NAC 4.5 not performing ADSSO

Unanswered Question
Nov 24th, 2009
User Badges:

Hi,


     I am running a NAC 4.5 platform on a network with 2 AD servers.  I have followed all the needed configuration and troubleshooting based on cisco documents, but ADSSO still doesn't work.  What am I possibly missing?  Time is synchronized running on a ntp server, have a valid ktpass, correct kerberos ticket shows on the kerbtray.  Still when my test pc logs on to the network, it is not performing SSO but asks for a local user account through the CCA.  Please help.  Thanks


Regards,


Dan

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Faisal Sehbai Thu, 11/26/2009 - 12:13
User Badges:
  • Gold, 750 points or more

Dan,


Please post your unauthenticated traffic policies.


Faisal

manfernandez Sun, 11/29/2009 - 09:08
User Badges:

Make sure that it is not Windows Server 2008 64Bit (not supported)  also Windows Server 2008 32 or 64 bit require a patch.


If you login into the CAS with the /admin and turn the logging up to 'Trace' on 'Active Directory Communication Logging".  Look for an error:


/* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:"Times New Roman"; mso-fareast-theme-font:minor-fareast; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;}

Unable to start server ... Client not found in Kerberos database (6)


This means you need to install Hotfix KB951191


Also: if you run the ktpass on the same user multiple times, you will have issues as well (per TAC) you will need to create a new user and use that one.

Actions

This Discussion