<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/4424584#M568138</link>
    <description>&lt;P&gt;This has been solved. I was prepending the hostname to the AD. It should only be the AD at the joinpoint.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 05:38:37 GMT</pubDate>
    <dc:creator>erroltalbot</dc:creator>
    <dc:date>2021-06-28T05:38:37Z</dc:date>
    <item>
      <title>ISE integration with AD fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876824#M39193</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying to join the ISE with our AD with no success, below the error logged in the ISE:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Error Description: Failed to find domain controller, please check network connectivity&lt;/P&gt;
&lt;P&gt;Support Details...&lt;/P&gt;
&lt;P&gt;Error Name: LW_ERROR_FAILED_FIND_DC&lt;/P&gt;
&lt;P&gt;Error Code: 40049&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Detailed Log:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error Description :&lt;/P&gt;
&lt;P&gt;Failed to find domain controller in domain 10.10.10.10 : domain does not exists in DNS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error Resolution :&lt;/P&gt;
&lt;P&gt;Please make sure that your DNS contains records for domain : 10.10.10.10, For further information please refer to the AD DNS diagnostic tools&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Join steps :&lt;/P&gt;
&lt;P&gt;13:51:40 Joining to domain 10.10.10.10 using user ise&lt;/P&gt;
&lt;P&gt;13:51:40&amp;nbsp;&amp;nbsp; Searching for DC in domain 10.10.10.10&lt;/P&gt;
&lt;P&gt;13:51:40&amp;nbsp;&amp;nbsp; Failed to find domain controller in domain 10.10.10.10 : domain does not exists in DNS&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Although we are having valid records for both AD and ISE in the DNS, i am able to resolve the DNS of our AD when making NSlookup in the ISE.&lt;/P&gt;
&lt;P&gt;I am not sure what is the issue?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Looking forward to hearing from you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Muhannad&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876824#M39193</guid>
      <dc:creator>Muhannad Abu Shamma</dc:creator>
      <dc:date>2019-03-11T06:54:24Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876825#M39194</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all, does your dns can answer srv request by sending AD IP address? Do you set the ntp on AD and ISE?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which version of ISE are you using? Have you applied the latest patches?&lt;/P&gt;
&lt;P&gt;When all these steps have been soon, did you took some traces on ISE?&lt;/P&gt;
&lt;P&gt;On ISE to check your dns server you can run the command below :&lt;/P&gt;
&lt;P&gt;nslookup _ldap._tcp.dc._msdcs.&lt;B&gt;&lt;I&gt;AD.DOMAIN&lt;/I&gt;&lt;/B&gt; querytype srv&lt;/P&gt;
&lt;P&gt;Replace AD.DOMAIN by your real AD domain name and paste your result.&lt;/P&gt;
&lt;P&gt;After getting those informations, if not working yet, you need to do some traces on ISE. If you don't know how, let me know I will try to do some screenshot on my lab to give you a guidance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 03:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876825#M39194</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-04T03:31:48Z</dc:date>
    </item>
    <item>
      <title>Dears,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876826#M39195</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The issue was in the Domain name when we configure the External identity, once it has been fixed the integration worked fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Muhannad&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 23:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876826#M39195</guid>
      <dc:creator>Muhannad Abu Shamma</dc:creator>
      <dc:date>2016-07-13T23:48:53Z</dc:date>
    </item>
    <item>
      <title>Nice to hear that.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876827#M39196</link>
      <description>&lt;P&gt;Nice to hear that.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 23:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876827#M39196</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-13T23:53:43Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876828#M39197</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I have the same problem :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;"Error Description: Failed to find domain controller, please check network connectivity&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Support Details...&lt;BR /&gt;Error Name: LW_ERROR_FAILED_FIND_DC&lt;BR /&gt;Error Code: 40049&lt;BR /&gt;&lt;BR /&gt;Detailed Log:&lt;BR /&gt;&lt;BR /&gt;Error Description : &lt;BR /&gt;Failed to find domain controller in domain PFE.LOCAL : domain does not exists in DNS &lt;BR /&gt;&lt;BR /&gt;Error Resolution : &lt;BR /&gt;Please make sure that your DNS contains records for domain : PFE.LOCAL, For further information please refer to the AD DNS diagnostic tools &lt;BR /&gt;&lt;BR /&gt;Join steps : &lt;BR /&gt;14:26:46 Joining to domain PFE.LOCAL using user bougamra&lt;BR /&gt;14:26:46&amp;nbsp;&amp;nbsp; Searching for DC in domain PFE.LOCAL&lt;BR /&gt;14:26:46&amp;nbsp;&amp;nbsp; Failed to find domain controller in domain PFE.LOCAL : domain does not exists in DNS "&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you help me please ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876828#M39197</guid>
      <dc:creator>bougamramohamed89</dc:creator>
      <dc:date>2017-03-22T14:27:41Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876829#M39198</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;i have the same problem can you help me please&lt;/P&gt;
&lt;P&gt;&lt;SPAN id="primaryOperationDetail" class="primaryOperationDetailSpanClass"&gt;Status:&amp;nbsp;&lt;B&gt;&lt;SPAN class="primaryDetailStatus"&gt;Join Operation Failed: Failed to find domain controller, please check network connectivity&lt;/SPAN&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 12:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876829#M39198</guid>
      <dc:creator>bougamramohamed89</dc:creator>
      <dc:date>2017-04-07T12:18:54Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876830#M39199</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;First of all, could you check your ntp configuration. AD and ISE must have the same clock to be able to be joined to your AD infrastructure.&lt;/P&gt;
&lt;P&gt;On ISE cli, could you run this nslookup command and paste the output on a txt file:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nslookup&amp;nbsp;_ldap._tcp.dc._msdcs.DOMAIN.SUFFIXE querytype&amp;nbsp;srv&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--&amp;gt; Example:&amp;nbsp;&lt;SPAN&gt;nslookup&amp;nbsp;_ldap._tcp.dc._msdcs.MYCOMPANY.COM querytype&amp;nbsp;srv&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Please check out on that link (http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_20.html#reference_8DC463597A644A5C9CF5D582B77BB24F). All AD and DNS requirements must be setup.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If it's not working, please activate some debugs and attach the log file to this post:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Activate traces for Active directory component:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ise_log1.png" class="migrated-markup-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Try to join your ISE to your AD.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Take the logs of the debug traces:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ise_log2_0.png" class="migrated-markup-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 13:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876830#M39199</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-04-07T13:52:59Z</dc:date>
    </item>
    <item>
      <title>Hi thanks for the answer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876831#M39200</link>
      <description>&lt;P&gt;Hi thanks for the answer&lt;/P&gt;
&lt;P&gt;but i did not find how to "&lt;SPAN&gt;Activate traces for Active directory component:" !!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sorry&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;how can i do that please ? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 07:49:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876831#M39200</guid>
      <dc:creator>bougamramohamed89</dc:creator>
      <dc:date>2017-04-10T07:49:03Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876832#M39201</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Did you go into this menu:&amp;nbsp;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="menucascade"&gt;&lt;SPAN class="uicontrol"&gt;Administration &lt;/SPAN&gt;&amp;gt; &lt;SPAN class="uicontrol"&gt;System &lt;/SPAN&gt;&amp;gt; &lt;SPAN class="uicontrol"&gt;Logging &lt;/SPAN&gt;&amp;gt; &lt;SPAN class="uicontrol"&gt;Debug Log Configuration&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 12:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876832#M39201</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-04-10T12:00:36Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876833#M39202</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;the domain name was not correct&lt;/P&gt;
&lt;P&gt;well now i wanna know how to assign unknown mac address to a vlan ?&lt;/P&gt;
&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 14:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876833#M39202</guid>
      <dc:creator>bougamramohamed89</dc:creator>
      <dc:date>2017-04-24T14:46:29Z</dc:date>
    </item>
    <item>
      <title>Hi Francesco,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876834#M39204</link>
      <description>&lt;P&gt;Hi Francesco,&lt;/P&gt;
&lt;P&gt;Thanks you've already been helpful.&lt;/P&gt;
&lt;P&gt;I am facing the same problem, the AD and ISE have the same Clock along with a NTP server.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please find below :&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;- the operation detail&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;- the result of the command&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;- The ad_agent.log file&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;PS: I changed the real domain by MY.DOMAIN &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;###&amp;nbsp;&lt;SPAN&gt;the operation detail ###&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Error Description : &lt;BR /&gt;Failed To Find Domain Controller In Domain MY.DOMAIN&amp;nbsp;: Domain Does Not Exists In DNS&lt;/P&gt;
&lt;P&gt;Error Resolution : &lt;BR /&gt;Please Make Sure That Your DNS Contains Records For Domain : MY.DOMAIN, For Further Information Please Refer To The AD DNS Diagnostic Tools&lt;/P&gt;
&lt;P&gt;Join Steps : &lt;BR /&gt;12:55:20 Joining To Domain MY.DOMAIN&amp;nbsp;Using User Administrator&lt;BR /&gt;12:55:20 Searching For DC In Domain&amp;nbsp;MY.DOMAIN&lt;BR /&gt;12:55:20 Failed To Find Domain Controller In Domain MY.DOMAIN&amp;nbsp;: Domain Does Not Exists In DNS&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; ### Result of&amp;nbsp;nslookup _ldap._tcp.dc._msdcs.MY.DOMAIN querytype srv ###&lt;/P&gt;
&lt;P&gt;Trying "_ldap._tcp.dc._msdcs.&lt;SPAN&gt;MY.DOMAIN&lt;/SPAN&gt;"&lt;BR /&gt;Received 102 bytes from 172.20.127.1#53 in 0 ms&lt;BR /&gt;Trying "_ldap._tcp.dc._msdcs.&lt;SPAN&gt;MY.DOMAIN&lt;/SPAN&gt;.&lt;SPAN&gt;MY.DOMAIN&lt;/SPAN&gt;"&lt;BR /&gt;Host _ldap._tcp.dc._msdcs.&lt;SPAN&gt;MY.DOMAIN&lt;/SPAN&gt; not found: 3(NXDOMAIN)&lt;BR /&gt;Received 109 bytes from 172.20.127.1#53 in 0 ms&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you very much!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 12:31:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876834#M39204</guid>
      <dc:creator>ffenina01</dc:creator>
      <dc:date>2017-05-17T12:31:37Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876835#M39207</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there ISE on the same network add your AD server or is there an ACL or firewall in between?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not on the same network, have you opened dns port? (UDP 53)&lt;/P&gt;
&lt;P&gt;Have you configured the right dns server?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you do the following command from your windows machine (not from the AD)?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First be sure that your machine has same dns server add your ISE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From a command line, type&amp;nbsp;&lt;B&gt;nslookup&lt;/B&gt;, &amp;nbsp;then type &lt;B&gt;set type=all&lt;/B&gt;, and finally type&lt;B&gt;_ldap._tcp.dc._msdcs.YOURDOMAIN&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Could you please paste the output of the result?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 03:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876835#M39207</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-05-18T03:25:07Z</dc:date>
    </item>
    <item>
      <title>Hi again, </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876836#M39210</link>
      <description>&lt;P&gt;Hi again,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ISE and the AD are on the same network, and yes everything is correctly configured I checked more than once every detail.&lt;BR /&gt;&lt;BR /&gt;It turned out to be a problem within the AD, we are working in a new environment with a brand new AD, so the sys admin recreated a new one and then everything went great and it instantly joined the ISE and I retrieved the groups, so "smooth" &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I still haven't figured out the origine of the problem, however everything is working.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I really appreciate your help thanks &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 12:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876836#M39210</guid>
      <dc:creator>ffenina01</dc:creator>
      <dc:date>2017-05-18T12:04:14Z</dc:date>
    </item>
    <item>
      <title>Ok well done! 
You're welcome</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876837#M39211</link>
      <description>&lt;P&gt;Ok well done!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're welcome&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 12:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876837#M39211</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-05-18T12:06:47Z</dc:date>
    </item>
    <item>
      <title>Hi Francesco,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876838#M39215</link>
      <description>&lt;P&gt;Hi Francesco,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm facing the same problem.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;And here is the output from the windows machine&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;C:\Users\Administrator&amp;gt;nslookup&lt;BR /&gt;1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa&lt;BR /&gt; primary name server = 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0&lt;BR /&gt;0.0.0.0.0.0.0.ip6.arpa&lt;BR /&gt; responsible mail addr = (root)&lt;BR /&gt; serial = 0&lt;BR /&gt; refresh = 28800 (8 hours)&lt;BR /&gt; retry = 7200 (2 hours)&lt;BR /&gt; expire = 604800 (7 days)&lt;BR /&gt; default TTL = 86400 (1 day)&lt;BR /&gt;Default Server: UnKnown&lt;BR /&gt;Address: ::1&lt;/P&gt;
&lt;P&gt;&amp;gt; set type=all&lt;BR /&gt;&amp;gt; type_ldap._tcp.dc._msdcs.ualab.com&lt;BR /&gt;Server: UnKnown&lt;BR /&gt;Address: ::1&lt;/P&gt;
&lt;P&gt;*** UnKnown can't find type_ldap._tcp.dc._msdcs.ualab.com: Non-existent domain&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you please help on this issue.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 01:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876838#M39215</guid>
      <dc:creator>Hemalatha Kumarasamy</dc:creator>
      <dc:date>2017-05-23T01:13:00Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876839#M39218</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to recreate all servers records in AD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here are 2 sites I used when I faced the same issue. Sorry I'm not an AD expert but this worked for me:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.windowsnetworking.com/kbase/WindowsTips/WindowsServer2008/AdminTips/ActiveDirectory/AQuickTipToFixDCSRVsinActiveDirectoryDomain.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://blogs.msdn.microsoft.com/servergeeks/2014/07/12/dns-records-that-are-required-for-proper-functionality-of-active-directory/&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 11:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876839#M39218</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-05-23T11:56:21Z</dc:date>
    </item>
    <item>
      <title>Hi Franceso,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876840#M39222</link>
      <description>&lt;P&gt;Hi Franceso,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you so much for the prompt reply.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I looked into the below link,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.windowsnetworking.com/kbase/WindowsTips/WindowsServer2008/AdminTips/ActiveDirectory/AQuickTipToFixDCSRVsinActiveDirectoryDomain.html"&gt;http://www.windowsnetworking.com/kbase/WindowsTips/WindowsServer2008/AdminTips/ActiveDirectory/AQuickTipToFixDCSRVsinActiveDirectoryDomain.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you please help me how to do this first step:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Import SRV records from C:\SystemRoot\Config\NetLogon.dns file.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Highly appreciate the help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Hema&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 16:23:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876840#M39222</guid>
      <dc:creator>Hemalatha Kumarasamy</dc:creator>
      <dc:date>2017-05-23T16:23:52Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876841#M39223</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This file is used when you're using a third party dns server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to focus on creating all entry by yourself or doing a netdiag fix command if I remember.&lt;/P&gt;
&lt;P&gt;I'm sorry to not being able to help you more but in that case I'll follow Microsoft technote.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 20:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876841#M39223</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-05-25T20:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/3228315#M39224</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 549px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/4434iCD08294C2B54D83C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 03:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/3228315#M39224</guid>
      <dc:creator>qhu</dc:creator>
      <dc:date>2017-12-07T03:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/3750579#M39225</link>
      <description>&lt;P&gt;I know this is an old thread,but still replying so that anyone facing this problem can be helped.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This problem arises when the windows server fails to create SRV records for the domain controller.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I faced this problem too and the issue got resolved after i re-installed AD services on the windows server without installing the DNS server which lead to an automatic creation of the DNS server along with the required records.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 10:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/3750579#M39225</guid>
      <dc:creator>araviku2</dc:creator>
      <dc:date>2018-11-21T10:00:17Z</dc:date>
    </item>
  </channel>
</rss>

