cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
476
Views
5
Helpful
3
Replies

ACS 3.3 Group Mapping Error with External Microsoft Server

acharyr123
Level 3
Level 3

Hi,

I have ACS 3.3 installed on Windows 2003 server with latest service packs. Users who wish to login to network devices has to be authenticated via windows credentials. So i have integrated ACS with Microsoft.

I need to create another group, but its not happening. Giving error interms of windows.

Can someone please suggest?

I have created 1 group.

3 Replies 3

Jagdeep Gambhir
Level 10
Level 10

Hi,

What is the error message ? Is it failed to enumerate group ?

If that is the case then it seems that account running acs service do not have spl priv like

act as a part of OS and login as service.

Regards,

~JG

Please rate helpful posts

Hi Gambhir,

Thanks for ur reply.

I have created 1 group successfully. It is working fine.

But whnever i try to create a new group then only i find this eror mesage "Windows Enumarate Group Failed".

Is it related to special privilege level isue???

Hi,

"Failed to enumerate windows groups"

Please check for the following:

If each domain's FQDN is listed as a DNS suffix in the IP properties of the server on which ACS is installed and you will also need to make sure that the ACS services have read permissions on the domain to be queried

You check this by going into the properties dialog for the NIC and clicking the Properties

button for TCP/IP, then the Advanced button, and then the DNS tab. Make sure the radio

button is in "Append these DNS suffixes (in order)" and make sure that the FQDN of the

domain in question is listed in the box.

Regards,

~JG

Please rate helpful posts

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: