<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You're welcome. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010480#M22621</link>
    <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;Yes I believe it did.&lt;/P&gt;
&lt;P&gt;However ISE1.x is getting quite old. 1.4 was released over 2 years ago and many many improvements have been made since then. The whole AD connector and related serviceability features was revamped in 2.x. Anybody using that feature in any robust sense would be well-served to migrate to the current release (2.2 patch 1).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jun 2017 03:24:58 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-06-04T03:24:58Z</dc:date>
    <item>
      <title>ISE not seeing deep enough into AD structure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010475#M22611</link>
      <description>&lt;P&gt;Hi all; I have no experience with ISE but am trying to help out some folks who are using the tool.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They are trying to pull info out of AD in our heavily nested structure, but can't see further than SIX levels deep. We have end-user machines in OUs that are EIGHT deep. Here it is, with some of the names changed for privacy reasons&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;OU=&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="color: red;"&gt;Windows10&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: #1f497d;"&gt;,OU=Client Devices,OU=xx.yyy.zzz,OU=Infrastructure Services,DC=PROD,DC=aaa,DC=bbb,DC=GOV&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;The folks using the tool report they can only see to the "OU=xx.yyy.zzz" level - they can't see "OU=Client Devices" or "OU=Windows10".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The error they are getting:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;Could not find SID for group: '&amp;lt;hidden&amp;gt;/Infrastructure Services/&amp;lt;hidden&amp;gt;/Client Devices/Windows10'. Specific error is: 'The group name is invalid'.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010475#M22611</guid>
      <dc:creator />
      <dc:date>2019-03-11T07:45:49Z</dc:date>
    </item>
    <item>
      <title>  </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010476#M22613</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Please re-post in Security -&amp;gt; &amp;nbsp;&lt;STRONG&gt;AAA Identity and NAC&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 15:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010476#M22613</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2017-06-02T15:30:46Z</dc:date>
    </item>
    <item>
      <title>Done.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010477#M22615</link>
      <description>&lt;P&gt;Done.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 17:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010477#M22615</guid>
      <dc:creator />
      <dc:date>2017-06-02T17:53:56Z</dc:date>
    </item>
    <item>
      <title>What version of ISE are you</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010478#M22617</link>
      <description>&lt;P&gt;What version of ISE are you using? In 2.0 and later you can specify the OU and join point explicitly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jun 2017 08:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010478#M22617</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-03T08:24:58Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin; not sure, I'm</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010479#M22619</link>
      <description>&lt;P&gt;Thanks Marvin; not sure, I'm the middleman. I will ask them first thing Monday morning.&lt;/P&gt;
&lt;P&gt;But, do you know if versions PRIOR to 2.0 had a limitation insofar as how many levels deep they can query down into?&lt;/P&gt;
&lt;P&gt;Thanks again...&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jun 2017 18:18:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010479#M22619</guid>
      <dc:creator />
      <dc:date>2017-06-03T18:18:22Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010480#M22621</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;Yes I believe it did.&lt;/P&gt;
&lt;P&gt;However ISE1.x is getting quite old. 1.4 was released over 2 years ago and many many improvements have been made since then. The whole AD connector and related serviceability features was revamped in 2.x. Anybody using that feature in any robust sense would be well-served to migrate to the current release (2.2 patch 1).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2017 03:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-seeing-deep-enough-into-ad-structure/m-p/3010480#M22621</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-04T03:24:58Z</dc:date>
    </item>
  </channel>
</rss>

