<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3902640#M470954</link>
    <description>&lt;P style="text-align: left;"&gt;Closing out on this one. I was able to successfully integrate AD by manually adjusting ISE clock in the CLI using the command "clock set"&lt;/P&gt;</description>
    <pubDate>Sun, 04 Aug 2019 09:49:14 GMT</pubDate>
    <dc:creator>bcotaz</dc:creator>
    <dc:date>2019-08-04T09:49:14Z</dc:date>
    <item>
      <title>Cannot join AD in ISE 2.4 | CLOCK_SKEW</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900178#M470903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to join my AD in ISE but getting an error.&lt;/P&gt;
&lt;P&gt;ISE is at 2.4&lt;/P&gt;
&lt;P&gt;AD is Microsoft Server 2016&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Here is the complete error:&lt;/FONT&gt;&lt;/P&gt;
&lt;TABLE width="796"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="796"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Result for ISE node:&amp;nbsp;&lt;STRONG&gt;&lt;A href="http://ise.securitydemo.net/" target="_blank"&gt;ise.securitydemo.net&lt;/A&gt;&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="796"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Status:&amp;nbsp;&lt;STRONG&gt;Join Operation Failed: Clock skew detected with active directory server&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Error Description: Clock Skew Detected With Active Directory Server&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Support Details...&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Error Name: LW_ERROR_CLOCK_SKEW&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Error Code: 40087&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Detailed Log:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;08:53:12 Joining To Domain &lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="http://meralcomeraki.com/" target="_blank"&gt;MXXXAKI&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="http://meralcomeraki.com/" target="_blank"&gt;.COM&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt; Using User Administrator&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;08:53:12&amp;nbsp;&amp;nbsp;&amp;nbsp;Searching For DC In Domain &lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="http://meralcomeraki.com/" target="_blank"&gt;MXXXAKI&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="http://meralcomeraki.com/" target="_blank"&gt;.COM&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;08:53:12&amp;nbsp;&amp;nbsp;&amp;nbsp;Found DC: &lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="http://win-3ce3a93d7r1.meralcomeraki.com/" target="_blank"&gt;WIN-3CE3A93D7R1.&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="http://win-3ce3a93d7r1.meralcomeraki.com/" target="_blank"&gt;mxxxaki&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="http://win-3ce3a93d7r1.meralcomeraki.com/" target="_blank"&gt;.com&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt; , Client Site Is Default-First-Site-Name , Dc Site Is Default-First-Site-Name &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;08:53:12&amp;nbsp;&amp;nbsp;&amp;nbsp;Checking Credentials For User Administrator&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;08:53:12&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Getting TGT For Account &lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="mailto:Administrator@MERALCOMERAKI.COM" target="_blank"&gt;Administrator@&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="mailto:Administrator@MERALCOMERAKI.COM" target="_blank"&gt;MXXXAKI&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;A href="mailto:Administrator@MERALCOMERAKI.COM" target="_blank"&gt;.COM&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've set up my AD as the NTP and DNS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's a screen capture of show NTP in ISE.&lt;/P&gt;
&lt;P&gt;I've also set Root Dispersion to zero already, please see attached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Brian&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 16:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900178#M470903</guid>
      <dc:creator>bcotaz</dc:creator>
      <dc:date>2019-07-30T16:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900199#M470904</link>
      <description>Your ISE isn't in Sync with your NTP server as you can see that the selected time source is not your NTP server. Check if your NTP server is up and running. Are there any devices that are in sync with your NTP server? Check this if it helps . &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119371-technote-ise-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119371-technote-ise-00.html&lt;/A&gt;</description>
      <pubDate>Tue, 30 Jul 2019 17:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900199#M470904</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-30T17:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900659#M470906</link>
      <description>Hi Serendra,&lt;BR /&gt;&lt;BR /&gt;I tried using google NTP server already, but my current time source is still 127.127.1.0.&lt;BR /&gt;Any idea how to force the ISE NTP to my configured google ntp server?&lt;BR /&gt;Screenshot below.&lt;BR /&gt;&lt;BR /&gt;[cid:image001.png@01D547DB.DF7C8FB0]&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Brian&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 31 Jul 2019 12:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900659#M470906</guid>
      <dc:creator>bcotaz</dc:creator>
      <dc:date>2019-07-31T12:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900820#M470908</link>
      <description>&lt;P&gt;127.127.1.0 is always listed first.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ntp.png" style="width: 724px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/42238i99FC7353676C1C11/image-dimensions/724x169?v=v2" width="724" height="169" role="button" title="ntp.png" alt="ntp.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 15:41:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3900820#M470908</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-31T15:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3902640#M470954</link>
      <description>&lt;P style="text-align: left;"&gt;Closing out on this one. I was able to successfully integrate AD by manually adjusting ISE clock in the CLI using the command "clock set"&lt;/P&gt;</description>
      <pubDate>Sun, 04 Aug 2019 09:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3902640#M470954</guid>
      <dc:creator>bcotaz</dc:creator>
      <dc:date>2019-08-04T09:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3996493#M470957</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The time you put was with seconds?&lt;/P&gt;&lt;P&gt;Did it require a restart after the command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 13:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3996493#M470957</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2019-12-10T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3998914#M470960</link>
      <description>&lt;P&gt;An ISE service restart is recommended but not required. Yes, the command needs seconds specified. As long as the time differences are within 5 minutes, the AD join would usually work.&lt;/P&gt;
&lt;P&gt;Nonetheless, I would suggest to get a good time source, which is reachable within your infrastructure by both AD, ISE, and others, and have all their clocks synchronized to it. This makes it easier to look at the logs if we need to troubleshoot anything.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2019 17:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ad-in-ise-2-4-clock-skew/m-p/3998914#M470960</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-12-14T17:13:21Z</dc:date>
    </item>
  </channel>
</rss>

