<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - Active Directory Design assistance in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419200#M527498</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am checking with our teams on your inquires. If possible, please share the TAC case number.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Aug 2017 17:59:39 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-08-22T17:59:39Z</dc:date>
    <item>
      <title>ISE - Active Directory Design assistance</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419198#M527494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeking any help / advice from anyone who has implemented in a live corporate environment the use of a Member Server to provide PassiveID support for an ISE implementation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the design from BRKSEC-3697 from Aaron Woland's lecture, we have implemented a member server and are using a manually installed agent. (see attached .pdf)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why?&lt;/P&gt;&lt;P&gt;Using this design since our Server Admins are concerned directly accessing or using an agent on any production DC's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problems!&lt;/P&gt;&lt;P&gt;Unable to read logs which will not provide PassiveID information to ISE-Primary/Secondary devices&lt;/P&gt;&lt;P&gt;Logs are placed into a folder called Forwarded Events with the correct EventID (4769)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1. can the member server be in the parent domain?&lt;/P&gt;&lt;P&gt;2. is there any way to point the required eventID if unable to use the Forwarded Events?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any assistance&lt;/P&gt;&lt;P&gt;Dave Moore&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I have a TAC case open, but really need a solution soon as 3 projects are relying on this problem resolution)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Aug 2017 18:24:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419198#M527494</guid>
      <dc:creator>dmooregfb</dc:creator>
      <dc:date>2017-08-21T18:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Active Directory Design assistance</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419199#M527496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Attachment of the design&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Aug 2017 18:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419199#M527496</guid>
      <dc:creator>dmooregfb</dc:creator>
      <dc:date>2017-08-21T18:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Active Directory Design assistance</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419200#M527498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am checking with our teams on your inquires. If possible, please share the TAC case number.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Aug 2017 17:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419200#M527498</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-22T17:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Active Directory Design assistance</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419201#M527499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hslai, thanks for this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SR 682790420 : PassiveID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Aug 2017 18:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419201#M527499</guid>
      <dc:creator>dmooregfb</dc:creator>
      <dc:date>2017-08-22T18:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Active Directory Design assistance</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419202#M527500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TAC case has been associated with an active ISE ESC case and one of our ESC engineers have been assigned to it, so please continue the discussion with TAC and ISE ESC teams.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On 1, the collector can be in the parent domain to collect the windows events from a child domain.&lt;/P&gt;&lt;P&gt;On 2, you may change the subscription to update the destination log to Application or System. Also, we should monitor for both 4768 and 4770.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-09-06 at 10.39.17 AM.png" class="image-1 jive-image" height="131" src="/legacyfs/online/fusion/111024_Screen Shot 2017-09-06 at 10.39.17 AM.png" style="height: 131.1455160744501px; width: 433px;" width="433" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 17:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419202#M527500</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-06T17:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Active Directory Design assistance</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419203#M527501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hslai, thanks for the information. Will keep the lines of communication open with TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 18:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-design-assistance/m-p/3419203#M527501</guid>
      <dc:creator>dmooregfb</dc:creator>
      <dc:date>2017-09-06T18:41:41Z</dc:date>
    </item>
  </channel>
</rss>

