xix
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Contents
C H A P T E R
12
Administering External User Databases
12-1
Unknown User Processing
12-1
Known, Unknown, and Discovered Users
12-2
General Authentication Request Handling and Rejection Mode
12-3
Authentication Request Handling and Rejection Mode with the
Windows NT/2000 User Database
12-4
Windows Authentication with a Domain Specified
12-5
Windows Authentication with Domain Omitted
12-6
Performance of Unknown User Authentication
12-7
Added Latency
12-7
Authentication Timeout Value on AAA clients
12-7
Network Access Authorization
12-8
Unknown User Policy
12-8
Database Search Order
12-9
Configuring the Unknown User Policy
12-9
Turning off External User Database Authentication
12-11
Database Group Mappings
12-11
Group Mapping by External User Database
12-12
Creating a Cisco Secure ACS Group Mapping for a Token Server, ODBC
Database, or LEAP Proxy RADIUS Server Database
12-13
Group Mapping by Group Set Membership
12-14
Group Mapping Order
12-15
No Access Group for Group Set Mappings
12-15
Default Group Mapping for Windows NT/2000
12-16
Creating a Cisco Secure ACS Group Mapping for Windows NT/2000,
Novell NDS, or Generic LDAP Groups
12-16
Editing a Windows NT/2000, Novell NDS, or Generic LDAP Group Set
Mapping
12-18
Deleting a Windows NT/2000, Novell NDS, or Generic LDAP Group Set
Mapping
12-20