<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Falk, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949301#M38118</link>
    <description>&lt;P&gt;Hi Falk,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is AD connector status operational.&lt;/P&gt;
&lt;P&gt;Is it impacting any authentications in the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Put ad_agent to DEBUG level and then look for this error message in the&lt;/P&gt;
&lt;P&gt;"show acs-logs filename ACSADAgent.log | in LW_ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS"&lt;/P&gt;
&lt;P&gt;It might leads to permission issue for ISE as a computer account on AD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the documentation that shows more detailed information about AD Connector on ISE and the internal operations it takes which may help to understand what the DNS SRV records are used for and help us troubleshoot the issue. This document will have all useful information that shows what is required with ISE and AD integration as well.&lt;/P&gt;
&lt;P&gt;The document is found at: Cisco ISE &amp;gt; Active Directory Integration with Cisco ISE 1.3 &amp;gt; AD Connector Internal Operations&amp;lt; http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE-ADIntegration.html#reference_EA017E71F25145C9A1374373ABFA102E&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2016 15:22:25 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2016-09-29T15:22:25Z</dc:date>
    <item>
      <title>ISE -&gt; Warning: SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949300#M38117</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Our ISE servers today uses bind dns servers, but as a test we try to use our Active Directory DNS's as ISE dns servers.&lt;BR /&gt;In our test everything "works", but when doing a diag in&amp;nbsp;&lt;SPAN dojoattachpoint="breadcrumb_span" id="xwt_widget_layout_Breadcrumb_0" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;Active Directory&lt;SPAN class="xwtBreadcrumbSeparator"&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;ADM-AD&lt;SPAN class="xwtBreadcrumbSeparator"&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;Active Directory Diagnostic Tool we get a warning from:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" id="xwt_widget_layout_Breadcrumb_0" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;&lt;BR /&gt;DNS SRV record query :&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;Test Name :DNS SRV record query&lt;BR /&gt;Description :Query for DNS SRV record using resolv.conf configuration and gethostbyaddr&lt;BR /&gt;Instance :ADM-AD&lt;BR /&gt;Status :Warning&lt;BR /&gt;Start Time :10:46:37 29.09.2016 CEST&lt;BR /&gt;End Time :10:46:37 29.09.2016 CEST&lt;BR /&gt;Duration :&amp;lt;1 sec&lt;BR /&gt;Result and Remedy...&lt;BR /&gt;SRV record found.Not all SRV records have IP, will need to run additional query for get IP.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;Do you guys know what that warning really does behind the ui screen?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;There are really not much my googlefu returns with this search..&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" id="xwt_widget_layout_Breadcrumb_0" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;ISE:&lt;BR /&gt;Version: 1.4.0.253&lt;BR /&gt;Patch Information: 4&lt;BR /&gt;&lt;BR /&gt;AD:&lt;BR /&gt;Forest domain level 2008&lt;BR /&gt;On windows 2012 and 2008&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;BIND:&lt;BR /&gt;Bind 9.10.3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;And the only thing we see with a tcpdump differs is that the BIND dns returns AUTHORITY SECTION and the AD dns does not?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN dojoattachpoint="breadcrumb_span" widgetid="xwt_widget_layout_Breadcrumb_0" class="xwtBreadcrumb  nested   "&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast "&gt;Answer from a newly setup test&amp;nbsp;bind as a slave to the DC dns returns:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;falk@broekn ~$ dig _ldap._tcp.dc._msdcs.domain.local. SRV @10.8.10.105&lt;BR /&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.10.3-P4-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; _ldap._tcp.dc._msdcs.domain.local. SRV @10.8.10.105&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 10442&lt;BR /&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 2&lt;BR /&gt;&lt;BR /&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 4096&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;_ldap._tcp.dc._msdcs.domain.local. IN SRV&lt;BR /&gt;&lt;BR /&gt;;; ANSWER SECTION:&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 WIN-QE31DOEGABT.domain.local.&lt;BR /&gt;&lt;BR /&gt;;; AUTHORITY SECTION:&lt;BR /&gt;_msdcs.domain.local. 3600 IN NS win-qe31doegabt.domain.local.&lt;BR /&gt;&lt;BR /&gt;;; ADDITIONAL SECTION:&lt;BR /&gt;win-qe31doegabt.domain.local. 3600 IN A 10.8.10.108&lt;BR /&gt;;; Query time: 2 msec&lt;BR /&gt;;; SERVER: 10.8.10.105#53(10.8.10.105)&lt;BR /&gt;;; WHEN: Thu Sep 29 11:49:53 CEST 2016&lt;BR /&gt;;; MSG SIZE rcvd: 156&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;And this is the same question directly from the newly setup AD test dns server:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;falk@broekn ~$ dig _ldap._tcp.dc._msdcs.domain.local. SRV @10.8.10.108 1&lt;BR /&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.10.3-P4-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; _ldap._tcp.dc._msdcs.domain.local. SRV @10.8.10.108&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 44694&lt;BR /&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 2&lt;BR /&gt;&lt;BR /&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 4000&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;_ldap._tcp.dc._msdcs.domain.local. IN SRV&lt;BR /&gt;&lt;BR /&gt;;; ANSWER SECTION:&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 WIN-QE31DOEGABT.domain.local.&lt;BR /&gt;&lt;BR /&gt;;; ADDITIONAL SECTION:&lt;BR /&gt;WIN-QE31DOEGABT.domain.local. 3600 IN A 10.8.10.108&lt;BR /&gt;;; Query time: 1 msec&lt;BR /&gt;;; SERVER: 10.8.10.108#53(10.8.10.108)&lt;BR /&gt;;; WHEN: Thu Sep 29 11:51:40 CEST 2016&lt;BR /&gt;;; MSG SIZE rcvd: 126&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Regards Falk&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:07:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949300#M38117</guid>
      <dc:creator>Andreas Falk</dc:creator>
      <dc:date>2019-03-11T07:07:04Z</dc:date>
    </item>
    <item>
      <title>Hi Falk,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949301#M38118</link>
      <description>&lt;P&gt;Hi Falk,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is AD connector status operational.&lt;/P&gt;
&lt;P&gt;Is it impacting any authentications in the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Put ad_agent to DEBUG level and then look for this error message in the&lt;/P&gt;
&lt;P&gt;"show acs-logs filename ACSADAgent.log | in LW_ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS"&lt;/P&gt;
&lt;P&gt;It might leads to permission issue for ISE as a computer account on AD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the documentation that shows more detailed information about AD Connector on ISE and the internal operations it takes which may help to understand what the DNS SRV records are used for and help us troubleshoot the issue. This document will have all useful information that shows what is required with ISE and AD integration as well.&lt;/P&gt;
&lt;P&gt;The document is found at: Cisco ISE &amp;gt; Active Directory Integration with Cisco ISE 1.3 &amp;gt; AD Connector Internal Operations&amp;lt; http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE-ADIntegration.html#reference_EA017E71F25145C9A1374373ABFA102E&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 15:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949301#M38118</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-09-29T15:22:25Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949302#M38119</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;tnx for the debug tips.&lt;BR /&gt;After some debugging with dig, wireshark and lots of coffee we have located the problem (&lt;EM&gt;/me thinks)&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;We can reproduce the problem with dig and&amp;nbsp;+noedns option.&lt;/P&gt;
&lt;P&gt;The problem seems to be that we have 8 domain controller (we are migrating from 2008 to 2012) and the answer from the debug query get's "truncated" without edns.&amp;nbsp;&amp;nbsp;(no&amp;nbsp;truncated flag in the .pcap)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For us the diagnose warning probably goes away when we only have 5 domain controllers left after the migration is done.&amp;nbsp;Then the query answer should be smaller than 512 bytes, and no "truncation" should occur.&lt;/P&gt;
&lt;P&gt;The anonymised dig's below, and the debug log is attached:&lt;BR /&gt;&lt;BR /&gt;vanilla:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;falk@broekn ~$ dig _ldap._tcp.dc._msdcs.domain.local SRV @192.168.9.127 &lt;BR /&gt;&lt;BR /&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.10.3-P4-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; _ldap._tcp.dc._msdcs.domain.local SRV @192.168.9.127&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 54522&lt;BR /&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 8, AUTHORITY: 0, ADDITIONAL: 9&lt;BR /&gt;&lt;BR /&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 4000&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;_ldap._tcp.dc._msdcs.domain.local. IN SRV&lt;BR /&gt;&lt;BR /&gt;;; ANSWER SECTION:&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-12.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-05.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-08.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-10.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-07.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-09.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-11.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-06.domain.local.&lt;BR /&gt;&lt;BR /&gt;;; ADDITIONAL SECTION:&lt;BR /&gt;dc-12.domain.local. 3600 IN A 192.168.1.14&lt;BR /&gt;dc-05.domain.local. 3600 IN A 192.168.9.127&lt;BR /&gt;dc-08.domain.local. 3600 IN A 192.168.1.10&lt;BR /&gt;dc-10.domain.local. 3600 IN A 192.168.1.12&lt;BR /&gt;dc-07.domain.local. 3600 IN A 192.168.9.129&lt;BR /&gt;dc-09.domain.local. 3600 IN A 192.168.1.11&lt;BR /&gt;dc-11.domain.local. 3600 IN A 192.168.1.13&lt;BR /&gt;dc-06.domain.local. 3600 IN A 192.168.9.128&lt;BR /&gt;&lt;BR /&gt;;; Query time: 0 msec&lt;BR /&gt;;; SERVER: 192.168.9.127#53(192.168.9.127)&lt;BR /&gt;;; WHEN: Fri Sep 30 16:01:21 CEST 2016&lt;BR /&gt;;; MSG SIZE rcvd: 524&lt;/PRE&gt;
&lt;P&gt;+noedns:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;falk@broekn ~$ dig &lt;STRONG&gt;+noedns&lt;/STRONG&gt; _ldap._tcp.dc._msdcs.domain.local SRV @192.168.9.127 &lt;BR /&gt;&lt;BR /&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.10.3-P4-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; +noedns _ldap._tcp.dc._msdcs.domain.local SRV @192.168.9.127&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 35413&lt;BR /&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 8, AUTHORITY: 0, ADDITIONAL: 7&lt;BR /&gt;&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;_ldap._tcp.dc._msdcs.domain.local. IN SRV&lt;BR /&gt;&lt;BR /&gt;;; ANSWER SECTION:&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-05.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-08.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-10.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-07.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-09.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-11.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-06.domain.local.&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.local. 600 IN SRV 0 100 389 dc-12.domain.local.&lt;BR /&gt;&lt;BR /&gt;;; ADDITIONAL SECTION:&lt;BR /&gt;dc-05.domain.local. 3600 IN A 192.168.9.127&lt;BR /&gt;dc-08.domain.local. 3600 IN A 192.168.1.10&lt;BR /&gt;dc-10.domain.local. 3600 IN A 192.168.1.12&lt;BR /&gt;dc-07.domain.local. 3600 IN A 192.168.9.129&lt;BR /&gt;dc-09.domain.local. 3600 IN A 192.168.1.11&lt;BR /&gt;dc-11.domain.local. 3600 IN A 192.168.1.13&lt;BR /&gt;dc-06.domain.local. 3600 IN A 192.168.9.128&lt;BR /&gt;&lt;BR /&gt;;; Query time: 0 msec&lt;BR /&gt;;; SERVER: 192.168.9.127#53(192.168.9.127)&lt;BR /&gt;;; WHEN: Fri Sep 30 16:01:50 CEST 2016&lt;BR /&gt;;; MSG SIZE rcvd: 497&lt;/PRE&gt;
&lt;P&gt;So I guess that we have our usual bad luck&amp;nbsp;with both the names and number&amp;nbsp;of servers so this can happen &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;From my little dns knowledge the answer should be flagged as truncated and the question should be re-queried on tcp. &lt;BR /&gt;But the answer from the dc's is flagged with&amp;nbsp;"Message is not truncated".&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;--&lt;/P&gt;
&lt;P&gt;Regards Falk&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 15:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949302#M38119</guid>
      <dc:creator>Andreas Falk</dc:creator>
      <dc:date>2016-09-30T15:05:08Z</dc:date>
    </item>
    <item>
      <title>Hi Falk,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949303#M38120</link>
      <description>&lt;P&gt;Hi Falk,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You are correct about DNS resolution in terms of packet length.&lt;/P&gt;
&lt;P&gt;TCP &amp;lt; 512&lt;/P&gt;
&lt;P&gt;UDP &amp;gt; 512&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Also it's recommended if you do an upgrade on DC side, you need to rejoin ISE with AD for best practices.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;ps: rate if it helps!!!!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 15:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-gt-warning-srv-record-found-not-all-srv-records-have-ip-will/m-p/2949303#M38120</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-09-30T15:32:15Z</dc:date>
    </item>
  </channel>
</rss>

