<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secondary ACS Unable to Join Domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879647#M294139</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to de-register the secondary ACS from the primary unit. With the secondary as standalone you should delete any references from AD configuration on the ACS Access Services (In Example: AD Group Conditions, AD Attributes), Authorization Profiles, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After removing the AD References on the ACS GUI Configuration please go under the Active Directory configuration and click on "Clear Configuration". NOTE: You might want to confirm that you have the AD account credentials to join the ACS back to the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After clearing the AD configuration we should configure it again from scratch, click on "Test Connection" and if succeded click on "Save Changes".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS should show as Connected and Joined. At this point you can register the unit back to the primary for it to take the secondary role again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If deeper investigation is needed or the issue persists the best approach would be to open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Dec 2011 22:55:43 GMT</pubDate>
    <dc:creator>camejia</dc:creator>
    <dc:date>2011-12-22T22:55:43Z</dc:date>
    <item>
      <title>Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879646#M294138</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two ACS 5.3 servers setup as primary and secondary. The Primary is joined to the domain and works without issue. The secondary server shows as connectivity status:disconnected under the AD configuration. If I test the connection using the username and passwords credentials it is successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the command line when I run the show app status acs command the adclient process results in execution failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-John&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879646#M294138</guid>
      <dc:creator>jlizzio</dc:creator>
      <dc:date>2019-03-11T01:38:04Z</dc:date>
    </item>
    <item>
      <title>Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879647#M294139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to de-register the secondary ACS from the primary unit. With the secondary as standalone you should delete any references from AD configuration on the ACS Access Services (In Example: AD Group Conditions, AD Attributes), Authorization Profiles, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After removing the AD References on the ACS GUI Configuration please go under the Active Directory configuration and click on "Clear Configuration". NOTE: You might want to confirm that you have the AD account credentials to join the ACS back to the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After clearing the AD configuration we should configure it again from scratch, click on "Test Connection" and if succeded click on "Save Changes".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS should show as Connected and Joined. At this point you can register the unit back to the primary for it to take the secondary role again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If deeper investigation is needed or the issue persists the best approach would be to open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2011 22:55:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879647#M294139</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2011-12-22T22:55:43Z</dc:date>
    </item>
    <item>
      <title>Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879648#M294140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TAC reviewed our logs and determined that something was corrupt due to the upgrade process from 5.2 to 5.3. I rebuilt the VM as 5.3 and it joined the domain without issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jan 2012 18:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879648#M294140</guid>
      <dc:creator>jlizzio</dc:creator>
      <dc:date>2012-01-10T18:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879649#M294141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Community has become a very helpful forum, however, AD - ACS 5.x issue can become very complex sometimes. TAC involvement might be required on those type of queries. Thanks for the update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: Also, I prefer to suggest my customer's to go with a server re-image when upgrading to 5.3 instead of using the "Patch" file. The Patch file can become at handy sometimes when a re-image is not a viable option, however, the re-image will assure a clean installation. A restore of the previous ACS 5.2 database can be performed as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jan 2012 19:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879649#M294141</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-10T19:21:18Z</dc:date>
    </item>
    <item>
      <title>Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879650#M294142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;Is it possible that to rebuild only the adclient, as I'm facing the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;MKD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2012 09:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879650#M294142</guid>
      <dc:creator>mkdccie</dc:creator>
      <dc:date>2012-03-27T09:15:42Z</dc:date>
    </item>
    <item>
      <title>Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879651#M294143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had the same problem on ACS 5.2 on secondary server. The reason was simple, I did not configured NTP server so there was unsynchronised time with AD domain server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 10:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879651#M294143</guid>
      <dc:creator>petr.hon</dc:creator>
      <dc:date>2012-04-17T10:18:08Z</dc:date>
    </item>
    <item>
      <title>Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879652#M294144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi petr,&lt;/P&gt;&lt;P&gt;NTP is working fine, and when I click the "Test" it says "Success".&lt;/P&gt;&lt;P&gt;But the adclient is not running !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MKD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 10:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879652#M294144</guid>
      <dc:creator>mkdccie</dc:creator>
      <dc:date>2012-04-17T10:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879653#M294145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had same problem when trying to apply a patch with version 5.3.40.5. I had to de-apply patch, de-register backup from main ACS, apply path, and re-register backup with main ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only after that, adclient executed correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 19:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879653#M294145</guid>
      <dc:creator>Ivan Bermejo Chamorro</dc:creator>
      <dc:date>2012-05-29T19:43:53Z</dc:date>
    </item>
    <item>
      <title>Secondary ACS Unable to Join Domain</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879654#M294146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had faced same issue which is resolved by using domain credential to join AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deregister secondary ACS from primary and re-registered. which helped and found everything working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note : Please always check &lt;SPAN style="font-size: 10pt;"&gt;ACSADAgent.log in such issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2013 19:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879654#M294146</guid>
      <dc:creator>rameshwar.hiwale</dc:creator>
      <dc:date>2013-02-19T19:39:40Z</dc:date>
    </item>
    <item>
      <title>Thanks petr.hon, I jut</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879655#M294147</link>
      <description>&lt;P&gt;Thanks petr.hon, I jut configured the NTP server and everything works again.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Mar 2014 05:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-acs-unable-to-join-domain/m-p/1879655#M294147</guid>
      <dc:creator>habnercosta</dc:creator>
      <dc:date>2014-03-15T05:23:20Z</dc:date>
    </item>
  </channel>
</rss>

