<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE ports (TCP 464) with AD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461488#M536594</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;We have a customer that is asking if port TCP 464 “KPASS” is required to be opened between the ISE and AD. If yes, what is the exact purpose of opening this port and is it required during the authentication phase ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jan 2017 07:57:26 GMT</pubDate>
    <dc:creator>saghisha</dc:creator>
    <dc:date>2017-01-05T07:57:26Z</dc:date>
    <item>
      <title>ISE ports (TCP 464) with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461488#M536594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;We have a customer that is asking if port TCP 464 “KPASS” is required to be opened between the ISE and AD. If yes, what is the exact purpose of opening this port and is it required during the authentication phase ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2017 07:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461488#M536594</guid>
      <dc:creator>saghisha</dc:creator>
      <dc:date>2017-01-05T07:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE ports (TCP 464) with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461489#M536595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is not specifically needed, but could alleviate some headaches.&amp;nbsp; KPASS is used on TCP Port 464 for Kerberos based password changes.&amp;nbsp; Starting in Vista, Microsoft used this as the default password change method.&amp;nbsp; However, if KPASS is not accessible (as in the port is closed), it will default back to NTLM for password changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This article goes more in-depth:&lt;/P&gt;&lt;P&gt;&lt;A href="https://blogs.technet.microsoft.com/askds/2011/09/30/friday-mail-sack-super-slo-mo-edition/" title="https://blogs.technet.microsoft.com/askds/2011/09/30/friday-mail-sack-super-slo-mo-edition/"&gt;https://blogs.technet.microsoft.com/askds/2011/09/30/friday-mail-sack-super-slo-mo-edition/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2017 13:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461489#M536595</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-01-05T13:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE ports (TCP 464) with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461490#M536596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Samer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the ports that need to be open between ISE nodes. ISE PSN talks to AD using certain functionalities.&lt;/P&gt;&lt;P&gt;For ISE to work correctly the ports need to be open.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/400001-500000/410001-420000/413001-414000/413702.jpg" title="http://www.cisco.com/c/dam/en/us/td/i/400001-500000/410001-420000/413001-414000/413702.jpg"&gt;http://www.cisco.com/c/dam/en/us/td/i/400001-500000/410001-420000/413001-414000/413702.jpg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 01:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461490#M536596</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-01-06T01:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE ports (TCP 464) with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461491#M536597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Charles. Much appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 07:37:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ports-tcp-464-with-ad/m-p/3461491#M536597</guid>
      <dc:creator>saghisha</dc:creator>
      <dc:date>2017-01-06T07:37:31Z</dc:date>
    </item>
  </channel>
</rss>

