<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493242#M537876</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having the same issue, NFR ISE and 2012r2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tried another DC yet. I have 3, will try that and continue to research.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Sep 2016 16:03:00 GMT</pubDate>
    <dc:creator>bwm0875</dc:creator>
    <dc:date>2016-09-01T16:03:00Z</dc:date>
    <item>
      <title>Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493234#M537856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting ERROR_RPC_NETLOGON_FAILED when authentication using MS-RPC against one domain controller.&amp;nbsp; Kerberos test pass fine.&amp;nbsp; If I use the other domain controller, both MS-RPC and Kerberos work.&amp;nbsp; I built a new DC and only Kerberos works against it.&amp;nbsp; I've read the bug id with AD and ISE related to this issue.&amp;nbsp; Removed and Rejoined ISE to the domain but that only works if it goes to DC01.&amp;nbsp; If it chooses DC02, MS-RPC fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming this is a Microsoft Server issue but have not been able to find a fix.&amp;nbsp; Anyone encountered this and found a resolution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DC01 2012 Essentials Server&amp;nbsp; -&amp;nbsp; MS_RPC and Kerberos Pass&lt;/P&gt;&lt;P&gt;DC02 2012 Standard Server&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; MS_RPC Fails and Kerberos Pass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;Active Directory Security log shows on the working DC a successful impersonation delegation and shows my username.&amp;nbsp; On DC02 that is not working the impersonation delegation shows Null SID and not username.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;MS_RPC Test from ISE&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Error&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Authentication encountered an error due to network, AD DNS misconfiguration. This may be a temporary error.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Processing Steps:&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Resolving identity - username&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Search for matching accounts at join point - domain.local&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Single matching account found in forest - &lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;domain.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Identity resolution detected single matching account&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;RPC Logon request failed - STATUS_ACCESS_DENIED,ERROR_RPC_NETLOGON_FAILED,username@&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;domain.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Communication with domain controller failed - dc02.domain.local,ERROR_RPC_NETLOGON_FAILED&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;RPC Logon request failed - STATUS_ACCESS_DENIED,ERROR_RPC_NETLOGON_FAILED,&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;username&lt;/SPAN&gt;@&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;domain.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Communication with domain controller failed - &lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;dc02.domain.local&lt;/SPAN&gt;,ERROR_RPC_NETLOGON_FAILED&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;RPC Logon request failed - STATUS_ACCESS_DENIED,ERROR_RPC_NETLOGON_FAILED,&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;username&lt;/SPAN&gt;@&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;domain.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Communication with domain controller failed - &lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;dc02.domain.local&lt;/SPAN&gt;,ERROR_RPC_NETLOGON_FAILED&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Failover threshold has been exceeded&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2016 17:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493234#M537856</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-08-19T17:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493235#M537859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a Firewall between ISE and the domain controllers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Aug 2016 23:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493235#M537859</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2016-08-23T23:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493236#M537862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Aug 2016 23:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493236#M537862</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-08-23T23:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493237#M537866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the same DC able to authenticate users on other domain-joined computers? If so, then please open a TAC case to investigate. If not, then it's best to consult with Microsoft support. Perhaps, the domain replication is not working correctly or something like that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Aug 2016 00:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493237#M537866</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-08-24T00:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493238#M537870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it authenticates everything else fine and works with ISE Kerberos test.&amp;nbsp; I only have Partner ISE Licenses for Lab environment and do not have TAC support.&amp;nbsp; That is why I tried this forum.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Aug 2016 12:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493238#M537870</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-08-24T12:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493239#M537872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried Microsoft forums yet? I have no idea why it needing impersonation at all and so far not finding anything useful in any of my searches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using some special access restrictions or some security measures to lock down the DC? A known extra permission needed by ISE (release 1.3+) is to grant ISE machine account or OU the read &lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 15px;"&gt;tokenGroups&lt;/SPAN&gt; permission. This can be achieved by issuing the dsacls commands on each DC.&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code _jivemacro_uid_14722452882983197" jivemacro_uid="_14722452882983197"&gt;
&lt;P&gt;dsacls "OU=XYZ,OU=External,OU=Users,OU=EG,DC=myDemo,DC=aSLD,DC=aTLD" /I:T /G “[****ISE_MACHINE_NAME***]$":rp;tokenGroups&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which Microsoft event log did you find such info? I looked at my 2008R2 and none of the events like yours. Attached is my security events during a PC user auth against my DC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Aug 2016 21:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493239#M537872</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-08-26T21:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493240#M537874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears Microsoft Windows Server 2012 and 2012 R2 added Impersonation Level in the event logs and "NULL SID" could appear in normal events. Attached is my 2012 R2 security events while testing MS-RPC user auth from my ISE 2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=89275&amp;amp;backBtn=true"&gt;BRKSEC-2132 - What's new in ISE Active Directory connector (2016 Berlin) &lt;/A&gt;&lt;/P&gt;&lt;P&gt;slide 130 shows how to disable encryption so to take a more useful packet capture in understanding communication problem between ISE and AD.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Aug 2016 23:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493240#M537874</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-08-26T23:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493241#M537875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I performed the steps to disable encryption but since it is MS-RPC and not Kerberos I don't think it helped.&amp;nbsp; Same error in packet capture as displayed in the error message when I run the test on ISE.&amp;nbsp; My guess is that this is an AD Problem.&amp;nbsp; No resolution on any MS Forums. I have the same GPO applied to DC01 that is working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;NetrLogonSamLogonEx response, STATUS_ACCESS_DENIED&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried running the dsacls agains my user group and domain but the tokengroups was not recognized.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL class="dp-c" start="1" style="font-size: 12px; font-family: Consolas, 'Courier New', Courier, mono, serif; list-style-position: initial; list-style-image: initial; color: #5c5c5c; margin-bottom: 1px !important; margin-left: 45px !important;"&gt;&lt;LI&gt;&lt;SPAN style="color: black; font-size: 9pt !important; font-style: inherit; background-color: inherit;"&gt;dsacls "OU=XYZ,OU=External,OU=Users,OU=EG,DC=myDemo,DC=aSLD,DC=aTLD" /I:T /G “[****ISE_MACHINE_NAME***]$":rp;tokenGroups&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Aug 2016 03:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493241#M537875</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-08-31T03:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493242#M537876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having the same issue, NFR ISE and 2012r2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tried another DC yet. I have 3, will try that and continue to research.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2016 16:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493242#M537876</guid>
      <dc:creator>bwm0875</dc:creator>
      <dc:date>2016-09-01T16:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493243#M537878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank goodness I'm not the only one.&amp;nbsp; I built a new DC and it didn't help.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2016 16:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493243#M537878</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-09-01T16:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493244#M537880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does sound like the netlogon service on the DC is either not reachable or rejecting the connection.&lt;/P&gt;&lt;P&gt;A sniffer might not shed too much light on why.&lt;/P&gt;&lt;P&gt;If you can, I would suggest to enable netlogon debug and reproduce the issue and send us the netlogon debug log file.&lt;/P&gt;&lt;P&gt;This should give us some idea of what netlogon thinks is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can enable netlogon debug using nltest (easiest) or the Registry as per here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/kb/109626" title="https://support.microsoft.com/en-us/kb/109626"&gt;https://support.microsoft.com/en-us/kb/109626&lt;/A&gt;&lt;A href="https://support.microsoft.com/en-us/kb/109626"&gt;https://support.microsoft.com/en-us/kb/109626&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would be interested in seeing the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2016 10:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493244#M537880</guid>
      <dc:creator>ChrisMurray</dc:creator>
      <dc:date>2016-09-02T10:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493245#M537882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This does work on the working DC.&amp;nbsp; So far I haven't found a fix for this on any MS forums.&amp;nbsp; Can we force ISE to only user Kerberos and not MS_RPC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS C:\Windows\system32&amp;gt; nltest /DBFlag:2080FFFF&lt;/P&gt;&lt;P&gt;SYSTEM\CurrentControlSet\Services\Netlogon\Parameters set to 0x2080ffff&lt;/P&gt;&lt;P&gt;Flags: 0&lt;/P&gt;&lt;P&gt;Connection Status = 1311 0x51f ERROR_NO_LOGON_SERVERS&lt;/P&gt;&lt;P&gt;The command completed successfully&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Sep 2016 03:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493245#M537882</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-09-03T03:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493246#M537884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Running dcdiag I found some errors about system volumes that lead me to enable DFS.&amp;nbsp; After installing DFS I can now enable netlogon debugging.&amp;nbsp; I will work on this later but looks like progress.&amp;nbsp; I'll work through the errors in the dcdiag.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Sep 2016 04:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493246#M537884</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-09-03T04:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493247#M537885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It makes sense, sort of, according to this cifs protocol post -- &lt;A href="https://lists.samba.org/archive/cifs-protocol/2011-July/001996.html"&gt;[cifs-protocol] [REG:111071166110452] access denied in NetrLogonSamLogonEx&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 01:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493247#M537885</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-09-05T01:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493248#M537888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DCDiag is needed to debug this issue fully.&amp;nbsp; Once I realized that DFS needed to be installed to replicate the Sysvol, Netlogin, etc, the next error lead me restoring the sysvol.&amp;nbsp; Everything works as expected now.&amp;nbsp; Thanks for pointing me in the right direction with the netlogin debugging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://jorgequestforknowledge.wordpress.com/2010/08/12/restoring-the-sysvol-non-authoritatively-when-either-using-ntfrs-or-dfs-r-part-3/" title="https://jorgequestforknowledge.wordpress.com/2010/08/12/restoring-the-sysvol-non-authoritatively-when-either-using-ntfrs-or-dfs-r-part-3/"&gt;(2010-08-12) Restoring The SYSVOL (Non-)Authoritatively When Either Using NTFRS Or DFS-R (Part 3) « Jorge's Quest For Kn…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 14:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493248#M537888</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2016-09-05T14:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493249#M537890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to hear you got it working. &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 17:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493249#M537890</guid>
      <dc:creator>ChrisMurray</dc:creator>
      <dc:date>2016-09-05T17:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493250#M537891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi guys, my apologies, i forgot to update my thread. I re-installed my AD as it was an upgraded directory from 2008r2 to 2012r2 over a couple of years. As i reviewed, I was actually having directory replication issues, so i decided to reload fresh on 2012r2. Everything is working as expected now.&amp;nbsp;&amp;nbsp; Thanks Goodness!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2016 16:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493250#M537891</guid>
      <dc:creator>bwm0875</dc:creator>
      <dc:date>2016-10-10T16:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493251#M537893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the similar problem.&amp;nbsp; But my case is a bit different.&amp;nbsp; Both my PSN01 and PSN02 connected to same domain controller, DC01.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PSN01 --&amp;gt; DC01,&amp;nbsp; RPC logon failed.&lt;/P&gt;&lt;P&gt;PSN02 --&amp;gt; DC01, RPC logon successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case, what could be the possibilities?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 06:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493251#M537893</guid>
      <dc:creator>geeyc5113</dc:creator>
      <dc:date>2017-11-13T06:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493252#M537895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your deployment has multiple domain controllers, please still investigate Active Directory health. For a single domain controller setup (e.g. in a lab), please wait for 5 minutes and see whether it recovers, as you might have hit CSCvf71029.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please engage Cisco TAC for further troubleshoots.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 14:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493252#M537895</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-13T14:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication ERROR_RPC_NETLOGON_FAILED</title>
      <link>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493253#M537898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just had this same issue.&amp;nbsp; Both ISE Servers were joined to the domain, and one of them dropped off.&amp;nbsp; I ran a diagnostics (same place you join to the domain) and it was failing on the two messages both related to Kerberos.&amp;nbsp; AD was healthy.&amp;nbsp; I can not remember what the exact fix was but it was something in ISE.&amp;nbsp; I believe I failed it back to the primary server, rebooted it, checked NTP (Made some corrections to time sources I was syncing).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the diagnostic tool under External ID Sources/AD.&amp;nbsp; This will give you the best direction to troubleshoot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 14:54:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-directory-authentication-error-rpc-netlogon-failed/m-p/3493253#M537898</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2017-11-13T14:54:40Z</dc:date>
    </item>
  </channel>
</rss>

