settings window, on the Output tab - should I check off 'Deinterlace' also? I've read and read about Interlace and Deinterlace, and I am confused as to "what to use when".
So my specific questions are:
1. Regarding the 'repetetive audio loop' on one of my clips - what could the problem be there?
Will it export OK? Or should I just recapture that one clip again?
2A. Do I Export to Encore directly, when I'm done with my timeline and want to go to burn the Blu-ray disk? Or do I need to make my timeline into 'one fluid file'?
2B. If I'm supposed to make a file of the timeline:
Am I supposed to be Exporting to Movie instead?
(When I tried that, my settings under 'Video' showed up as a greyed out area for Frame Size, locked at 720x480 wiContinuation:
2B. If I'm supposed to make a file of the timeline:
Am I supposed to be Exporting to Movie instead?
(When I tried that, my settings under 'Video' showed up as a greyed out area for Frame Size, locked at 720x480 with a ratio at 4.3. I changed the Pixel Aspect Ratio to "D1/DV NTSC Widescreen 16:9 (1.2)" and the ratio that shows beside the greyed out Frame Rate area does change to 16:9. But the size is still locked at 720x480.
Shouldn't I be seeing 1440x1080 SOMEwhere along the export line? Or at least some sort of ratio that would pertain to HD?
2C. Am I supposed to be Exporting to Adobe Media Encoder?
And if so, should I be choosing:
H.264;
HDTV 1080p 29.97 High Quality;
Output tab having 'Deinterlace' checked;
using VBR, 2 Pass;
leaving Target Bitrate default of 32;
and Maximum Bitrate default of 40?;
and should I be setting the 'Key Frame Distance' at 30 also?
2D. When exporting, should I always Deinterlace footage?
(I've read so much about Deinterlace and Interlace that I'm lost about the 'when to use either' aspect)
3. If I absolutely have to use a third-party program like Cineform, at what point do you use that program? Is this used at the time that you capture the footage, and then import those files into PPCS3? Or is this a program that you use to Export your project when you're done with your editing?
(I read all the information that Dan Isaacs posted about the "Premiere Pro HDV workflow Guide", but that was entirely too confusing to me right now, as a newbie to HDV, etc. I was going to attempt that way, but I ended up doing this post first).
In my meandering throughout the CS3 forum regarding SD, HD, HDV, etc etc, I have picked up alot of information regarding certain problems and situations. I may have all the info in my head, and I'm just applying it wrong; or, I'm missing something in the mix? I'm not sure what it is, but I seem to be having quite a problem doing what seems to be something that should be 'easy'.
I find this forum extremely helpful and understanding, so I'm looking to you all for help. I would appreciate any and all comments and suggestions!
Thanks so much! -
I have unlocked iphone and got walmart family mobile. I was issued a phone number initially then asked for a different one. Now when I send text messages, they show up the original number, but when I make phone calls, the id shows up the new number, I can recieve text messages to both numbers. If you try to call the first number it says it is not a working number. On my phone, if I go under "about" it says "my phone number" and it says the second number, under settings, and messaging, it says that I send and recieve messages from the original one. T-mobile, has no idea why this is happening and has tried everything to fix it
This is for iMessages only, not for text messages as in SMS/MMS.
Settings > Messages > Send & Receive > Apple ID.
Select your Apple ID and at the menu window that appears, select Sign Out.
Turn iMessage off at Settings > Messages > iMessage.
Then follow these instructions.
You can remove an iPhone from your support profile by following these steps.
Step 1: Click on this link to open the login window of your support profile.
Step 2: Log into the website using your Apple ID – same as your iTunes login.
Step 3: Click on the button ‘Edit products’ and select the iPhone that you want to remove from the list.
Step 4: Click on the arrow behind the product, and then click on the button ‘Unregister’ to delete the iPhone from your support profile.
After you unregister your iPhone, on your iPhone go to Settings > Messages > iMessage and turn iMessage on.
Go to Settings < Messages > Send & Receive > Apple ID. Sign back in with your Apple ID.
This should re-register your iPhone with your Apple ID with iMessage with the new phone number only.
Maybe you are looking for
-
Communication between Best Buy and Apple
Where is the communication between these two companies? It's frustrating to have NO CLUE if a phone will come in a day or in 5 weeks. Who at Apple is deciding what they end to what stores? Obviously, Best Buy has to pay for the phones. There has to b
-
Uploading photos from browser to an existing Web Gallery
Hi: This question is related with this thread: http://discussions.apple.com/thread.jspa?threadID=1077164&tstart=15 but I fell that not receiving the right answer because the topic doesn't describe the problem fine. I uploaded a web gallery from iPhot
-
Hi all, I exported an interface from development instance and imported in test instance without any error. I opened up the interface and flow tab is greyed out and I can't set IKM selections. My question is why flow tab is greyed out and how to fix i
-
Printing of Excise and other CIN related conditions in PO
Hi, In Tax procedure (TAXINN), i have marked the print indicator for Excise related conditions assuming that these conditions should be printed in the PO output. But it is not happening. Please guide me. Regards, Sattuj
-
Best way to push change data from sql server to windows/web application
i apologized that i do not know should i ask this question in this forum or not. i have win apps which will load all data initially from db and display through grid but from the next time when any data will change in db or any data will be inserted n