<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AD Operational/Not Operational in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3700960#M507811</link>
    <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does ISE automatically leave from Active Directory domain and re-join during reboot if it is already joined?&lt;/P&gt;
&lt;P&gt;Does ISE periodically communicate with Active Directory DC after it joined to a domain?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I read "Active Directory Integration with Cisco ISE 2.x" below but it only describe behavior on application reset or configuration restore.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'When you reset the Cisco ISE application configuration from the command-line interface or restore configuration after a backup or upgrade, it performs a leave operation, disconnecting the Cisco ISE node from the Active Directory domain, if it is already joined.'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Background]&lt;/P&gt;
&lt;P&gt;My customer says they sometimes see "Not Operational" when checking AD integration status in [Administrator]-&amp;gt;[External Identity Source]-&amp;gt;AD domain after ISE reboot.&lt;/P&gt;
&lt;P&gt;They say there seems no impact to user authentication during "Not Operational", but asking why ISE changes its status.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Sep 2018 06:41:40 GMT</pubDate>
    <dc:creator>mick5kull</dc:creator>
    <dc:date>2018-09-05T06:41:40Z</dc:date>
    <item>
      <title>AD Operational/Not Operational</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3700960#M507811</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does ISE automatically leave from Active Directory domain and re-join during reboot if it is already joined?&lt;/P&gt;
&lt;P&gt;Does ISE periodically communicate with Active Directory DC after it joined to a domain?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I read "Active Directory Integration with Cisco ISE 2.x" below but it only describe behavior on application reset or configuration restore.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'When you reset the Cisco ISE application configuration from the command-line interface or restore configuration after a backup or upgrade, it performs a leave operation, disconnecting the Cisco ISE node from the Active Directory domain, if it is already joined.'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Background]&lt;/P&gt;
&lt;P&gt;My customer says they sometimes see "Not Operational" when checking AD integration status in [Administrator]-&amp;gt;[External Identity Source]-&amp;gt;AD domain after ISE reboot.&lt;/P&gt;
&lt;P&gt;They say there seems no impact to user authentication during "Not Operational", but asking why ISE changes its status.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 06:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3700960#M507811</guid>
      <dc:creator>mick5kull</dc:creator>
      <dc:date>2018-09-05T06:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: AD Operational/Not Operational</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3701331#M507812</link>
      <description>&lt;P&gt;If this is the behavior seen by your customer in production network, it is best handled by TAC. Please request your customer to open a TAC service request.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Krish&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 16:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3701331#M507812</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-09-05T16:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: AD Operational/Not Operational</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3701342#M507814</link>
      <description>&lt;P&gt;Also part of the reason your authentications may not be affected is because by default is the authentication process fails on a PSN, the PSN will drop the request and allow the NAD to fail over to the another PSN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As Krish said you definitely want to get a TAC case going.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 16:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3701342#M507814</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-05T16:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: AD Operational/Not Operational</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3701678#M507816</link>
      <description>&lt;P&gt;Thanks for your comment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand "Not Operational" status after ISE reboot is not expected behavior and need TAC assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any comments on below queries?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; Does ISE automatically leave from Active Directory domain and re-join during reboot if it is already joined?&lt;BR /&gt;&amp;gt; Does ISE periodically communicate with Active Directory DC after it joined to a domain?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If yes, I think customer and I should check network accessibility between ISE and AD controller more before open a SR on ISE.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 01:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-operational-not-operational/m-p/3701678#M507816</guid>
      <dc:creator>mick5kull</dc:creator>
      <dc:date>2018-09-06T01:23:09Z</dc:date>
    </item>
  </channel>
</rss>

