<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic James, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955827#M37694</link>
    <description>&lt;P&gt;James,&lt;/P&gt;
&lt;P&gt;You can have multiple AD joint points for different domains. &amp;nbsp;You can use those as store sequence in case of one AD failover.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;ps : rate if it helps!!!&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2016 12:37:26 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2016-11-07T12:37:26Z</dc:date>
    <item>
      <title>ISE 2.1 LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955824#M37690</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We are running ISE 2.1 Patch 1 and ran into an interesting problem yesterday where our Primary PSN dis-joined from the domain which meant our&amp;nbsp;SOE machines were failing 802.1X and falling back to MAB.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are&amp;nbsp;there any other failover mechanisms for AD authentication (short of failing over to the secondary PSN) that we can implement if this was to happen again?&amp;nbsp; Has this happened to anyone before?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:12:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955824#M37690</guid>
      <dc:creator>James Paton</dc:creator>
      <dc:date>2019-03-11T07:12:31Z</dc:date>
    </item>
    <item>
      <title>Hi James,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955825#M37691</link>
      <description>&lt;P&gt;Hi James,&lt;/P&gt;
&lt;P&gt;If your PSN got disconnected from AD domain. But the PSN is still active. Failover will happen when primary PSN gets down then it will failover to next configured PSN on NAD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;However, if you can use identity store sequence in ISE in order to move from AD to LDAP/internal/RSA as per your configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps!!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;ps : rate if it helps!!!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 08:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955825#M37691</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-11-07T08:53:17Z</dc:date>
    </item>
    <item>
      <title>Hi Gagan,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955826#M37693</link>
      <description>&lt;P&gt;Hi Gagan,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What if we are only using AD, what are our options if our primary PSN is removed from the domain and the node is still active?&amp;nbsp; Can we use different AD join points or sequences?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 10:00:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955826#M37693</guid>
      <dc:creator>James Paton</dc:creator>
      <dc:date>2016-11-07T10:00:34Z</dc:date>
    </item>
    <item>
      <title>James,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955827#M37694</link>
      <description>&lt;P&gt;James,&lt;/P&gt;
&lt;P&gt;You can have multiple AD joint points for different domains. &amp;nbsp;You can use those as store sequence in case of one AD failover.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;ps : rate if it helps!!!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 12:37:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955827#M37694</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-11-07T12:37:26Z</dc:date>
    </item>
    <item>
      <title>Thanks Gagan,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955828#M37695</link>
      <description>&lt;P&gt;Thanks Gagan,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;LDAP looks like it will overcome and provide a failover if the PSN is dis-joined from the domain.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 20:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955828#M37695</guid>
      <dc:creator>James Paton</dc:creator>
      <dc:date>2016-11-07T20:22:21Z</dc:date>
    </item>
    <item>
      <title>Your welcome:).</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955829#M37696</link>
      <description>&lt;P&gt;Your welcome:).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 20:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-ldap/m-p/2955829#M37696</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-11-07T20:29:00Z</dc:date>
    </item>
  </channel>
</rss>

