<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE-PIC AD DS (global vs site based SRV request) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-pic-ad-ds-global-vs-site-based-srv-request/m-p/3751104#M487860</link>
    <description>&lt;P&gt;uys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My client is trying to integrate ISE-PIC with AD (for Passive auth) with “FMC”.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;I&lt;/EM&gt;&lt;SPAN&gt;n the ISE-PIC Admin guide, I read &lt;EM&gt;"You might not be able to join Cisco ISE-PIC with an Active Directory domain if the DNS SRV records are missing &lt;/EM&gt;&lt;/SPAN&gt;(the domain controllers do not advertise their SRV records for the domain that you are trying to join to)"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I sent this to my client, he replied with "&lt;SPAN&gt;That is our problem. Not all DCs can be resolved by &lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;global DNS SRV records&lt;/U&gt;.&lt;/EM&gt;&lt;/STRONG&gt; But &lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;we have all SRV records based by sites"&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have reached my AD DS knowledge on this last one.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to address that issue on ISE-PIC?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Sam&lt;/P&gt;</description>
    <pubDate>Thu, 22 Nov 2018 01:11:24 GMT</pubDate>
    <dc:creator>Samuel Vuillaume</dc:creator>
    <dc:date>2018-11-22T01:11:24Z</dc:date>
    <item>
      <title>ISE-PIC AD DS (global vs site based SRV request)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-ad-ds-global-vs-site-based-srv-request/m-p/3751104#M487860</link>
      <description>&lt;P&gt;uys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My client is trying to integrate ISE-PIC with AD (for Passive auth) with “FMC”.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;I&lt;/EM&gt;&lt;SPAN&gt;n the ISE-PIC Admin guide, I read &lt;EM&gt;"You might not be able to join Cisco ISE-PIC with an Active Directory domain if the DNS SRV records are missing &lt;/EM&gt;&lt;/SPAN&gt;(the domain controllers do not advertise their SRV records for the domain that you are trying to join to)"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I sent this to my client, he replied with "&lt;SPAN&gt;That is our problem. Not all DCs can be resolved by &lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;global DNS SRV records&lt;/U&gt;.&lt;/EM&gt;&lt;/STRONG&gt; But &lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;we have all SRV records based by sites"&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have reached my AD DS knowledge on this last one.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to address that issue on ISE-PIC?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 01:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-ad-ds-global-vs-site-based-srv-request/m-p/3751104#M487860</guid>
      <dc:creator>Samuel Vuillaume</dc:creator>
      <dc:date>2018-11-22T01:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-PIC AD DS (global vs site based SRV request)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-ad-ds-global-vs-site-based-srv-request/m-p/3764454#M487862</link>
      <description>&lt;P&gt;I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Dec 2018 03:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-ad-ds-global-vs-site-based-srv-request/m-p/3764454#M487862</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-16T03:50:14Z</dc:date>
    </item>
  </channel>
</rss>

