<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE LDAP integration without Groups? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450855#M518222</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arnie, Have you tried using default values for groups?&amp;nbsp;&amp;nbsp; I just tested with invalid object names for groups and even for search space and was able to bind successfully and perform a test auth against LDAP server.&amp;nbsp; I was not able to add groups, but attributes did appear and were retrieved in test auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, if existing behavior not working and requesting change in the design, then suggest submitting an enhancement request to Tal Surasky as the PM for AAA and Id Stores.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Feb 2018 05:20:27 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-02-07T05:20:27Z</dc:date>
    <item>
      <title>ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450847#M518214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ISE LDAP experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am integrating to an LDAP directory that does not contain any groups.&amp;nbsp; I have also been given a restricted view of the users in the directory (I can only see their UID).&amp;nbsp;&amp;nbsp; When I bind to this directory using ISE 2.3 patch 2, I get:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;Ldap bind succeeded to iddiraaa.education.local:636&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900; font-size: 8pt; font-family: courier new,courier;"&gt;Subject search ended with an error.Please check search base configured properly&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900; font-size: 8pt; font-family: courier new,courier;"&gt;Group search ended with an error.Please check search base configured properly&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;Response time 265ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Subject Search Base: CN=Person,DC=IDDir&lt;/P&gt;&lt;P&gt;My Group Search Base: CN=Person,DC=IDDir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I click on the button "Naming Contexts..." next to each search base, ISE reports "No suggestions from server"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I bind using Windows ldaps with same credentials, I can view the users just fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I read in the ISE Admin Guide that ISE expects to see Groups in the LDAP directory:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Is there any way around that?&amp;nbsp; Do I need a dummy group perhaps and make all users members of that dummy group?&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Is there a log I can trawl to see what's going on under the covers?&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114899_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 23:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450847#M518214</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-01-29T23:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450848#M518215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try DEBUG on prrt-JNI, AAA-runtime, AAA-config. And, check prrt-server.log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 23:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450848#M518215</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-29T23:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450849#M518216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for that!&lt;/P&gt;&lt;P&gt;After some scratching of my head I figured out this had to be done on the PAN, and not the PSN &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran debug while clicking on "Test Bind to Server"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two lines in bold look promising - but doesn't give me much to go on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,305,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.writeData - success,SSLConnection.cpp:1077&lt;/P&gt;&lt;P&gt;ConnectionHandler,2018-01-30 09:40:29,308,DEBUG,0x7f3f03c96700,LdapTestBindConnectionHandler::handle_input called,LdapTestBindConnectionHandler.cpp:109&lt;/P&gt;&lt;P&gt;ConnectionHandler,2018-01-30 09:40:29,308,DEBUG,0x7f3f03c96700,LdapTestBindConnectionHandler::fetchBindResponse called,LdapTestBindConnectionHandler.cpp:391&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,308,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.readData - nInDataSize=0, entity=client,SSLConnection.cpp:835&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,308,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.readData - output-size=22,SSLConnection.cpp:917&lt;/P&gt;&lt;P&gt;Connection,2018-01-30 09:40:29,308,DEBUG,0x7f3f03c96700,LdapBindResponse::update: bind result = 0 (Success),LdapConnectionResponses.cpp:106&lt;/P&gt;&lt;P&gt;Connection,2018-01-30 09:40:29,309,DEBUG,0x7f3f03c96700,LdapBindResponse::update: password policy control is not returned by the server,LdapConnectionResponses.cpp:140&lt;/P&gt;&lt;P&gt;Connection,2018-01-30 09:40:29,309,INFO ,0x7f3f03c96700,LdapSslConnectionContext:sslConnectionEstablished: flag certificate send is true,LdapSslConnectionContext.cpp:402&lt;/P&gt;&lt;P&gt;ConnectionHandler,2018-01-30 09:40:29,309,DEBUG,0x7f3f03c96700,LdapTestBindConnectionHandler::fetchBindResponse::onInput(id = 1102): bind succeeded,LdapTestBindConnectionHandler.cpp:437&lt;/P&gt;&lt;P&gt;Connection,2018-01-30 09:40:29,309,DEBUG,0x7f3f03c96700,LdapConnectionContext::sendSearchRequest(id = 1102): base = CN=Person,DC=IDDir, filter = (objectClass=Group),LdapConnectionContext.cpp:516&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,309,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.writeData - nInDataSize=71, entity=client,SSLConnection.cpp:970&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,309,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.writeData - success,SSLConnection.cpp:1077&lt;/P&gt;&lt;P&gt;ConnectionHandler,2018-01-30 09:40:29,313,DEBUG,0x7f3f03c96700,LdapTestBindConnectionHandler::handle_input called,LdapTestBindConnectionHandler.cpp:109&lt;/P&gt;&lt;P&gt;ConnectionHandler,2018-01-30 09:40:29,313,DEBUG,0x7f3f03c96700,LdapTestBindConnectionHandler::fetchGroupSearchResponse called,LdapTestBindConnectionHandler.cpp:575&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,313,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.readData - nInDataSize=0, entity=client,SSLConnection.cpp:835&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,313,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.readData - output-size=126,SSLConnection.cpp:917&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Connection,2018-01-30 09:40:29,313,DEBUG,0x7f3f03c96700,LdapSearchResponse::update: SDK result = 32(No such object),LdapConnectionResponses.cpp:265&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ConnectionHandler,2018-01-30 09:40:29,313,ERROR,0x7f3f03c96700,LdapTestBindConnectionHandler::fetchSearchResponse::onInput(id = 1102): search ended with an error: 150,LdapTestBindConnectionHandler.cpp:596&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,313,DEBUG,0x7f3f03c96700,NIL-CONTEXT,Crypto::Result=0, Crypto.SSLConnection.pvDone,SSLConnection.cpp:278&lt;/P&gt;&lt;P&gt;Crypto,2018-01-30 09:40:29,313,DEBUG,0x7f3f03c96700,NIL-CONTEXT,shutting session id&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 23:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450849#M518216</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-01-29T23:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450850#M518217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would need to customize the LDAP server settings so that ISE can apply group membership to some attribute, even if not a traditional group attribute.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 23:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450850#M518217</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-01-29T23:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450851#M518218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to be clear on the wording, when you say "so that ISE &lt;EM&gt;can apply&lt;/EM&gt; group membership", what is meant by &lt;EM&gt;can apply&lt;/EM&gt;?&amp;nbsp; Is ISE going to modify something in the LDAP directory (i.e. need write access) or, did you mean that there has to exist a Group in the LDAP, and each user MUST be a member of that Group?&amp;nbsp; If so, would any Group suffice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for my lack of LDAP understanding.&amp;nbsp; I am relating as best as I can to how I understand Active Directory to work (Users and Groups, and their relationship).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 00:19:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450851#M518218</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-01-30T00:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450852#M518219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at Slide 17 of &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-64526"&gt;ISE 1.3-2.1 Sponsor Authorization on Secondary Attributes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, the LDAP schema "Active Directory" in ISE are using the attribute &lt;STRONG&gt;memberOf&lt;/STRONG&gt; for groups, but you may map it to another attribute in your LDAP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 01:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450852#M518219</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-30T01:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450853#M518220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe a better word would be "reconcile" rather than assign.&amp;nbsp;&amp;nbsp; As shown in AD example below, there are pointers telling ISE how to exampne the scheme and extract group objects and members, a fundamental part of defining the LDAP store.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" height="203" src="https://community.cisco.com/legacyfs/online/fusion/114901_pastedImage_0.png" style="width: 592px; height: 203.381px;" width="592" /&gt;&lt;/P&gt;&lt;P&gt;If you do not have the specified group or member attribute defined, then it is possible this will cause LDAP lookup to fail.&amp;nbsp; Note that these are mandatory attributes.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Hsing.&amp;nbsp; I was thinking of referencing that doc as well as an example of how to manipulate group references.&amp;nbsp; In that doc, I showed how to have ISE treat a different attribute as if it was a group object. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 01:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450853#M518220</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-01-30T01:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450854#M518221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The customer doesn't want to budge on this point.&amp;nbsp; They are questioning why ISE requires this Group concept when any generic LDAP browser will happily bind and traverse the LDAP directory they've created (which only contains a single attribute).&amp;nbsp; This directory was designed and built for simplicity and speed and it works well with other applications they have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way around this mandatory Group Map attribute and Group Name attribute in ISE?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 23:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450854#M518221</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-02-06T23:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450855#M518222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arnie, Have you tried using default values for groups?&amp;nbsp;&amp;nbsp; I just tested with invalid object names for groups and even for search space and was able to bind successfully and perform a test auth against LDAP server.&amp;nbsp; I was not able to add groups, but attributes did appear and were retrieved in test auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, if existing behavior not working and requesting change in the design, then suggest submitting an enhancement request to Tal Surasky as the PM for AAA and Id Stores.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 05:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450855#M518222</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-02-07T05:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450856#M518223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried various permutations but I think my lack of LDAP understanding is causing me to stumble.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have admin access to the LDAP directory itself to see how it's configured.&lt;/P&gt;&lt;P&gt;But I can browse the directory using Windows Server command ldp.&amp;nbsp; When I search the thing I can see the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-5" src="https://community.cisco.com/legacyfs/online/fusion/115159_pastedImage_4.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The uid contains the username that I am allowed to query on.&amp;nbsp; That's it.&amp;nbsp; Million dollar question is how to configure ISE to allow me to do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ISE config is as follows:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/115157_pastedImage_2.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.cisco.com/legacyfs/online/fusion/115158_pastedImage_3.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can bind, but get error&lt;/P&gt;&lt;P&gt;Ldap bind succeeded to I*********.local:636&lt;/P&gt;&lt;P&gt;Subject search ended with an error.Please check search base configured properly&lt;/P&gt;&lt;P&gt;Group search ended with an error.Please check search base configured properly&lt;/P&gt;&lt;P&gt;Response time 496ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as the Genera tab is concerned, I don't know whether it resembles what you were talking about? i.e. using Dummy values for the Group Map and Group Name attributes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing I do seems to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115149_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 02:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450856#M518223</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-02-12T02:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450857#M518224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try saving it away and then re-do the test binding.&lt;/P&gt;&lt;P&gt;I got similar errors as you did and it went ok after saving it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed &lt;A href="https://technet.microsoft.com/en-us/library/cc738093(v=ws.10).aspx"&gt;Ldp Examples: Active Directory&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; to perform search tests on our test AD instance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;IMG alt="Screen Shot 2018-02-11 at 6.59.33 PM.png" class="image-1 jive-image" height="219" src="/legacyfs/online/fusion/115160_Screen Shot 2018-02-11 at 6.59.33 PM.png" style="height: 219.18387096774194px; width: 426px;" width="426" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 03:00:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450857#M518224</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-12T03:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450858#M518225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for that. It turns out that I was given the incorrect Subject ObjectClass and as soon as I substituted that with a wildcard, I was able to move forward (this was also the value I gave the Windows ldp tool in my previous example).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115163_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for all the assistance with this.&amp;nbsp; I somehow have an aversion to LDAP and I think it will still haunt me beyond the grave ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 06:07:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450858#M518225</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-02-12T06:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP integration without Groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450859#M518226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad you were able to work things out.&amp;nbsp; I was going to provide some examples of some common LDAP records as your earlier examples do not reflect typical schema and objectclass definitions...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.oracle.com/cd/E19623-01/820-6169/ldapsearch-examples.html" title="https://docs.oracle.com/cd/E19623-01/820-6169/ldapsearch-examples.html"&gt;ldapsearch Examples - Sun OpenDS Standard Edition 2.0 Administration Guide&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://manuals.gfi.com/en/kerio/connect/content/server-configuration/ldap-and-directory-services/mapping-users-groups-from-an-openldap-or-generic-ldap-server-294.html" title="https://manuals.gfi.com/en/kerio/connect/content/server-configuration/ldap-and-directory-services/mapping-users-groups-from-an-openldap-or-generic-ldap-server-294.html"&gt;https://manuals.gfi.com/en/kerio/connect/content/server-configuration/ldap-and-directory-services/mapping-users-groups-f…&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.ldap.com/specs/rfc4519.txt" title="https://docs.ldap.com/specs/rfc4519.txt"&gt;https://docs.ldap.com/specs/rfc4519.txt&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115172_pastedImage_5.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 13:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-integration-without-groups/m-p/3450859#M518226</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-02-12T13:30:42Z</dc:date>
    </item>
  </channel>
</rss>

