<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.1 EAP-TLS User Authentication in Multiforest in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999230#M181430</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to see if the dns server is able to resolve the domain2, if you issue a nslookup for domain2 what do you show, do you receive any responses? I would start there and see what that turns up. Also what type of trust do you have enabled between domain1 and domain2, ISE uses kerberos to authenticate these users so we need to see if you have an external trust configured between these domains then authentication will fail since kerberos is not allowed. Please use a forest trust which allows kerberos and that should fix your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you were using acs 4.2 at one point then it would have worked because that uses ntlm auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an article for reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://setspn.blogspot.com/2009/09/ad-external-trusts-and-kerberos.html"&gt;http://setspn.blogspot.com/2009/09/ad-external-trusts-and-kerberos.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jun 2012 17:45:56 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-06-27T17:45:56Z</dc:date>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999228#M181428</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are currently evaluating the ISE 1.1 in a multiforest environment and we have problems to authenticate users which based in other domains (domain2) then the ISE (domain) is based.&lt;/P&gt;&lt;P&gt;This is the setup:&lt;/P&gt;&lt;P&gt;In domain1 is a MSFT CA with OCSP, DC and ISE&lt;/P&gt;&lt;P&gt;In domain2 is a DC and the users&lt;/P&gt;&lt;P&gt;there is a two way trust between the domains. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my authentication scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. agent connect to a wireless network (ok)&lt;/P&gt;&lt;P&gt;2. client exchanges certificate information with ISE (ok)&lt;/P&gt;&lt;P&gt;3. ISE exchanges certificate status with CA (ok)&lt;/P&gt;&lt;P&gt;4. ISE extracts the subject Alternative Name from the certificate &lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt; (ok)&lt;/P&gt;&lt;P&gt;5. ISE queries Active Directory store for the user&amp;nbsp; &lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt; (not ok fails with&amp;nbsp; 22056 Subject not found)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the log i can see the other forest (domain2) is not even queried to retrieve user data only domain1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could query the other domain during AD setup and was able to add groups from the other domain bet i could retrieve attributes of the user in domain2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Extract from Log File&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; daemon.ipcclient2 executing request 'CAPIGetObjectByName' in thread 2951601040&lt;/P&gt;&lt;P&gt;DIAG&amp;nbsp; &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; daemon.ipcclient2 doCAPIGetObjectByName: category=Person &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:name=dersa@domain2.ch" target="_blank"&gt;name=dersa@domain2.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;options=2&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; dns.findsrv FindSrvFromDns(0): _kerberos._tcp.domain2.ch&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.adagent.domaininfo rejecting domain domain2.ch.&amp;nbsp; Blocked, not in DNS or our domain list&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.adagent findObject ADNames: &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch#012name&lt;/A&gt;&lt;/P&gt;&lt;P&gt;: &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;type=SAM domain=domain1.LAN#012&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search base , filter (&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;)), attrs 7e638646 (cacheOps=40f, GC=0)&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper age 6, expire age 60, cutoff time 0, refresh 15, negative=true, cacheOps 40f&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper.ad Cache expired 96fe94aa2a7249bca2f59766075e7859, CN=SearchMark,CN=CENTRIFY MARKER,DC=domain1,DC=LAN&lt;/P&gt;&lt;P&gt;DIAG&amp;nbsp; &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.ldap 10.0.128.10:389 search base="DC=domain1,DC=lan" filter="(&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;))"&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search: refresh list returns 0 objects&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.cache Cache store &amp;lt;GUID=96fe94aa2a7249bca2f59766075e7859&amp;gt;;CN=SearchMark,CN=CENTRIFY MARKER,DC=domain1,DC=LAN : update indexes No&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search base , filter (&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;)), attrs e4a3aa15 (cacheOps=40f, GC=1)&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper age 6, expire age 3600, cutoff time 0, refresh 15, negative=true, cacheOps 40f&lt;/P&gt;&lt;P&gt;DIAG&amp;nbsp; &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.ldap 10.0.128.9:3268 search base="" filter="(&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;))"&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search: refresh list returns 0 objects&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.cache Cache store &amp;lt;GUID=7c68c59bc09f4775a14d6a7f521e491c&amp;gt;;CN=SearchMark,CN=CENTRIFY MARKER,DC=$ : update indexes No&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.adagent findObject: NotFound:&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt;&lt;SPAN&gt; Category:user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache making negative response for Person userPrincipalName="&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;" (GC=0)&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.cache Cache store &amp;lt;GUID=972f489502d74f49afdef7f38206e909&amp;gt;;CN=CENTRIFY NEGATIVE RESPONSE,CN=Person,DC=domain1,DC=LAN : update indexes Yes&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:'dersa@domain2.ch'" target="_blank"&gt;'dersa@domain2.ch'&lt;/A&gt;&lt;/P&gt;&lt;P&gt;is not a canonical name&lt;/P&gt;&lt;P&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; daemon.ipcclient2 request 'CAPIGetObjectByName' complete&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; daemon.ipcclient2 executing request 'CAPIGetObjectByName' in thread 2951601040&lt;BR /&gt;DIAG&amp;nbsp; &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; daemon.ipcclient2 doCAPIGetObjectByName: category=Person &lt;A href="mailto:name=dersa@domain2.ch" target="_blank"&gt;name=dersa@domain2.ch&lt;/A&gt; options=2&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; dns.findsrv FindSrvFromDns(0): _kerberos._tcp.domain2.ch&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.adagent.domaininfo rejecting domain domain2.ch.&amp;nbsp; Blocked, not in DNS or our domain list&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.adagent findObject ADNames: &lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch#012name&lt;/A&gt;: &lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt; type=SAM domain=domain1.LAN#012&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search base , filter (&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;)), attrs 7e638646 (cacheOps=40f, GC=0)&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper age 6, expire age 60, cutoff time 0, refresh 15, negative=true, cacheOps 40f&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper.ad Cache expired 96fe94aa2a7249bca2f59766075e7859, CN=SearchMark,CN=CENTRIFY MARKER,DC=domain1,DC=LAN&lt;BR /&gt;DIAG&amp;nbsp; &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.ldap 10.0.128.10:389 search base="DC=domain1,DC=lan" filter="(&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;))"&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search: refresh list returns 0 objects&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.cache Cache store &amp;lt;GUID=96fe94aa2a7249bca2f59766075e7859&amp;gt;;CN=SearchMark,CN=CENTRIFY MARKER,DC=domain1,DC=LAN : update indexes No&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search base , filter (&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;)), attrs e4a3aa15 (cacheOps=40f, GC=1)&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper age 6, expire age 3600, cutoff time 0, refresh 15, negative=true, cacheOps 40f&lt;BR /&gt;DIAG&amp;nbsp; &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.ldap 10.0.128.9:3268 search base="" filter="(&amp;amp;(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(&lt;A href="mailto:sAMAccountName=dersa@domain2.ch" target="_blank"&gt;sAMAccountName=dersa@domain2.ch&lt;/A&gt;))"&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache ADCB::search: refresh list returns 0 objects&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.cache Cache store &amp;lt;GUID=7c68c59bc09f4775a14d6a7f521e491c&amp;gt;;CN=SearchMark,CN=CENTRIFY MARKER,DC=$ : update indexes No&lt;BR /&gt;&lt;SPAN&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.adagent findObject: NotFound:&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt;&lt;SPAN&gt; Category:user&lt;/SPAN&gt;&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.bind.cache making negative response for Person userPrincipalName="&lt;A href="mailto:dersa@domain2.ch" target="_blank"&gt;dersa@domain2.ch&lt;/A&gt;" (GC=0)&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.cache Cache store &amp;lt;GUID=972f489502d74f49afdef7f38206e909&amp;gt;;CN=CENTRIFY NEGATIVE RESPONSE,CN=Person,DC=domain1,DC=LAN : update indexes Yes&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; base.objecthelper &lt;A href="mailto:'dersa@domain2.ch'" target="_blank"&gt;'dersa@domain2.ch'&lt;/A&gt; is not a canonical name&lt;BR /&gt;DEBUG &amp;lt;fd:34 CAPIGetObjectByName &amp;gt; daemon.ipcclient2 request 'CAPIGetObjectByName' complete&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999228#M181428</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2019-03-11T02:14:54Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999229#M181429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;I was now able to query user attributes from domain2, i had to provide the username in this format domain2\username. I believe this is the problem i am sending the username in the wrong format. If i would be able to modify the format from &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:username@domain.ch"&gt;username@domain.ch&lt;/A&gt;&lt;SPAN&gt; to domain\username everything would be fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 17:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999229#M181429</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2012-06-27T17:35:50Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999230#M181430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to see if the dns server is able to resolve the domain2, if you issue a nslookup for domain2 what do you show, do you receive any responses? I would start there and see what that turns up. Also what type of trust do you have enabled between domain1 and domain2, ISE uses kerberos to authenticate these users so we need to see if you have an external trust configured between these domains then authentication will fail since kerberos is not allowed. Please use a forest trust which allows kerberos and that should fix your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you were using acs 4.2 at one point then it would have worked because that uses ntlm auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an article for reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://setspn.blogspot.com/2009/09/ad-external-trusts-and-kerberos.html"&gt;http://setspn.blogspot.com/2009/09/ad-external-trusts-and-kerberos.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 17:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999230#M181430</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-27T17:45:56Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999231#M181431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tarik,&lt;/P&gt;&lt;P&gt;the trust type is forest Trust. As i mentioned, i was able to retrieve user attributes when i do it in the active directory configuration procedure. What matters at the moment is the format of the username. I have to send it as domai\username. But i can't achieve this with Binary Certificate Comparisation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 17:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999231#M181431</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2012-06-27T17:54:42Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999232#M181432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It looks like ISE is unable to contact the GC for domain2, are you able to resolve domain2? In the case you are able to resolve the name using netbios, now when you upn (&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:xxx@xxx.xx"&gt;xxx@xxx.xx&lt;/A&gt;&lt;SPAN&gt;) that requires dns to be operational since it looks up the dns domain and then sends the user request to the domain GC, my assumption is when you netbios it sends the request to domain1's GC and then it is able to authenticate the user through the trust. I am not an AD expert but I am assuming that is why one is working over the other.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When issue a dns query on the ISE cli for domain2 do you receive any GC's in the response?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;tarik admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 18:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999232#M181432</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-27T18:05:12Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999233#M181433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from the ISE cli i can nslookup domain2.lan and i get this result&lt;/P&gt;&lt;P&gt;nos-ch-wbn-ise1/admin# nslookup domain2.lan&lt;/P&gt;&lt;P&gt;Trying "domain2.lan"&lt;/P&gt;&lt;P&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 57373&lt;/P&gt;&lt;P&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 16, AUTHORITY: 0, ADDITIONAL: 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;;; QUESTION SECTION:&lt;/P&gt;&lt;P&gt;;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ANY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;;; ANSWER SECTION:&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.68.21&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.28.1.3&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.28.1.2&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.68.20&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; labdc01.lab.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; labdc02.lab.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; labex01.lab.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bsdehepdc01.domain2.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bsdehepfs01.domain2.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mordor.softlink.ch.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; shire.softlink.ch.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; labex02.lab.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; icm60.icm60domain.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bsfs02.domain2.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bsfs03.domain2.lan.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SOA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bsfs02.domain2.lan. admin.domain2.lan. 217091 900 600 86400 3600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;;; ADDITIONAL SECTION:&lt;/P&gt;&lt;P&gt;labdc01.lab.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.28.2.196&lt;/P&gt;&lt;P&gt;bsdehepdc01.domain2.lan. 311 IN&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.68.20&lt;/P&gt;&lt;P&gt;bsdehepfs01.domain2.lan. 2771 IN&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.68.21&lt;/P&gt;&lt;P&gt;bsfs02.domain2.lan. 1649&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.28.1.2&lt;/P&gt;&lt;P&gt;bsfs03.domain2.lan. 595&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.28.1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i assume dns is working fine.&lt;/P&gt;&lt;P&gt;Do i have to see the GC of the trusted domain as well in the ISE Active Directory Configuration ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks &amp;amp; regards&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 18:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999233#M181433</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2012-06-27T18:17:14Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999234#M181434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The best thing at this point is to open a SR with TAC since the nslookup commands wont allow you to look for GCs through the cli. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you are looking for a quick solution what you can do is configure the second domain as an ldap instance since you are using eap-tls. Then you can create and identity store sequence that will check AD then LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did notice the following replies:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mordor.softlink.ch.&lt;/P&gt;&lt;P&gt;domain2.lan.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; shire.softlink.ch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know why these servers are being sent in the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 18:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999234#M181434</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-27T18:27:22Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999235#M181435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tarik,&lt;/P&gt;&lt;P&gt;those are external servers from our provider, i have to verify with them why this is like it is. At the moment i have multiple ldap in the production environment with my ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't if i can open tac cases with eval versions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'll try&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 18:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999235#M181435</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2012-06-27T18:34:41Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1 EAP-TLS User Authentication in Multiforest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999236#M181436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're you able to get the DNS info cleaned up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jul 2012 03:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-eap-tls-user-authentication-in-multiforest/m-p/1999236#M181436</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-01T03:35:39Z</dc:date>
    </item>
  </channel>
</rss>

