ACS 5.1, ASA 8.2.2, AD, Device Access. Can't get it to work...

Unanswered Question
Jun 28th, 2010

Does anyone have any direction/pointers on how to configure ACS 5.1 to use AD to authenticate and authorize device admin access for Cisco ASA firewalls running 8.2.2? The only way I can seem to get it to work is to tell it to continue if authentication is failed (which means any user/password entered works). The events in the log are:


24408 User authentication against Active Directory failed since user has entered the wrong password


However, I know with 100% certainty that the username and password are good to go (it's the same username and password that works just fine with our old ACS 3.3 system). At this point I feel like I'm missing something really stupid, but for the life of me I can't find it (and the ACS 5.1 user guide leaves a LOT to be desired IMO). Any help is greatly appreciated. We are trying to pilot ACS 5.1 to see if we want to upgrade to it instead of ACS 4.2 but with it failing on what would seem to be such a basic use case, it's not looking promising... TIA.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
mgraham50 Thu, 10/20/2011 - 05:47

Hello,


Did you ever get this resolved?

We are having the exact same problem and cannot remedy it.

Thanks!

prospero Fri, 10/21/2011 - 08:10

Unfortunately we did not. Given other issues with the POC we actually killed the project. It's too bad Cisco doesn't have folks that actively watch and participate in these forums...

Steve McDermott Tue, 04/23/2013 - 09:05

I had this same issue and found out that my RADIUS keys did not match.  I am migrating from ACS 4.2 to ACS version 5.4.  I corrected my key on the the 5.4 installation and now access works perfectly.  Hope that helps.

Actions

This Discussion

Related Content