<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS DC discovery failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-dc-discovery-failure/m-p/3986597#M455539</link>
    <description>&lt;P&gt;When ACS or ISE are connected to Active Directory, they behave just like any Windows client.&amp;nbsp; They use DNS to find the closest domain controller (assuming AD Sites &amp;amp; Services is configured properly in AD).&amp;nbsp; It also gets a list of all domain controllers and tests connectivity to them on a regular basis to know which ones are alive for authentication.&amp;nbsp; I don't think you can turn off those messages because if you did, it would apply to all domain controllers and not just specific ones.&amp;nbsp; I assume that there is a firewall or similar blocking access to the other 4 domain controllers.&amp;nbsp; So this will continue to happen.&lt;/P&gt;&lt;P&gt;If you want ISE or ACS to use only 2 specific domain controllers, you can have them configure AD Sites &amp;amp; Services where the 2 domain controllers are in a separate site along with the ACS/ISE management IP addresses.&amp;nbsp; Those entries into Sites &amp;amp; Services can be /32 addresses.&amp;nbsp; Then open up the firewall to the other domain controllers to get rid of the alarms.&amp;nbsp; ISE will then prefer the 2 domain controllers in the same site and will only fail over to the other 4 domain controllers if the first 2 are unavailable.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2019 14:18:05 GMT</pubDate>
    <dc:creator>Colby LeMaire</dc:creator>
    <dc:date>2019-11-20T14:18:05Z</dc:date>
    <item>
      <title>ACS DC discovery failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-dc-discovery-failure/m-p/3986395#M455531</link>
      <description>&lt;P&gt;We have two ACS 5.8.1.4 servers, working in replication, and 6 Domain Controllers. The project plans provide for the integration of ACS servers with only two of the 6 DCs.&lt;/P&gt;&lt;P&gt;After configuration, ACS primary and secondary are joined and connected with 2 of the 6 domain controllers. Tab Users and Identity Stores &amp;gt; External Identity Stores &amp;gt; Active Directory display all 6 DC hosts after running ACS AD troubleshooting test in web gui.&lt;/P&gt;&lt;P&gt;ACS periodically generates logs “DC discovery failed” (see screenshot). We assume that ACS generates errors due to the availability of the remaining 4 DCs.&lt;/P&gt;&lt;P&gt;What is the cause of this error and how to configure ACS not to generate “DC discovery failure” error?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="4E4F1C46-3E40-4344-966C-30F0D349A3EA.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/61911i40E884EC8050EB01/image-size/large?v=v2&amp;amp;px=999" role="button" title="4E4F1C46-3E40-4344-966C-30F0D349A3EA.jpeg" alt="4E4F1C46-3E40-4344-966C-30F0D349A3EA.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 06:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-dc-discovery-failure/m-p/3986395#M455531</guid>
      <dc:creator>ViktorVik36163</dc:creator>
      <dc:date>2019-11-20T06:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACS DC discovery failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-dc-discovery-failure/m-p/3986597#M455539</link>
      <description>&lt;P&gt;When ACS or ISE are connected to Active Directory, they behave just like any Windows client.&amp;nbsp; They use DNS to find the closest domain controller (assuming AD Sites &amp;amp; Services is configured properly in AD).&amp;nbsp; It also gets a list of all domain controllers and tests connectivity to them on a regular basis to know which ones are alive for authentication.&amp;nbsp; I don't think you can turn off those messages because if you did, it would apply to all domain controllers and not just specific ones.&amp;nbsp; I assume that there is a firewall or similar blocking access to the other 4 domain controllers.&amp;nbsp; So this will continue to happen.&lt;/P&gt;&lt;P&gt;If you want ISE or ACS to use only 2 specific domain controllers, you can have them configure AD Sites &amp;amp; Services where the 2 domain controllers are in a separate site along with the ACS/ISE management IP addresses.&amp;nbsp; Those entries into Sites &amp;amp; Services can be /32 addresses.&amp;nbsp; Then open up the firewall to the other domain controllers to get rid of the alarms.&amp;nbsp; ISE will then prefer the 2 domain controllers in the same site and will only fail over to the other 4 domain controllers if the first 2 are unavailable.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 14:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-dc-discovery-failure/m-p/3986597#M455539</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-11-20T14:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACS DC discovery failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-dc-discovery-failure/m-p/3995618#M455546</link>
      <description>&lt;OL&gt;&lt;LI&gt;&lt;SPAN class="s1"&gt;A firewall and network access is open for all 6 DCs, but messages are still going. Tests connectivity from ACS to all DCs are OK. So what we need to do to stop those messages?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="s1"&gt;ACS configured with the ‘ip name server’ command for only 2 of 6 IPs of Domain Controllers (also DNS roles). System shows that 3 ‘ip name server’ is the max value. So how to configure all 6 DNS servers on ACS ?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 09 Dec 2019 06:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-dc-discovery-failure/m-p/3995618#M455546</guid>
      <dc:creator>ViktorVik36163</dc:creator>
      <dc:date>2019-12-09T06:06:01Z</dc:date>
    </item>
  </channel>
</rss>

