Field
Description
Usage tips
Use DNS
SRV lookup
to obtain
Kerberos
Key
Distribution
Center
addresses
Yes
is the recommended setting. This means
that VCS will use a DNS SRV lookup of the
AD domain
to obtain the address details of
the Kerberos Key Distribution Center servers.
If the lookup cannot provide the addresses
then set this field to
No
and enter the IP
address of the primary Key Distribution Center
servers into the
Address 1
field that will be
displayed. Typically,
Port 1
can be left as its
default value of 88.
Typically, the KDC addresses are the same as
the Domain Controller addresses.
Username
and
Password
The AD domain administrator username and
password. The password is case sensitive.
The domain administrator's credentials are
required only when you attempt to join a
domain. The VCS only needs to join the
domain once, after which the connection can
be enabled or disabled as required.
3. Click
Save
to store the configuration and join the AD domain.
The VCS should join the AD domain. If you receive an error message, check the following:
l
the configuration settings on this page, including the username and password
l
the VCS’s CA certificate, private key and server certificate
l
the
Status
area at the bottom of the Active Directory Service page for more information about the status
of the connection to the AD domain
Note that:
n
The domain administrator username and password are not stored in VCS; they are only required to join an
AD domain (or to leave a domain).
n
The VCS only needs to join the AD domain once, even if the connection to the Active Directory Service is
disabled and turned back on again. The only time a join is needed again is if the VCS leaves the domain or
needs to join a different domain.
Adding non-primary Domain Controllers and Kerberos Key Distribution Center servers (optional)
This procedure is only required if you are not using DNS SRV lookups of the
AD domain
to obtain the
address details of the Domain Controller servers and the Kerberos Key Distribution Center servers.
1. Go to
Configuration > Authentication > Devices > Active Directory Service
.
2. Enter up to 4 further Domain Controller server addresses (up to 5 in total).
3. Enter up to 4 further Kerberos Key Distribution Center server addresses and port numbers (up to 5 in total).
4. Click
Save
.
5. If the VCS is part of a cluster, check that the configuration entered on the master peer has been replicated
to each other peer.
Clustered VCS systems
In a clustered system, each VCS must join the AD domain separately. To do this:
Cisco VCS Administrator Guide (X8.1.1)
Page 126 of 507
Device authentication
About device authentication