<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Distributed System - AD join issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154736#M138420</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer your question: You need to join your PDP nodes for user/machine authentications coming from NAD devices (Switches, Firewalls, WLCs, etc). If you want to integrate ISE admin, lobby admin to AD then you need the Admin nodes joined as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the AD join error: Can you bump up the logging to "debugging" for AD and post the outputs from the log file again? Also, did you make sure that you have the proper permissions for the AD account that you are trying to use to join the nodes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Mar 2013 17:01:19 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2013-03-01T17:01:19Z</dc:date>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154735#M138418</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have deployed 04 ISE nodes in the following senario. (ISE ver 1.1.2.245)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;1 ISE - Primary (A) Secondary (M) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2 ISE - Primary (M) Secondary (A)&lt;/P&gt;&lt;P&gt;3 ISE -&amp;nbsp; Policy Service (PDP)&lt;/P&gt;&lt;P&gt;4 ISE -&amp;nbsp; Policy Service (PDP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When integrating with AD, we can only integrat to the 1 ISE only. NTP, Timezone, DNS working on all 04 boxes perfectly. We are getting the attached error while integrating AD with other ISE nodes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above senario, what ISE nodes should have the AD joined, only the PDP or all 04 nodes should have joined..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please advise. Please see the attached screenprints for the deployment and detailed error while joining to AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:08:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154735#M138418</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2019-03-11T03:08:33Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154736#M138420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer your question: You need to join your PDP nodes for user/machine authentications coming from NAD devices (Switches, Firewalls, WLCs, etc). If you want to integrate ISE admin, lobby admin to AD then you need the Admin nodes joined as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the AD join error: Can you bump up the logging to "debugging" for AD and post the outputs from the log file again? Also, did you make sure that you have the proper permissions for the AD account that you are trying to use to join the nodes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 17:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154736#M138420</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2013-03-01T17:01:19Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154737#M138430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the debug logs for AD joining. I can see the below two issues, but dont know how to find the solution..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;•1)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/LI&gt;&lt;LI&gt;•2)&amp;nbsp; SASL bind to &lt;A href="mailto:ldap/hqv-dcs-02.abq.gov.qa@ABQ.GOV.QA"&gt;ldap/hqv-dcs-02.xxxx.gov.qa@xxxx.GOV.QA&lt;/A&gt; - GSSAPI Mechanism with Kerberos error ": Cannot contact any KDC for requested realm"&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state ProbePorts complete for hqv-dcs-02.xxx.gov.qa. Elapsed time 0.014737 secs&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findkdc KDC locator for xxx.GOV.QA&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domaincontroller: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.dc.xxx.gov.qa: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findsrv FindSrvFromDns(0): _kerberos._tcp.xxxsite._sites.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST: SniffList: postfailsort=hqv-dcs-02.xxx.gov.qa, hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.kerberos.keytab GetSaltFromKDC returns: xxx.GOV.QAAdmin-Asif&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.aduser getSalt update: user:&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:admin-asif@xxx.GOV.QA"&gt;admin-asif@xxx.GOV.QA&lt;/A&gt;&lt;SPAN&gt; salt:xxx.GOV.QAAdmin-Asif&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findkdc KDC locator for xxx.GOV.QA&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domaincontroller: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.dc.xxx.gov.qa: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findsrv FindSrvFromDns(0): _kerberos._tcp.xxxsite._sites.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:47 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST: SniffList: postfailsort=hqv-dcs-02.xxx.gov.qa, hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findkdc KDC locator for xxx.GOV.QA&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domaincontroller: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.dc.xxx.gov.qa: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findsrv FindSrvFromDns(0): _kerberos._tcp.xxxsite._sites.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST: SniffList: postfailsort=hqv-dcs-02.xxx.gov.qa, hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad Performing LDAP binding with GSSAPI mechanisms to server - hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findkdc KDC locator for xxx.GOV.QA&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domaincontroller: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.dc.xxx.gov.qa: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findsrv FindSrvFromDns(0): _kerberos._tcp.xxxsite._sites.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:53:49 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST: SniffList: postfailsort=hqv-dcs-02.xxx.gov.qa, hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.osutil Module=Kerberos : SASL bind to &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ldap/hqp-dcs-01.xxx.gov.qa@xxx.GOV.QA"&gt;ldap/hqp-dcs-01.xxx.gov.qa@xxx.GOV.QA&lt;/A&gt;&lt;SPAN&gt; - GSSAPI Mechanism with Kerberos error ": Cannot contact any KDC for requested realm" (reference base/adbind.cpp:495 rc: -1765328228)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST:reportFailure: hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DIAG&amp;nbsp; base.bind.ad connectToServiceInDomain: Failed to connect to hqp-dcs-01.xxx.gov.qa:389: SASL bind to &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ldap/hqp-dcs-01.xxx.gov.qa@xxx.GOV.QA"&gt;ldap/hqp-dcs-01.xxx.gov.qa@xxx.GOV.QA&lt;/A&gt;&lt;SPAN&gt; - GSSAPI Mechanism with Kerberos error ": Cannot contact any KDC for requested realm"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domaincontroller: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.dc.xxx.gov.qa: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findsrv FindSrvFromDns(0): _ldap._tcp.xxxsite._sites.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST: SniffList: postfailsort=hqv-dcs-02.xxx.gov.qa, hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad Attempting to connect to a DC in site 'xxxsite'&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad Connecting to hqv-dcs-02.xxx.gov.qa:389&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:04 xxx-TW-ISE-2 adjoin[27660]: DIAG&amp;nbsp; base.bind.ldap 10.0.11.52:389 fetch dn="" filter="(objectclass=*)" timeout=11&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG lrpc.adobject new object: &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad Connected root=DC=xxx,DC=gov,DC=qa, domain=xxx.GOV.QA functionality=3&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad Address of hqv-dcs-02.xxx.gov.qa is 10.0.11.52&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad Performing LDAP binding with GSSAPI mechanisms to server - hqv-dcs-02.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findkdc KDC locator for xxx.GOV.QA&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domaincontroller: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.dc.xxx.gov.qa: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG dns.findsrv FindSrvFromDns(0): _kerberos._tcp.xxxsite._sites.xxx.gov.qa&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:06 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST: SniffList: postfailsort=hqv-dcs-02.xxx.gov.qa, hqp-dcs-01.xxx.gov.qa&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.osutil Module=Kerberos : SASL bind to &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ldap/hqv-dcs-02.xxx.gov.qa@xxx.GOV.QA"&gt;ldap/hqv-dcs-02.xxx.gov.qa@xxx.GOV.QA&lt;/A&gt;&lt;SPAN&gt; - GSSAPI Mechanism with Kerberos error ": Cannot contact any KDC for requested realm" (reference base/adbind.cpp:495 rc: -1765328228)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG network.state NST:reportFailure: hqv-dcs-02.xxx.gov.qa&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad connectToList: Failed to connect to hqv-dcs-02.xxx.gov.qa:389: SASL bind to &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ldap/hqv-dcs-02.xxx.gov.qa@xxx.GOV.QA"&gt;ldap/hqv-dcs-02.xxx.gov.qa@xxx.GOV.QA&lt;/A&gt;&lt;SPAN&gt; - GSSAPI Mechanism with Kerberos error ": Cannot contact any KDC for requested realm"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.osutil Module=LDAP : reconnect failed (reference base/adbind.cpp:785 rc: -11)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG base.bind.ad Destroying binding to 'xxx.GOV.QA'&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting zonename to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting schema to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting zone to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.dc.xxx.gov.qa: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting domaincontroller to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting site to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting domain to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting prew2k.host to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting host to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG cli.adjoin Unexpected LDAP Error Connect error &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG cli.adjoin&amp;nbsp; due to unexpected configuration or network error.&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG cli.adjoin Please try the --verbose option or run 'adinfo --diag' to diagnose the problem.&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting host to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: DEBUG util.settings Setting prew2k.host to &lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:21 xxx-TW-ISE-2 adjoin[27660]: INFO&amp;nbsp; cli.adjoin Join to domain 'xxx.gov.qa', zone 'null' failed.&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:23 xxx-TW-ISE-2 adinfo[27666]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:23 xxx-TW-ISE-2 adinfo[27666]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:23 xxx-TW-ISE-2 adinfo[27668]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:23 xxx-TW-ISE-2 adinfo[27668]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:33 xxx-TW-ISE-2 adinfo[28164]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:33 xxx-TW-ISE-2 adinfo[28164]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:44 xxx-TW-ISE-2 adinfo[28172]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:44 xxx-TW-ISE-2 adinfo[28172]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:54 xxx-TW-ISE-2 adinfo[28900]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:54:54 xxx-TW-ISE-2 adinfo[28900]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:05 xxx-TW-ISE-2 adinfo[28905]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:05 xxx-TW-ISE-2 adinfo[28905]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:16 xxx-TW-ISE-2 adinfo[28907]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:16 xxx-TW-ISE-2 adinfo[28907]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:27 xxx-TW-ISE-2 adinfo[28911]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:27 xxx-TW-ISE-2 adinfo[28911]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:38 xxx-TW-ISE-2 adinfo[28913]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:38 xxx-TW-ISE-2 adinfo[28913]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:49 xxx-TW-ISE-2 adinfo[28920]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:55:49 xxx-TW-ISE-2 adinfo[28920]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:56:00 xxx-TW-ISE-2 adinfo[28988]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:56:00 xxx-TW-ISE-2 adinfo[28988]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 3 09:56:11 xxx-TW-ISE-2 adinfo[29010]: DEBUG util.except (IO) : Cannot open file /var/centrifydc/kset.domain: No such file or directory (reference util/setting.cpp:106 rc: 2)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Mar 2013 16:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154737#M138430</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2013-03-03T16:50:17Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154738#M138436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Make sure you are joining with a user ID that has permissions to create a machine into the domain.&amp;nbsp; Also make sure the subnet that you are joining the PSN devices on have AD sites and services set up so that the ISE knows what domain controller to contact that is closest to it.&amp;nbsp; If you run the detailed test before joining the node that will usually tell you the problem that is getting in the way.&amp;nbsp; It also helps to have your DNS entries done prior to joining the nodes, make sure you populate your PTR records as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 05:36:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154738#M138436</guid>
      <dc:creator>chris_day</dc:creator>
      <dc:date>2013-03-04T05:36:34Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154739#M138445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Integrating Cisco ISE with Active Directory&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Prerequisites:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Before you connect your Cisco ISE server with the Active Directory domain, you must check the&lt;/P&gt;&lt;P&gt;following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;Ensure that your Cisco ISE server and Active Directory are time synchronized. Time in the Cisco&lt;/P&gt;&lt;P&gt;ISE is set according to the Network Time Protocol (NTP) server. It is recommended that you use the&lt;/P&gt;&lt;P&gt;NTP to synchronize time between the Cisco ISE and Active Directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;If there is a firewall between Cisco ISE and Active Directory, certain ports need to be opened to&lt;/P&gt;&lt;P&gt;allow Cisco ISE to communicate with Active Directory. Ensure that the following default ports are&lt;/P&gt;&lt;P&gt;open:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;If your Active Directory source has a multidomain forest, ensure that trust relationships exist&lt;/P&gt;&lt;P&gt;between the domain to which Cisco ISE is connected and the other domains with resources to which&lt;/P&gt;&lt;P&gt;you need access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;The DNS server that is configured in Cisco ISE using the &lt;STRONG&gt;ip name-server &lt;/STRONG&gt;command should be able&lt;/P&gt;&lt;P&gt;to resolve the domain names in your Active Directory identity source. Typically, the DNS server that&lt;/P&gt;&lt;P&gt;is part of the Active Directory deployment is configured in Cisco ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Protocol Port Number&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;LDAP 389 (UDP)&lt;/P&gt;&lt;P&gt;SMB1&lt;/P&gt;&lt;P&gt;1. SMB = Server Message Block&lt;/P&gt;&lt;P&gt;445 (TCP)&lt;/P&gt;&lt;P&gt;KDC2&lt;/P&gt;&lt;P&gt;2. KDC = Kerberos Key Distribution Center&lt;/P&gt;&lt;P&gt;88 (TCP)&lt;/P&gt;&lt;P&gt;Global Catalog 3268 (TCP), 3289&lt;/P&gt;&lt;P&gt;KPASS 464 (TCP)&lt;/P&gt;&lt;P&gt;NTP 123 (UDP)&lt;/P&gt;&lt;P&gt;LDAP 389 (TCP)&lt;/P&gt;&lt;P&gt;LDAPS3&lt;/P&gt;&lt;P&gt;3. LDAPS = Lightweight Directory Access Protocol over TLS/SSL&lt;/P&gt;&lt;P&gt;636 (TCP)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;5&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;The Active Directory username that you provide while joining to an Active Directory domain should&lt;/P&gt;&lt;P&gt;be predefined in Active Directory and should have any one of the following permissions:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;– &lt;/STRONG&gt;Add the workstation to the domain to which you are trying to connect.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;– &lt;/STRONG&gt;On the computer where the Cisco ISE account was created, establish permissions for creating&lt;/P&gt;&lt;P&gt;computer objects or deleting computer objects before you join Cisco ISE to the domain.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;– &lt;/STRONG&gt;Permissions for searching users and groups that are required for authentication.&lt;/P&gt;&lt;P&gt;After you join your Cisco ISE server to the Active Directory domain, you might still need the&lt;/P&gt;&lt;P&gt;permissions discussed previously to do the following:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;– &lt;/STRONG&gt;Join any secondary Cisco ISE servers to this domain&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;– &lt;/STRONG&gt;Back up or restore data&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;– &lt;/STRONG&gt;Upgrade the Cisco ISE to a higher version if the upgrade process involves backup and restore&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;&lt;STRONG&gt;If your Cisco ISE deployment has multiple nodes in a distributed setup, you must first define the&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Active Directory domain on the primary administration node and then explicitly join each of the&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;secondary policy service nodes to that domain.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;Every Cisco ISE administrator account is assigned one or more administrative roles. To perform the&lt;/P&gt;&lt;P&gt;operations that are described in the following procedures, you must have one of the following roles&lt;/P&gt;&lt;P&gt;assigned: Super Admin or System Admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;Ensure that your Microsoft Active Directory Server does not reside behind a network address&lt;/P&gt;&lt;P&gt;translator and does not have a Network Address Translation (NAT) address. “&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 20:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154739#M138445</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2013-03-06T20:32:58Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154740#M138467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, I am not sure either. Did you turn on the highest level of logging for active directory in ISE? Also, you said that you were able to join the first node, if so were you able to pull any groups?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 02:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154740#M138467</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2013-03-08T02:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154741#M138490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In addition to what everyone has posted above you can also check the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the command line run a nslookup of your domain.&amp;nbsp; Ensure that all NS records are your correct domain controllers and that they are active.&amp;nbsp; Remove any NS records for domain controller that are no longer active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 16:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154741#M138490</guid>
      <dc:creator>kylerossd</dc:creator>
      <dc:date>2013-03-08T16:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154742#M138512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AD username is a member of Domain Admin. All the ISE nodes have been added to DNS and were able to resolve with hostname and IP address wise verse.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2013 18:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154742#M138512</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2013-03-10T18:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154743#M138538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we give nslookup on ISE CLI, it resolve the ip address on all ISE nodes..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have open a TAC case and we are working on this and will update once fixed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2013 18:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154743#M138538</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2013-03-10T18:56:06Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154744#M138548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have exactly the same problem - did TAC ever find a solution for you?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 14:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154744#M138548</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-10-15T14:36:14Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154745#M138562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a TAC case for the same. They will help you out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2013 23:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154745#M138562</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-10-17T23:49:43Z</dc:date>
    </item>
    <item>
      <title>ISE Distributed System - AD join issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154746#M138569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Your deployment design is correct and just verify the below activity&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;All nodes &lt;STRONG&gt;• &lt;/STRONG&gt;View and configure system time and NTP server settings. &lt;STRONG&gt;• &lt;/STRONG&gt;Install server certificate, manage certificate signing request. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;The server certificate operations must be performed directly on each individual node. The private keys are not stored in the local database and are not copied from the relevant node; the private keys are stored in the local file system.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 22:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-system-ad-join-issue/m-p/2154746#M138569</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-10-18T22:54:05Z</dc:date>
    </item>
  </channel>
</rss>

