<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed ISE AD Connection in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427911#M530150</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Do you have any link for the fix CSCvb46425. I cannot find any information about that fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Apr 2017 09:18:15 GMT</pubDate>
    <dc:creator>Christian Overrein</dc:creator>
    <dc:date>2017-04-19T09:18:15Z</dc:date>
    <item>
      <title>Distributed ISE AD Connection</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427909#M530148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a distributed ISE solution implementet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Se attachement ISE-Deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISE nodes are jointed to respective Active Directory as in the picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get alarm on all ISE nodes that are not joined in AD that "Active Directory not joined". Se attachement ISE_Alarm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All radius athentications working great in all domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the challanges is external identity mapping medn retriving groups from AD. It says that the Primary Administrations Node need to be a member for the domain.&lt;/P&gt;&lt;P&gt;- I have tested to join the domain with Primary Admin node, do the group mapping and then leave the domain. That works great. If the admin nodes is member of all domains the PSN and MNT generate alarms. Same alarm as the attachement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration for External Identity Sources looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active Directory&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Initial_Scope&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain-3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also tried with scope for each domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do anyone have som ideas here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx for any answers and help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2017 13:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427909#M530148</guid>
      <dc:creator>Christian Overrein</dc:creator>
      <dc:date>2017-04-18T13:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed ISE AD Connection</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427910#M530149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If on ISE 2.2, this alarm is added as the fix for CSCvb46425. If any alarm alerting it incorrectly, please engage Cisco TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2017 21:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427910#M530149</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-04-18T21:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed ISE AD Connection</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427911#M530150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Do you have any link for the fix CSCvb46425. I cannot find any information about that fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Apr 2017 09:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427911#M530150</guid>
      <dc:creator>Christian Overrein</dc:creator>
      <dc:date>2017-04-19T09:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed ISE AD Connection</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427912#M530153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please see &lt;A href="https://community.cisco.com/docs/DOC-72004"&gt;Bug Status &amp;amp;amp; Notifications&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Apr 2017 14:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-ad-connection/m-p/3427912#M530153</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2017-04-19T14:51:16Z</dc:date>
    </item>
  </channel>
</rss>

