<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and AD synchronization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-synchronization/m-p/2100454#M146624</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering if any one would know the answer to this one...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have ISE linked to AD...all working well, however, when a user is given a certificate, the user won't be able to connect to the (wireless) network due to certificate problems.....after 1/2 hour to an hour, the user will be able to authenticate successfuly....without any futher intervention from IT Support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like ISE to AD sync issue.....does anyone know how often does the ISE pulls AD for information....?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UUmmmm thinking about this though, ISE should check the User "state" in AD every time the user tries to Authenticate....so could we possibly be talking about an AD replication issue here instead of ISE to AD???&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:51:37 GMT</pubDate>
    <dc:creator>superduperlopez</dc:creator>
    <dc:date>2019-03-11T02:51:37Z</dc:date>
    <item>
      <title>ISE and AD synchronization</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-synchronization/m-p/2100454#M146624</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering if any one would know the answer to this one...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have ISE linked to AD...all working well, however, when a user is given a certificate, the user won't be able to connect to the (wireless) network due to certificate problems.....after 1/2 hour to an hour, the user will be able to authenticate successfuly....without any futher intervention from IT Support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like ISE to AD sync issue.....does anyone know how often does the ISE pulls AD for information....?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UUmmmm thinking about this though, ISE should check the User "state" in AD every time the user tries to Authenticate....so could we possibly be talking about an AD replication issue here instead of ISE to AD???&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-synchronization/m-p/2100454#M146624</guid>
      <dc:creator>superduperlopez</dc:creator>
      <dc:date>2019-03-11T02:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD synchronization</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-synchronization/m-p/2100455#M146640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you check your Authentiction details.&amp;nbsp; You will probably see no certificate found for the user. There is an issue with distributed AD environments:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;In a distributed environment, a delay occurs before any domain&amp;nbsp; controller has received the certificates and CRLs through Active&amp;nbsp; Directory replication. The delay will vary depending on the Active&amp;nbsp; Directory environment configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'd ask the AD guys, what replication type and schedule are they running? This can be troubleshot watching the Published Certificates tab of the user record.&amp;nbsp; Open and close the record while enrolling and after to see when it shows up.&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/5/4/117451-Employee-cert-published.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you should see is something like this in ISE record details, Steps section:&lt;/P&gt;&lt;TABLE id="S2"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;&lt;STRONG&gt;12811&amp;nbsp; Extracted TLS Certificate message containing client certificate&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12812&amp;nbsp; Extracted TLS ClientKeyExchange message&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12813&amp;nbsp; Extracted TLS CertificateVerify message&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12804&amp;nbsp; Extracted TLS Finished message&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12801&amp;nbsp; Prepared TLS ChangeCipherSpec message&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12802&amp;nbsp; Prepared TLS Finished message&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12816&amp;nbsp; TLS handshake succeeded&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12509&amp;nbsp; EAP-TLS full handshake finished successfully&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12505&amp;nbsp; Prepared EAP-Request with another EAP-TLS challenge&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11006&amp;nbsp; Returned RADIUS Access-Challenge&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11001&amp;nbsp; Received RADIUS Access-Request&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11018&amp;nbsp; RADIUS is re-using an existing session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;12504&amp;nbsp; Extracted EAP-Response containing EAP-TLS challenge-response&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;&lt;STRONG&gt;Evaluating Identity Policy&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;EM&gt;&lt;STRONG&gt;15048&amp;nbsp; Queried PIP&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;EM&gt;&lt;STRONG&gt;15048&amp;nbsp; Queried PIP&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;&lt;STRONG&gt;15004&amp;nbsp; Matched rule&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;22037&amp;nbsp; Authentication Passed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;&lt;STRONG&gt;12506&amp;nbsp; EAP-TLS authentication succeeded&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11503&amp;nbsp; Prepared EAP-Success&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as your question: &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;does anyone know how often does the ISE pulls AD for information....?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It only "Pulls" information when you populate the AD dictionary (Groups and/or User attributes) in External Identities.&lt;/P&gt;&lt;P&gt;As far as how often if performs a lookup. It performs a lookup for every authentication as required and every processing of an Authorization Policy rule that requires a reference to that specifc rule. (think of multiple situations for processing rules which in turn would result in CoA processings for the session)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So your comment:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;UUmmmm thinking about this though, ISE should check the User "state" in&amp;nbsp; AD every time the user tries to Authenticate....&lt;STRONG&gt;&lt;EM&gt;so could we possibly be&amp;nbsp; talking about an AD replication issue here instead of ISE to AD&lt;/EM&gt;&lt;/STRONG&gt;???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; good troubleshooting /thinking!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you find this answer useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" /&gt;&lt;PARAM name="counter" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 18:07:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-synchronization/m-p/2100455#M146640</guid>
      <dc:creator>jw.sl9</dc:creator>
      <dc:date>2012-12-05T18:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD synchronization</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-synchronization/m-p/2100456#M146665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Kindly review the below link:&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/en/US/docs/solutions/Enterprise/Security/TrustSec_2.0/trustsec_2.0_dig.pdf"&gt;https://www.cisco.com/en/US/docs/solutions/Enterprise/Security/TrustSec_2.0/trustsec_2.0_dig.pdf &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 10:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-synchronization/m-p/2100456#M146665</guid>
      <dc:creator>manjeets</dc:creator>
      <dc:date>2013-05-22T10:42:05Z</dc:date>
    </item>
  </channel>
</rss>

