<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Can't join Multiple domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596491#M540366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The log file has been to share to you via box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The domain name is “icesnet.local” and AD admin user is “iseuser”&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I can see from the log, “failed to find domain controller in domain ICESNET.LOCAL”, but I can see from the DNS, the domain does exist in DNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Gaspard Liu (刘洪曦)  .:|:.:|:.&lt;/P&gt;&lt;P&gt;CCIE Wireless&lt;/P&gt;&lt;P&gt;Travel Plan:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Feb 2016 03:50:30 GMT</pubDate>
    <dc:creator>gasliu</dc:creator>
    <dc:date>2016-02-26T03:50:30Z</dc:date>
    <item>
      <title>ISE Can't join Multiple domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596489#M540320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;My customer is using ISE 2.0 to serve multiple domain user for AAA process. However, I can only join one AD into ISE. Every time I try to join the second AD, it will fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;I check the fail reason, it shows because ISE can't resolve the domain by DNS. For example, if the second domain is demo.local, it will show ISE can't find the domain controller of demo.local.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;I check the SVR is correct on DNS, and when I use SSH to log in ISE console and use nslookup, the demo.local can be resolve as the right AD's address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Do you have any experience it? Is it a bug?&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;&lt;SPAN style="color: #3d3d3d; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 14px;"&gt;The error code is &lt;/SPAN&gt;&lt;SPAN style="font-weight: bold; font-size: large; font-family: Times; color: #000000;"&gt;LW_ERROR_FAILED_FIND_DC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3d3d3d;"&gt;Thank you for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Feb 2016 13:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596489#M540320</guid>
      <dc:creator>gasliu</dc:creator>
      <dc:date>2016-02-25T13:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Can't join Multiple domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596490#M540333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Please review the DNS server section in &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_20.html#reference_8DC463597A644A5C9CF5D582B77BB24F"&gt;Prerequisites for Integrating Active Directory and Cisco ISE&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Then, from ISE admin CLI, the DNS query test is illustrated as below, where the domain is “lab.local”:&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code _jivemacro_uid_14564328423223316" jivemacro_uid="_14564328423223316"&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;ise/admin# nslooku&lt;STRONG&gt;p _ldap._tcp.dc._msdcs.LAB.&lt;/STRONG&gt;LOCAL querytype srv&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;Trying "_ldap._tcp.dc._msdcs.LAB.LOCAL"&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 17149&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;;; QUESTION SECTION:&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;;_ldap._tcp.dc._msdcs.LAB.LOCAL.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SRV&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;;; ANSWER SECTION:&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;_ldap._tcp.dc._msdcs.LAB.LOCAL. 320 IN&amp;nbsp; SRV&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 100 389 ws2012r2.lab.local.&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;;; ADDITIONAL SECTION:&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;ws2012r2.lab.local.&amp;nbsp;&amp;nbsp;&amp;nbsp; 3320&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.99.10&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Menlo;"&gt;Received 102 bytes from 10.1.100.10#53 in 8 ms&lt;/P&gt;

&lt;/PRE&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;If the deployment is meeting the DNS server requirements and the “SRV” query looking ok, then need to debug further.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Alter the debug level of "Active Directory" to TRACE.&lt;UL&gt;&lt;LI&gt;&lt;IMG __jive_id="93493" alt="Screen Shot 2016-02-25 at 12.06.39 PM.png" class="image-1 jive-image" height="179" src="/legacyfs/online/fusion/93493_Screen Shot 2016-02-25 at 12.06.39 PM.png" style="height: 179.18518518518516px; width: 354px;" width="354" /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Perform the join step.&lt;/LI&gt;&lt;LI&gt;Download and examine the debug log "ad_agent.log"&lt;UL&gt;&lt;LI&gt;&lt;IMG __jive_id="93497" alt="Screen Shot 2016-02-25 at 12.16.08 PM.png" class="jive-image image-2" src="/legacyfs/online/fusion/93497_Screen Shot 2016-02-25 at 12.16.08 PM.png" style="height: 275px; width: 620px;" /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;Here is an sample error entry:&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code _jivemacro_uid_14564328423194118" jivemacro_uid="_14564328423194118"&gt;
&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;…,VERBOSE,...,DNS lookup for '_ldap._tcp.dc._msdcs.TEST1.LOCAL' failed with errno 0, h_errno = 1, error=LW_ERROR_DNS_ERROR_DOMAIN_NOT_FOUND,LWNetDnsQueryWithBuffer(),netlogon/utils/lwnet-dns.c:1935&lt;/P&gt;

&lt;/PRE&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;If you need help in looking at the debug log, please share the file directly to me via box.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Feb 2016 20:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596490#M540333</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-02-25T20:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Can't join Multiple domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596491#M540366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The log file has been to share to you via box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The domain name is “icesnet.local” and AD admin user is “iseuser”&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I can see from the log, “failed to find domain controller in domain ICESNET.LOCAL”, but I can see from the DNS, the domain does exist in DNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Gaspard Liu (刘洪曦)  .:|:.:|:.&lt;/P&gt;&lt;P&gt;CCIE Wireless&lt;/P&gt;&lt;P&gt;Travel Plan:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 03:50:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596491#M540366</guid>
      <dc:creator>gasliu</dc:creator>
      <dc:date>2016-02-26T03:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Can't join Multiple domain</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596492#M540384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Closing this thread, as Gaspard opened a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2016 17:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-t-join-multiple-domain/m-p/3596492#M540384</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-03-14T17:30:55Z</dc:date>
    </item>
  </channel>
</rss>

