11-16-2009 12:07 AM - edited 03-10-2019 04:48 PM
Hi there
is it possible to have multiple windows databases on an ACS SE? The problem is, that we need access to two differen domains, that are not trusted and have no super domain.
Thanks a lot and best regards
Dominic
Solved! Go to Solution.
11-16-2009 08:49 AM
Hi,
We would require two way external/transitive trust between the two domains.
There are 2 ways to work around our problem:
1. Install another ACS at the remote site/domain and forward all the
requests for the users of remote domain to that ACS.
2. Configure partner domain as LDAP on the ACS (at corp site), this should not require domain trust. The only problem we will have certain authentication methods will not be supported when using ldap.
Here is the complete list of stuff which is supported with LDAP:
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_serverâ_for_windows/4.1/user/Overvw.html#wp824733â
Hope that helps!
Regards,
~JG
Do rate helpful posts
11-16-2009 08:49 AM
Hi,
We would require two way external/transitive trust between the two domains.
There are 2 ways to work around our problem:
1. Install another ACS at the remote site/domain and forward all the
requests for the users of remote domain to that ACS.
2. Configure partner domain as LDAP on the ACS (at corp site), this should not require domain trust. The only problem we will have certain authentication methods will not be supported when using ldap.
Here is the complete list of stuff which is supported with LDAP:
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_serverâ_for_windows/4.1/user/Overvw.html#wp824733â
Hope that helps!
Regards,
~JG
Do rate helpful posts
11-16-2009 09:20 AM
Hi JG
thanks for your feedback. We now installed two more ACS' on virtual machines and forward all the domain.xx suffix requests to the remote domain.
Regards
Dominic
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide