<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE AD Domain Controller connection in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672905#M25372</link>
    <description>Not necessarily. I accidentally posted here instead of a separate, albeit somewhat related issue. Apologies.</description>
    <pubDate>Tue, 24 Jul 2018 10:13:58 GMT</pubDate>
    <dc:creator>rcheyfit</dc:creator>
    <dc:date>2018-07-24T10:13:58Z</dc:date>
    <item>
      <title>Cisco ISE AD Domain Controller connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672824#M25369</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have a redundant Cisco ISE deployment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ise1&lt;/P&gt;
&lt;P&gt;ise2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;AD domain (2 domain controllers)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ad1&lt;/P&gt;
&lt;P&gt;ad2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Normally&amp;nbsp;the ad connection looks like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ise1-ad&lt;U&gt;1&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;ise2-ad&lt;U&gt;2&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but sometimes like&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ise1-ad&lt;U&gt;1&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;ise2-ad&lt;U&gt;1&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone please tell me about his experience? Is this a normal behavior? In my opinion always both DCs should be connected or am I wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 08:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672824#M25369</guid>
      <dc:creator>Hkelling1988</dc:creator>
      <dc:date>2018-07-24T08:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD Domain Controller connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672884#M25370</link>
      <description />
      <pubDate>Tue, 24 Jul 2018 10:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672884#M25370</guid>
      <dc:creator>rcheyfit</dc:creator>
      <dc:date>2018-07-24T10:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD Domain Controller connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672886#M25371</link>
      <description>&lt;P&gt;I´m not sure if I understand correctly. Do you really think it´s a licensing topic?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 09:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672886#M25371</guid>
      <dc:creator>Hkelling1988</dc:creator>
      <dc:date>2018-07-24T09:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD Domain Controller connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672905#M25372</link>
      <description>Not necessarily. I accidentally posted here instead of a separate, albeit somewhat related issue. Apologies.</description>
      <pubDate>Tue, 24 Jul 2018 10:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3672905#M25372</guid>
      <dc:creator>rcheyfit</dc:creator>
      <dc:date>2018-07-24T10:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD Domain Controller connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3673451#M25373</link>
      <description>this is all determined by AD sites and services. would recommend you look through Cisco Live content by Chris Murray on the subject. &lt;BR /&gt;&lt;A href="https://www.ciscolive.com/global/on-demand-library/?search=chris%20murray#/session/14525434149870017MRf" target="_blank"&gt;https://www.ciscolive.com/global/on-demand-library/?search=chris%20murray#/session/14525434149870017MRf&lt;/A&gt;&lt;BR /&gt;What's new in ISE Active Directory connector - BRKSEC-2132&lt;BR /&gt;&lt;BR /&gt; If you need more debugging would recommend opening tac case</description>
      <pubDate>Tue, 24 Jul 2018 16:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3673451#M25373</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-07-24T16:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD Domain Controller connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3673512#M25374</link>
      <description>&lt;P&gt;What ISE is doing when picking up one DC or the other is perfectly expected.&lt;BR /&gt;To understand how this process takes place you can read the section "&lt;SPAN&gt;DC Discovery"&amp;nbsp;&lt;/SPAN&gt;from this document "Active Directory Integration with Cisco ISE 2.x":&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;DC Discovery&lt;BR /&gt;AD connector selects a domain controller (DC) for a given domain as follows:&lt;BR /&gt;&lt;BR /&gt;Performs a DNS SRV query (not scoped to a site) to get a full list of domain controllers in the domain.&lt;BR /&gt;Performs DNS resolution for DNS SRVs that lack IP addresses.&lt;BR /&gt;Sends CLDAP ping requests to domain controllers according to priorities in the SRV record and processes only the first response, if any. The CLDAP response contains the DC site and client site (for example, site to which the Cisco ISE machine is assigned).&lt;BR /&gt;If the DC site and client site are the same, the response originator (that is, DC) is selected.&lt;BR /&gt;If the DC site and client site are not the same, the AD Connector performs a DNS SRV query scoped to the discovered client site, gets the list of domain controllers serving the client site, sends CLDAP ping requests to these domain controllers, and processes only the first response, if any. The response originator (that is, DC) is selected. If there is no DC in the client's site serving the site or no DC currently available in the site, then the DC detected in Step 2 is selected.&lt;BR /&gt;You can influence the domain controllers that Cisco ISE uses by creating and using an Active Directory site. See the Microsoft Active Directory documentation on how to create and use sites.&lt;BR /&gt;Cisco ISE also provides the ability to define a list of preferred DCs per domain. This list of DCs will be prioritized for selection before DNS SRV queries. But this list of preferred DCs is not an exclusive list. If the preferred DCs are unavailable, other DCs are selected. You can create a list of preferred DCs in the following cases:&lt;BR /&gt;&lt;BR /&gt;The SRV records are bad, missing or not configured.&lt;BR /&gt;The site association is wrong or missing or the site cannot be used.&lt;BR /&gt;The DNS configuration is wrong or cannot be edited.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 17:12:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-domain-controller-connection/m-p/3673512#M25374</guid>
      <dc:creator>jalemanp</dc:creator>
      <dc:date>2018-07-24T17:12:46Z</dc:date>
    </item>
  </channel>
</rss>

