Chapter 8 Managing Users and Identity Stores

Managing External Identity Stores

Figure 8-1 LDAP Interface Configuration in NAC Profiler

Step 5 Click Update Server.

Step 6 Click the Configuration tab and click Apply Changes.

The Update NAC Profiler Modules page appears.

Step 7 Click Update Modules to enable LDAP to be used by ACS.

You must enable the endpoint profiles that you want to authenticate against the Cisco NAC Profiler. For information on how to do this, see Configuring Endpoint Profiles in NAC Profiler for LDAP Authentication, page 8-36.

For proper Active Response Events you need to configure Active Response Delay time from your Cisco NAC Profiler UI. For this, choose Configuration > NAC Profiler Modules > Configure Server >

Advanced Options > Active Response Delay.

Configuring Endpoint Profiles in NAC Profiler for LDAP Authentication

For the non-802.1X endpoints that you want to successfully authenticate, you must enable the corresponding endpoint profiles in NAC Profiler for LDAP authentication.

Note If the profile is not enabled for LDAP, the endpoints in the profile will not be authenticated by the Cisco NAC Profiler.

To enable the endpoint profiles for LDAP authentication:

Step 1 Log into your NAC Profiler.

 

User Guide for Cisco Secure Access Control System 5.3

8-36

OL-24201-01

Page 188
Image 188
Cisco Systems OL-24201-01 manual Advanced Options Active Response Delay, Ldap Interface Configuration in NAC Profiler