<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE adding Domain Controllers to black list in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602302#M517700</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the two domains showing no forest, it's probably due to ISE unable to discover such info through DNS and/or Global Catalog queries. As they are not used for authentications, it should have no impact without forest info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 24 Feb 2018 15:06:07 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-02-24T15:06:07Z</dc:date>
    <item>
      <title>ISE adding Domain Controllers to black list</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602300#M517698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have joined my ISE 2.3p1 to an AD forest which has two way trust relationship with a bunch of other AD forests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see below I have selectively white listed a subset of these forests for my Authentication.&amp;nbsp; Two of those non-white listed domains (cap and devcap) are causing ISE to complain.&lt;/P&gt;&lt;P&gt;Q1: Why do I constantly see this stuff in the ISE CLI logs?&amp;nbsp; I didn't &lt;EM&gt;blacklist&lt;/EM&gt; them, and I don't see this for any other domain that I haven't white listed either. What is the difference between&lt;EM&gt; blacklisting&lt;/EM&gt; and simply &lt;EM&gt;not using&lt;/EM&gt; them?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;06/02/2018 06:16:13,WARNING,140182414153472,&lt;SPAN style="color: #ff0000;"&gt;Added to black list&lt;/SPAN&gt;: &lt;SPAN style="color: #ff9900;"&gt;domain=devcap.********&lt;/SPAN&gt; DC=a04wndm31.devcap.******** addr=161.143.153.140 TTL=06:16:23 reason=Network,lwadvapi/threaded/dcmanager.cpp:269&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;06/02/2018 06:16:16,WARNING,140182414153472,&lt;SPAN style="color: #ff0000;"&gt;Added to black list&lt;/SPAN&gt;: &lt;SPAN style="color: #ff9900;"&gt;domain=cap.********&lt;/SPAN&gt; DC=a04wpdm61.cap.******** addr=161.143.155.22 TTL=06:16:26 reason=Network,lwadvapi/threaded/dcmanager.cpp:269&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;This stuff is clogging my Splunk database and those guys charge by the MB&lt;/SPAN&gt; &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/devil.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q2: I don't see a value for the Forest column for those two domains.&amp;nbsp; Is that a problem for ISE?&amp;nbsp; All the other domains have a forest value displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="115418" class="image-1 jive-image" height="663" src="https://community.cisco.com/legacyfs/online/fusion/115418_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" width="1125" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I ran Diagnostic Tool (all tests) and I got no errors at all.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2018 01:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602300#M517698</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-02-22T01:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE adding Domain Controllers to black list</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602301#M517699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE will blacklist a domain controller if there is some network error so that ISE does not&amp;nbsp; use the bad DC and discovery is triggered to find a better DC. &lt;/P&gt;&lt;P&gt;apart from any network connectivity issue, it is also possible that the firewall is dropping the packets.&lt;/P&gt;&lt;P&gt;More troubleshooting is needed here to find the case of this. Would suggest to engage TAC to find the root cause of it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be researching more for the 2nd question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2018 15:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602301#M517699</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-02-22T15:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE adding Domain Controllers to black list</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602302#M517700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the two domains showing no forest, it's probably due to ISE unable to discover such info through DNS and/or Global Catalog queries. As they are not used for authentications, it should have no impact without forest info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2018 15:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602302#M517700</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-24T15:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE adding Domain Controllers to black list</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602303#M517701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still seeing these SYSLOGs on a daily basis.&amp;nbsp; I have asked my customer about these two domains but no response yet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The constant SYSLOG events that I am seeing are (and related to the two domains I don't care about)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt;&amp;nbsp; &lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;AD&lt;/SPAN&gt;-&lt;SPAN class="t"&gt;Connector&lt;/SPAN&gt;&lt;/SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DC&lt;/SPAN&gt; &lt;SPAN class="t"&gt;removed&lt;/SPAN&gt; &lt;SPAN class="t"&gt;from&lt;/SPAN&gt; &lt;SPAN class="t"&gt;black&lt;/SPAN&gt; &lt;SPAN class="t"&gt;list&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;INFO &lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;AD&lt;/SPAN&gt;-&lt;SPAN class="t"&gt;Connector&lt;/SPAN&gt;&lt;/SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DC&lt;/SPAN&gt; &lt;SPAN class="t"&gt;added&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;black&lt;/SPAN&gt; &lt;SPAN class="t"&gt;list&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;AD&lt;/SPAN&gt;-&lt;SPAN class="t"&gt;Connector&lt;/SPAN&gt;&lt;/SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DC&lt;/SPAN&gt; &lt;SPAN class="t"&gt;discovery&lt;/SPAN&gt; &lt;SPAN class="t"&gt;failed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have joined ISE to a domain controller that has many two-way trust relationships.&lt;/P&gt;&lt;P&gt;I whitelisted only those domains that I can access for authentication.&lt;/P&gt;&lt;P&gt;I did NOT whitelist these two domains that are causing me grief.&amp;nbsp; Yet it seems that ISE is going behind my back and trying to be overly clever.&amp;nbsp; The result is a constant stream of SYSLOGs to Splunk.&amp;nbsp; Why can't it simply ignore the domains that I explicitly didn't whitelist?&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2018 03:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-adding-domain-controllers-to-black-list/m-p/3602303#M517701</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-04-04T03:55:41Z</dc:date>
    </item>
  </channel>
</rss>

