<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 patch 11 Secure ldap problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4076282#M559963</link>
    <description>&lt;P&gt;Is there any use guide with troubleshooting that we can use to implement secure ldap on ISE 2.4!&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2020 11:51:12 GMT</pubDate>
    <dc:creator>Moudar</dc:creator>
    <dc:date>2020-04-29T11:51:12Z</dc:date>
    <item>
      <title>ISE 2.4 patch 11 Secure ldap problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4076268#M559962</link>
      <description>&lt;P&gt;Trying to start using Secure LDAP but the problem is that when we test bind to server we get this massage:"&lt;STRONG&gt;ldap bind ended with an error&lt;/STRONG&gt;"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise error.PNG" style="width: 448px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/73290iDFA2EF4DC38E4764/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise error.PNG" alt="ise error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas!?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 11:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4076268#M559962</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2020-04-29T11:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 11 Secure ldap problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4076282#M559963</link>
      <description>&lt;P&gt;Is there any use guide with troubleshooting that we can use to implement secure ldap on ISE 2.4!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 11:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4076282#M559963</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2020-04-29T11:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 11 Secure ldap problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4076537#M559979</link>
      <description>I don't have a guide for this, but ensure that your are using the correct CA cert selections in the connection tab of the LDAP connector. Both sides need to trust each other.  &lt;BR /&gt;&lt;BR /&gt;There is also a section in the 2.6 admin guide that indicates what settings need to be enabled for certain ISE features to function.  Look under the section titled "Configure Security Settings" which directs you to Administration &amp;gt; System &amp;gt; Settings &amp;gt; Security Settings in the GUI. &lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_010010.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_010010.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Someone else had suggested that you could enable debugs for prrt-JNI, AAA-runtime, AAA-config, then check the prrt-server.log file for more information on the errors.  &lt;BR /&gt;&lt;BR /&gt;Lastly, there is this terminated bug which indicates that ISE might not support mutual cert secure ldap authentication. I'm not sure if it still applies or not.  &lt;BR /&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj82754" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj82754&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Apr 2020 17:36:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4076537#M559979</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-04-29T17:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 11 Secure ldap problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4077015#M559995</link>
      <description>&lt;P&gt;is there any way to make sure that there is a trust between the two, what we know is that there is a trust but how to make sure?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 09:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4077015#M559995</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2020-04-30T09:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 11 Secure ldap problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4078255#M560052</link>
      <description>&lt;P&gt;&lt;A id="link_21" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320219" target="_self"&gt;&lt;SPAN class=""&gt;Damien Miller&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;already gave some info on troubleshooting.&lt;/P&gt;
&lt;P&gt;In case you are using the LDAPS from Google G-Suite or the like, that is not currently supported. Also, the LDAPS in ISE supports for encryption only but not for mutual authentication. The root CA of the LDAP server needs imported into ISE trusted certificates and trusted for client authentications.&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2020 05:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4078255#M560052</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-05-02T05:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 11 Secure ldap problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4078860#M560078</link>
      <description>&lt;P&gt;Take a packet capture on ISE with the filer " ip host &amp;lt;&lt;EM&gt;ip address of LDAP server&lt;/EM&gt;&amp;gt; and check if the handshake between the two is completing or not.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 10:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4078860#M560078</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-05-04T10:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 11 Secure ldap problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4272254#M564782</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this still the case with newer ISE version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will probably ask a feature request to our Cisco representative but can you suggest if there is a specific internal reference for this feature?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 10:47:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-11-secure-ldap-problem/m-p/4272254#M564782</guid>
      <dc:creator>giovanni.augusto</dc:creator>
      <dc:date>2021-01-14T10:47:01Z</dc:date>
    </item>
  </channel>
</rss>

