<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PassiveID add Domain Controller (missing DC) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3711281#M507471</link>
    <description>&lt;P&gt;checked with our AD admin, our DNS only resolve some of DC based on domain&lt;/P&gt;
&lt;P&gt;but ISE seems not to use API or similar cmd like" nltest /dclist:xxx.com" to resolve the DCs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this is the case, PassiveID wont work for lots cases especially when large amount DCs in the enterprise.&lt;/P&gt;
&lt;P&gt;No one will display 100 DCs based on domain name ....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Sep 2018 17:44:19 GMT</pubDate>
    <dc:creator>csco11552159</dc:creator>
    <dc:date>2018-09-21T17:44:19Z</dc:date>
    <item>
      <title>PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710704#M507466</link>
      <description>&lt;P&gt;Recently we are trying to add new DCs into PassiveID list to use WMI monitoring.&lt;/P&gt;
&lt;P&gt;The problems how ISE find the DCs, in our Dev environment, we found some DCs are missing from the list. and we have no way to add them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when use :&lt;/P&gt;
&lt;P&gt;nltest /dclist:dev&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will see 4 DCs.&lt;/P&gt;
&lt;P&gt;But from PassiveID "Add Domain Controllers" list, cannot find all of them.&lt;/P&gt;
&lt;P&gt;Then we test our production DCs, we have same issues, some "site" DCs are totally missing.&lt;/P&gt;
&lt;P&gt;Is some kind reasons about DC"Site" ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How does ISE find all DCs&amp;nbsp;available&amp;nbsp; to add?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 19:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710704#M507466</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-09-20T19:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710749#M507467</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like a configuration issue with AD. ISE gets the list of domain controllers when it joins the domain. There is no way to manually add DCs in ISE today.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 20:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710749#M507467</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-09-20T20:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710785#M507468</link>
      <description>&lt;P&gt;we saw the same result for other domains. it seems site impacted PassiveID DCs....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 21:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710785#M507468</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-09-20T21:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710851#M507469</link>
      <description>I would suspect some issue with AD sites and services and misconfiguration of AD infrastructure since ISE cannot see them. I would open a TAC case to start and work with Microsoft as well to see where the problem lies&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Sep 2018 02:01:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710851#M507469</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-21T02:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710900#M507470</link>
      <description>&lt;P&gt;Opened a ticket with TAC wait for some updates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Psn with passive ID enabled only see the "site" DC which are auto associated with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Passive wmi should see everything ..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 04:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3710900#M507470</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-09-21T04:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3711281#M507471</link>
      <description>&lt;P&gt;checked with our AD admin, our DNS only resolve some of DC based on domain&lt;/P&gt;
&lt;P&gt;but ISE seems not to use API or similar cmd like" nltest /dclist:xxx.com" to resolve the DCs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this is the case, PassiveID wont work for lots cases especially when large amount DCs in the enterprise.&lt;/P&gt;
&lt;P&gt;No one will display 100 DCs based on domain name ....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 17:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3711281#M507471</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-09-21T17:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3711309#M507472</link>
      <description>&lt;P&gt;I would think that ISE needs all domains in DNS to be able to resolve and work with them.&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26660"&gt;@Timothy Abbott&lt;/a&gt;&amp;nbsp;is our SME will await for him to confirm. Right now it sounds like as before will need to tune AD to work with ISE.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 18:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3711309#M507472</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-21T18:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID add Domain Controller (missing DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3712398#M507473</link>
      <description>&lt;P&gt;what if we deploy PSN to each "Site", witll ISE use site based DNS resolution to find all DC?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we do have all site based DNS resolution. If ISE is using this way, it should be able to see all DC at the "site".&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 19:27:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-add-domain-controller-missing-dc/m-p/3712398#M507473</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-09-24T19:27:50Z</dc:date>
    </item>
  </channel>
</rss>

