<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE AD failover in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169062#M418492</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've NOT tried that yet.&amp;nbsp; I do notice the followings:&amp;nbsp; AD1 is ad1.cciesec.com AD2 is ad2.cciesec.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ISE, it shows me that it is connected to ad1.cciesec.com.&amp;nbsp; When I shutdown ad1.cciesec.com, if I refresh the page, it shows me that it is connected to ad2.cciesec.com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Apr 2013 21:00:59 GMT</pubDate>
    <dc:creator>david.tran</dc:creator>
    <dc:date>2013-04-12T21:00:59Z</dc:date>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169056#M418484</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a ISE 1.1.3.124 VM operating in standalone mode that is authenticating devices against AD. The AD environment consists of multiple member servers, and while this is working fine, when the Domain controller that the ISE Displays it is connected to fails, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;LABEL&gt;In normal operating mode under External Identity Sources -&amp;gt; Active Directory the management web page displays the following status:&lt;/LABEL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;LABEL&gt;"Connected to: &lt;STRONG&gt;mydc01.mydomain.com&lt;/STRONG&gt;"&lt;/LABEL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when I shutdown the this domain controller, it displays the following status even there are more Domain Controllers in the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Joined to Domain but Disconnected"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the CLI config, I have added all of the Domain Controllers IP addresses using the "ip name-server" command &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now any authentications fail with the following message "&lt;A href="https://10.191.10.5/mntreport/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Fadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=24444+Active+Directory+operation+has+failed+because+of+an+unspecified+error+in+the+ISE&amp;amp;__locale=en_US&amp;amp;iportalID=QHLVSY&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: red; font-family: arial; background-color: #ebeff3; margin-top: 0pt;" target="_self"&gt;24444 Active Directory operation has failed because of an unspecified error in the ISE&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can the ISE be configured to look at more than 1 AD server?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate any help on this.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169056#M418484</guid>
      <dc:creator>steveklem</dc:creator>
      <dc:date>2019-03-11T03:17:25Z</dc:date>
    </item>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169057#M418485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could someone shed some light into this?&lt;/P&gt;&lt;P&gt;I'm curious as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both of our ISE nodes are joined to the same DC, even though I've tried leaving domain, and re-joining.&lt;/P&gt;&lt;P&gt;If a DC failure would disable the entire external ID store, we'd like to know if there's a wordaround.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Apr 2013 13:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169057#M418485</guid>
      <dc:creator>huangedmc</dc:creator>
      <dc:date>2013-04-10T13:45:47Z</dc:date>
    </item>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169058#M418486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This link might be helpfull&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_45_multiple_active_directories.pdf"&gt;http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_45_multiple_active_directories.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 06:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169058#M418486</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2013-04-11T06:38:43Z</dc:date>
    </item>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169059#M418487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for providing the link.&lt;/P&gt;&lt;P&gt;I've read that TrustSec2.1 guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While it provides instruction on how to allow ISE to communicate to multiple AD domain's, it does not address the specific issue that the OP and I have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When an ISE node joins to an AD domain, and says &lt;LABEL&gt;"Connected to: &lt;STRONG&gt;mydc01.mydomain.com&lt;/STRONG&gt;"&lt;/LABEL&gt;, why does ISE lose connection to the domain altogether, when "mydc01" fails, and there are other domain controllers available?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 13:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169059#M418487</guid>
      <dc:creator>huangedmc</dc:creator>
      <dc:date>2013-04-11T13:55:50Z</dc:date>
    </item>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169060#M418488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have ISE in VMWare standalone mode with IP address of 192.168.1.3 and AD1 server of 192.168.1.1 and AD2 server of 192.168.1.2 in Active Directory of CCIESEC.&amp;nbsp; I've successfully added ISE into the Active Directory and it is shown as "connected"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i shutdown AD1, I still can run the "detail test connection" on ISE to AD with AD1 offline without any issues.&amp;nbsp; The same thing when AD2 is offline and AD1 is online.&amp;nbsp; In other words, ISE function fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works with both ISE 1.1.2 patch-5 and 1.1.3 patch-1 in my test environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 19:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169060#M418488</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-04-12T19:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169061#M418490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks David, yes the detailed test does seem to work in this scenario (it did for me) but have you tried to actually authenticate a device against AD while it is down. This is when it fails.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 20:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169061#M418490</guid>
      <dc:creator>steveklem</dc:creator>
      <dc:date>2013-04-12T20:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169062#M418492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've NOT tried that yet.&amp;nbsp; I do notice the followings:&amp;nbsp; AD1 is ad1.cciesec.com AD2 is ad2.cciesec.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ISE, it shows me that it is connected to ad1.cciesec.com.&amp;nbsp; When I shutdown ad1.cciesec.com, if I refresh the page, it shows me that it is connected to ad2.cciesec.com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169062#M418492</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-04-12T21:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169063#M418494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve,&lt;/P&gt;&lt;P&gt;Have you opened a TAC case with Cisco on this?&amp;nbsp; This has definitely made me very nervous about this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169063#M418494</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-04-12T21:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169064#M418496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No I haven't yet David, thought I'd put it to the forum first, but like you said maybe I should.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:40:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169064#M418496</guid>
      <dc:creator>steveklem</dc:creator>
      <dc:date>2013-04-12T21:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169065#M418498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve,&lt;/P&gt;&lt;P&gt;What version of ISE are you running?&amp;nbsp; appliance or VM?&amp;nbsp; Can&amp;nbsp; you share the "show version output"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169065#M418498</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-04-12T21:43:00Z</dc:date>
    </item>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169066#M418500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running VM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show version" output below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt; Steve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Application Deployment Engine OS Release: 2.0&lt;/P&gt;&lt;P&gt;ADE-OS Build Version: 2.0.4.018&lt;/P&gt;&lt;P&gt;ADE-OS System Architecture: i386&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 2005-2011 by Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;All rights reserved.&lt;/P&gt;&lt;P&gt;Hostname: alxise01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Version information of installed applications&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Cisco Identity Services Engine&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.1.3.124&lt;/P&gt;&lt;P&gt;Build Date&amp;nbsp;&amp;nbsp; : Thu Feb&amp;nbsp; 7 17:55:38 2013&lt;/P&gt;&lt;P&gt;Install Date : Thu Mar 14 10:27:53 2013&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 00:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169066#M418500</guid>
      <dc:creator>steveklem</dc:creator>
      <dc:date>2013-04-15T00:39:34Z</dc:date>
    </item>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169067#M418502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An Active Directory Forest also has “Domain Resource Records” in DNS, which are required to locate a domain controller. It seems the additional domain controllers are having some issues with “Domain Resource Records” which you need to fix. When “Domain Resource Records” in Active Directory integrated DNS zone become corrupt, even the domain controller machine itself will be unable to find the Domain Controller for the AD Domain. Please check for any warning or error notifications in the event logs on Additional Domain Controllers, especially the netlogon service events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To fix those issues you may use the following utilities of Windows Support Tools:&lt;/P&gt;&lt;P&gt;Dcdiag&lt;/P&gt;&lt;P&gt;netdiag&lt;/P&gt;&lt;P&gt;portqry&lt;/P&gt;&lt;P&gt;nltest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 00:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169067#M418502</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-04-24T00:47:52Z</dc:date>
    </item>
    <item>
      <title>ISE AD failover</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169068#M418505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the verdict on this one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had an issue similar this morning on 1.2 with a failed DC and clients failing authentication to the ISE node bound to it, but not my other one that was bound to a different controller.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 20:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169068#M418505</guid>
      <dc:creator>ryan.lambert</dc:creator>
      <dc:date>2013-10-04T20:07:27Z</dc:date>
    </item>
    <item>
      <title>Bumping this thread...can</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169069#M418508</link>
      <description>&lt;P&gt;Bumping this thread...can someone please clarify how ISE handles the availability of the domain controllers in a windows domain?&lt;/P&gt;
&lt;P&gt;Server admins need to perform patches/maintenance/decommission of their AD servers, so it would be very beneficial to know exactly how ISE would behave in these cases.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 19:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-failover/m-p/2169069#M418508</guid>
      <dc:creator>CSCO10662744_2</dc:creator>
      <dc:date>2016-07-28T19:51:05Z</dc:date>
    </item>
  </channel>
</rss>

