Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Cisco ACS 5.X and Radius using AD

Hello All - I am currently useing ACS 5.2 and have no problem using Tacacs+ with AD access.


But with Radius it seems I can only get the Local identity store to work, does anyone know if you need to do something special to get Radius to work with active directory with Cisco ACS?

1 ACCEPTED SOLUTION

Accepted Solutions
Silver

Cisco ACS 5.X and Radius using AD

Hello Bobby,

would you please include screen shot for:

1) access policies ->> default device admin ->> group mapping

2) access policies ->> default network adming->> group mapping

Kind regards

Talal

10 REPLIES
New Member

Cisco ACS 5.X and Radius using AD

Just to note,  I keep getting

Failure Reason :

22056 Subject  not found in the applicable identity store(s).
New Member

Cisco ACS 5.X and Radius using AD

Any help here?

Silver

Cisco ACS 5.X and Radius using AD

Hello Bobby,

can you please attach screen shots of following configuration:

users and identity stores ->> active directory.

both TABs , genearal and direcotry groups.

Kind regards

Talal

New Member

Cisco ACS 5.X and Radius using AD

It is working for Tacacs+  but not Radius

New Member

Cisco ACS 5.X and Radius using AD

the Directory Groups has two groups,  one for R/W and one for R/O.   

Silver

Cisco ACS 5.X and Radius using AD

Hello Bobby,

would you please include screen shot for:

1) access policies ->> default device admin ->> group mapping

2) access policies ->> default network adming->> group mapping

Kind regards

Talal

New Member

Re: Cisco ACS 5.X and Radius using AD

Ah, i looked there and noticed that the Default Network Admin was setup for Internal only, i moved it over to use the active directory,   but now i'm getting

15015 Could not find ID Store

Silver

Re: Cisco ACS 5.X and Radius using AD

perfect ;o)

New Member

Cisco ACS 5.X and Radius using AD

Bobby, I ran into the same issue with the "15015 Could not find ID Store" issue.  It turned out to be an issue with communication between the ACS and AD.  It looked like AD was connected successfully, but until I rebooted ACS, I kept getting the same error.  It was like it couldn't see the AD security groups even though it could scan the AD tree successfully.

So, try rebooting ACS if you haven't already and see if that resolves the error.

New Member

Cisco ACS 5.X and Radius using AD

Tim - I was able to get it to work after I setup the correct authentication in the ACS and tell it what shell to run.

1383
Views
5
Helpful
10
Replies