<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE with AD Problem: &amp;quot;Could not read groups data: Glob in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102129#M177925</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jw&lt;/P&gt;&lt;P&gt;1. I'm join by GUI.&lt;/P&gt;&lt;P&gt;2. 4 Nodes in my deployment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 for Admin with Monitoring&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 for Policy Service&lt;/P&gt;&lt;P&gt;3. Now I split ISE to Standalone node and try to join AD&lt;/P&gt;&lt;P&gt;4. I just see this CMD in the CLI document and do nothing with this command.&lt;/P&gt;&lt;P&gt;5. I run a Details Test then Its fail but it able to join Domain &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my domain infrastructure, I have 4 Sites contain many subnets inside. Each site contains 2 Server for GC service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS record found: _ldap._tcp.xxxx&lt;/P&gt;&lt;P&gt;Found SRV records : more than 10 SRV records&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pongsatorn M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Dec 2012 02:15:48 GMT</pubDate>
    <dc:creator>Pongsatorn Maneesud</dc:creator>
    <dc:date>2012-12-06T02:15:48Z</dc:date>
    <item>
      <title>Cisco ISE with AD Problem: "Could not read groups data: Global catalog not found"</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102127#M177923</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I make the ActiveDirectory integration with Cisco ISE, I have complete with this integration. but when I try to read the Groups from Active Directory, ISE shows the message "Could not read groups data: Global catalog not found".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Domain has multiple sites and subnets, each contains GC for local logon. I have set ISE to the correct site and subnet. Forward and Reverse DNS are working with no error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone get this problem, please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/4/4/117442-Screen%20Shot%202555-12-05%20at%2011.31.51%20PM.png" alt="Screen Shot 2555-12-05 at 11.31.51 PM.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have check into the ISE CLI Reference Guide 1.1.x&lt;/P&gt;&lt;PRE&gt;You are about to configure Active Directory settings.
&lt;/PRE&gt;&lt;P&gt; &lt;A name="wp2275664" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV style="color: #000000; font-family: 'Courier New', Courier, mono; font-size: 10px; margin: -0.55em 0em; background-color: #ffffff;"&gt;&lt;PRE&gt;Are you sure you want to proceed? y/n [n]: y
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp2275711" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV style="color: #000000; font-family: 'Courier New', Courier, mono; font-size: 10px; margin: -0.55em 0em; background-color: #ffffff;"&gt;&lt;PRE&gt;Parameter Name: dns.servers
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp2275712" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV style="color: #000000; font-family: 'Courier New', Courier, mono; font-size: 10px; margin: -0.55em 0em; background-color: #ffffff;"&gt;&lt;PRE&gt;Parameter Value: 10.77.122.135
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp2275713" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV style="color: #000000; font-family: 'Courier New', Courier, mono; font-size: 10px; margin: -0.55em 0em; background-color: #ffffff;"&gt;&lt;PRE&gt;Active Directory internal setting modification should only be performed if approved by ISE 
support. Please confirm this change has been approved y/n [n]: y
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp2275669" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What shoud I set in the Parameter Name ? dns.servers or my dns hostname ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest for this too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pongsatorn M.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:51:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102127#M177923</guid>
      <dc:creator>Pongsatorn Maneesud</dc:creator>
      <dc:date>2019-03-11T02:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE with AD Problem: "Could not read groups data: Glob</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102128#M177924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just checking...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Did you join by GUI? &lt;/LI&gt;&lt;LI&gt;How many Nodes in your deployment?&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;Did you join all the nodes running the Policy Service persona?&lt;/LI&gt;&lt;LI&gt;Why are/did you modify the CLI settings?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;And&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Have you run a Detail Test?&amp;nbsp; If not, do so.&amp;nbsp; If so, zip it up and attach it to a reply post.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you find this answer useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" /&gt;&lt;PARAM name="counter" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 17:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102128#M177924</guid>
      <dc:creator>jw.sl9</dc:creator>
      <dc:date>2012-12-05T17:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE with AD Problem: "Could not read groups data: Glob</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102129#M177925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jw&lt;/P&gt;&lt;P&gt;1. I'm join by GUI.&lt;/P&gt;&lt;P&gt;2. 4 Nodes in my deployment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 for Admin with Monitoring&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 for Policy Service&lt;/P&gt;&lt;P&gt;3. Now I split ISE to Standalone node and try to join AD&lt;/P&gt;&lt;P&gt;4. I just see this CMD in the CLI document and do nothing with this command.&lt;/P&gt;&lt;P&gt;5. I run a Details Test then Its fail but it able to join Domain &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my domain infrastructure, I have 4 Sites contain many subnets inside. Each site contains 2 Server for GC service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS record found: _ldap._tcp.xxxx&lt;/P&gt;&lt;P&gt;Found SRV records : more than 10 SRV records&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pongsatorn M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 02:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102129#M177925</guid>
      <dc:creator>Pongsatorn Maneesud</dc:creator>
      <dc:date>2012-12-06T02:15:48Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE with AD Problem: "Could not read groups data: Global c</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102130#M177926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;send the detail results &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt; &lt;BR /&gt;I hope you find this information useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" value="" /&gt;&lt;PARAM name="counter" value="" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 03:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102130#M177926</guid>
      <dc:creator>jw.sl9</dc:creator>
      <dc:date>2012-12-06T03:03:59Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE with AD Problem: "Could not read groups data: Global c</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102131#M177927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not use google chrome, try using mozilla instead (ise does not play nice with chrome). Also check your sites and services information and see if there domain controllers listed for the subnet that ISE is connected to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 06:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102131#M177927</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-12-06T06:15:24Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ISE with AD Problem: "Could not read groups data: Globa</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102132#M177928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;Site and subnet is set. it still not working.&lt;BR /&gt;&lt;BR /&gt;But I fixes it already using CLI reference guide.&lt;BR /&gt;"application configure ise"&lt;BR /&gt;&lt;BR /&gt;ISE should describe more integration requirements about this. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 14:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102132#M177928</guid>
      <dc:creator>Pongsatorn Maneesud</dc:creator>
      <dc:date>2012-12-06T14:45:18Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE with AD Problem: "Could not read groups data: Global c</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102133#M177929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pongsatorn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What was your CLI fix for this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am seeing the same thing in a resent deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2013 19:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102133#M177929</guid>
      <dc:creator>gschmitt.ngit</dc:creator>
      <dc:date>2013-01-02T19:48:14Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ISE with AD Problem: "Could not read groups data: Globa</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102134#M177930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you explain more about your deployment ?&lt;/P&gt;&lt;P&gt;Can you expalin more about the Active Directory Infrastructure in your site ?&lt;/P&gt;&lt;P&gt;What happen when you open your command-line and type "netdom query fsmo" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, this is my working solution for me&lt;/P&gt;&lt;P&gt;I using this command below to fix my issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"application configuration ise"&lt;/P&gt;&lt;P&gt;Then I select option 3 to make a static Active Directory setting&lt;/P&gt;&lt;P&gt;Parameter Name: dns.servers&amp;nbsp; --&amp;gt; not change to anything you think before &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; just type "dns.servers"&lt;/P&gt;&lt;P&gt;Parameter Value: 1.2.3.4&amp;nbsp; --&amp;gt; Point to your AD IP address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then select option 5 after that option 4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Pongsatorn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2013 17:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102134#M177930</guid>
      <dc:creator>Pongsatorn Maneesud</dc:creator>
      <dc:date>2013-01-03T17:00:10Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ISE with AD Problem: "Could not read groups data: Globa</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102135#M177931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pongsatorn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached the results of the ISE detailed AD test. As you can see, there is a fair number of domain controllers in the AD forest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems everything works correctly until it gets to testing the AD connectivity on port 3268. Then I get this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Testing Active Directory connectivity:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Global Catalog: pdascdc02.xyz.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; gc:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3268/tcp - refused&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Testing Active Directory connectivity:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Global Catalog: pdascdc02.xyz.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; gc:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3268/tcp - refused&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason, the request to the controllers on port 3268 is being refused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts you might have are greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2013 17:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-ad-problem-quot-could-not-read-groups-data-global/m-p/2102135#M177931</guid>
      <dc:creator>gschmitt.ngit</dc:creator>
      <dc:date>2013-01-03T17:58:25Z</dc:date>
    </item>
  </channel>
</rss>

