<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.1 AD join fails in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788388#M224053</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you had these two connected before or is this the first time you are adding the AD to the ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rober E Roulhac Jr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Sep 2011 15:58:25 GMT</pubDate>
    <dc:creator>rroulhac</dc:creator>
    <dc:date>2011-09-12T15:58:25Z</dc:date>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788387#M224049</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to join my ACS 5.1 to my AD.&amp;nbsp; In the External Identity Stores &amp;gt; Active Directory I have put in the AD administrator details and hit the test button and the test succeeds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when I try to save changes it fails with an eror saying it can't connect to the LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error while configuring Active Directory:Error while configuring Active Directory:Unexpected LDAP Error Can't contact LDAP server&amp;nbsp; due to unexpected configuration or network error.Please try the --verbose option or run 'adinfo --diag' to diagnose the problem.Join to domain 'Mydomain.local', zone 'null' failed.&lt;/P&gt;&lt;P&gt;&lt;IMG src="file:/C:/DOCUME%7E1/Stevie/LOCALS%7E1/Temp/moz-screenshot.png" /&gt;&lt;IMG src="file:/C:/DOCUME%7E1/Stevie/LOCALS%7E1/Temp/moz-screenshot-1.png" /&gt;&lt;IMG src="file:/C:/DOCUME%7E1/Stevie/LOCALS%7E1/Temp/moz-screenshot-2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone seen this before. ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done this lots of times and never had any issue once the test connection succeeds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've checked the time and timezones on both ACS and AD and they are the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Stephen.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788387#M224049</guid>
      <dc:creator>StevieOliver_2</dc:creator>
      <dc:date>2019-03-11T01:23:37Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788388#M224053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you had these two connected before or is this the first time you are adding the AD to the ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rober E Roulhac Jr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 15:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788388#M224053</guid>
      <dc:creator>rroulhac</dc:creator>
      <dc:date>2011-09-12T15:58:25Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788389#M224055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I had these devices connected before and then I changed IP addresses of the DC and ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't understand why the test connection is successful then it fails to save the config.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS works fine from the DC and ACS.&amp;nbsp; They can both resolve each other's new IP ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Stephen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 16:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788389#M224055</guid>
      <dc:creator>StevieOliver_2</dc:creator>
      <dc:date>2011-09-12T16:13:13Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788390#M224056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like bug &lt;/P&gt;&lt;H6&gt;CSCtg49699&lt;/H6&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm going to upgrade to the latest 5.2 when I can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 20:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788390#M224056</guid>
      <dc:creator>StevieOliver_2</dc:creator>
      <dc:date>2011-09-12T20:19:46Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788391#M224057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you made changes tin the DNS server to resolve the new ip address of the DC to the DC Domain name?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you made sure the DC Domian Name that you have configured in the ACS is the same as the DC Domain Name that you have configured the DC server to have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS finds the DC by DNS lookup.&amp;nbsp; If you have changed the IP addresses although they might be able to ping one another due to the underlying network being configured correctly, if you have not gone in and changed the ip addressing in the DNS server to match the domain name of the DC to the new IP address this could also possibly cause the ACS to be able to ping the DC (which is why the test succeeds), but not be able to actually send or recieve actual data traffic from the DC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would check that as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert E Roulhac Jr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 13:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788391#M224057</guid>
      <dc:creator>rroulhac</dc:creator>
      <dc:date>2011-09-13T13:37:02Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788392#M224058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upgraded to the very latest 5.2 patch and still the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DNS would seem fine.&amp;nbsp; I can ping the ACS and AD from each other by name.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only possible clue I can see in a Wireshark capture is a couple of Kerberos errors.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KRB5KDC_ERR_ETYPE_NOSUPP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KRB5KRB_APP_ERR_SKEW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second one seems to indicate a time difference between ACS and AD but as far as I can see they are both the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't know if this is relevant but it is the only clue I can find.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 21:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788392#M224058</guid>
      <dc:creator>StevieOliver_2</dc:creator>
      <dc:date>2011-09-13T21:03:24Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788393#M224059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Fixed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured my DC as a timeserver and pointed ACS to the DC and it connected to the DC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least I've got the ACS upgraded to the latest version as a result of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 13:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788393#M224059</guid>
      <dc:creator>StevieOliver_2</dc:creator>
      <dc:date>2011-09-14T13:02:13Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 AD join fails</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788394#M224060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am glad you figured it out and do apologize for not being more responsive.&amp;nbsp; If there is anything else i could help with in the future let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert E Roulhac Jr&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:rroulhac@cisco.com"&gt;rroulhac@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 13:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-ad-join-fails/m-p/1788394#M224060</guid>
      <dc:creator>rroulhac</dc:creator>
      <dc:date>2011-09-14T13:37:06Z</dc:date>
    </item>
  </channel>
</rss>

