<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Not Identifying AD Group Attributes when using Multiple  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015672#M158153</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have identified what causes this to happen. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This only happens if your setup has PDP servers not a part of your Admin and Troubleshooting boxes and you change the &lt;LABEL&gt;Identity Store Name for your Active Directory External Identity Source.&lt;/LABEL&gt; You must resync the PDP boxes to update the information it must not be updating automatically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps someone else I cannot create a bug id for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-CC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2012 17:47:31 GMT</pubDate>
    <dc:creator>Christopher Calhoun</dc:creator>
    <dc:date>2012-10-05T17:47:31Z</dc:date>
    <item>
      <title>ISE Not Identifying AD Group Attributes when using Multiple ISE Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015669#M158083</link>
      <description>&lt;P&gt;So we have multiple ISE Servers with differing personas. I was having an issue with our new ISE setup not identifying AD Group Attributes when using them in Authorization rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2- 3395 appliances running Admin and Monitoring/Troubleshooting Personas and 2- 3395 appliances running as Policy server personas. We are running&amp;nbsp; v1.1.1.268 with the latest two patches. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was unable to pull Active Directory Group Attributes in any of my Authorization rules. After Resyncing all the boxes with the Primary Administration box I was able to do this. There is no bug listings for this occurance nor do we have Smartnet to call support for other reasons. I thought this might be useful to someone who is having the same issue and is unable to figure it out with TAC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-CC&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015669#M158083</guid>
      <dc:creator>Christopher Calhoun</dc:creator>
      <dc:date>2019-03-11T02:37:57Z</dc:date>
    </item>
    <item>
      <title>ISE Not Identifying AD Group Attributes when using Multiple ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015670#M158100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under the deployment tab were all the nodes in sync? What did you do in order resync just apply the sync up (dont know the exact syntax) to force replication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 21:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015670#M158100</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-03T21:01:33Z</dc:date>
    </item>
    <item>
      <title>ISE Not Identifying AD Group Attributes when using Multiple ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015671#M158117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Absolutely. All units said in-sync after setting their personas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is our layout:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE-ADM-01&amp;nbsp; Admin-Primary, Monitoring-Secondary &lt;/P&gt;&lt;P&gt;ISE-ADM-02&amp;nbsp; Admin-Secondary, Monitoring-Primary&lt;/P&gt;&lt;P&gt;ISE-PDP-01&amp;nbsp; Policy Only&lt;/P&gt;&lt;P&gt;ISE-PDP-02&amp;nbsp; Policy Only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I synced one at a time starting with ADM-02. After completing the other two boxes. Active Directory Attribs were pulled down when using them in the Ext Group within my Authz rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-CC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 00:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015671#M158117</guid>
      <dc:creator>Christopher Calhoun</dc:creator>
      <dc:date>2012-10-04T00:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Not Identifying AD Group Attributes when using Multiple</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015672#M158153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have identified what causes this to happen. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This only happens if your setup has PDP servers not a part of your Admin and Troubleshooting boxes and you change the &lt;LABEL&gt;Identity Store Name for your Active Directory External Identity Source.&lt;/LABEL&gt; You must resync the PDP boxes to update the information it must not be updating automatically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps someone else I cannot create a bug id for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-CC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 17:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-identifying-ad-group-attributes-when-using-multiple-ise/m-p/2015672#M158153</guid>
      <dc:creator>Christopher Calhoun</dc:creator>
      <dc:date>2012-10-05T17:47:31Z</dc:date>
    </item>
  </channel>
</rss>

