cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
900
Views
0
Helpful
3
Replies

windows LDAP authen on ACS 4.1

I have windows 2003 AD and trying to setup ACS authentication with Generic Ldap.

I fill these fields in ACS 4.1 as below

User directory subtree cn=users,dc=mydomain,dc=local

Group directory subtree cn=users,dc=mydomain,dc=local

Userobjecttype uid

Userobjectclass Person

Groupobjecttype cn

Groupobjectclass GoupOfUniqueNames

Group attribute name UniqueMember

Admin dn cn=myname,cn=users,dc=mydomain,dc=local

A authentication failure show up with “external user not found” when I try to log on to a device.Please help to fill with the exact syntax for the above fields. All examples on the web are base on Novell LDAP

Thanks in advance

Vincent

3 Replies 3

smahbub
Level 6
Level 6

ACS forwards the username and password to an LDAP database by using a Transmission Control Protocol (TCP) connection on a port that you specify. The LDAP database passes or fails the authentication request from ACS. When receiving the response from the LDAP database, ACS instructs the requesting AAA client to grant or deny the user access, depending on the response from the LDAP server.

Refer the following url for more information on Generic LDAP AUthentiication on ACS 4.1:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/UsrDb.html#wp491718

My question is what is the default attribute name from windows directory server for UserObjectType and UserObjectClass

Thks

Userobjecttype: cn

Userobjectclass: user

Regards

Andy