<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.7 AD join - remove 2008 DC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4511244#M571346</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;Thanks for your suggestions. We don't have Default-First-Site and all DC's show under there relative site names. I however looked into SRV records and all our DC's for this site were set to default priority and weight. I lowered the priority of 2008 server and now I see ldap and kerberos going to our preferred DC's. I then blocked all traffic to our DC's and everything still works. yay..&lt;/P&gt;</description>
    <pubDate>Wed, 01 Dec 2021 15:12:39 GMT</pubDate>
    <dc:creator>rajitoor55</dc:creator>
    <dc:date>2021-12-01T15:12:39Z</dc:date>
    <item>
      <title>ISE 2.7 AD join - remove 2008 DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4510091#M571291</link>
      <description>&lt;P&gt;We have AD joined ISE servers and 3 Doman Controllers. One of them is an old 2008 which we are trying to get rid of.&lt;/P&gt;&lt;P&gt;As soon as I block the traffic on the intermediate firewall, all authentications start failing. All traffic is confirmed allowed to new 2016 DC's.&amp;nbsp;Why ISE is not moving to the new DC's and what can I do to make it work with new DC's.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 16:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4510091#M571291</guid>
      <dc:creator>rajitoor55</dc:creator>
      <dc:date>2021-11-29T16:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 AD join - remove 2008 DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4510096#M571292</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Not sure how traffic blocking is experienced by ISE when trying to connect to the&amp;nbsp; old-DC , perhaps turn it off and keep it reachable. Sometimes there is a subtle difference between lost . unreachable or rejected connections. ? FYI :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/ise_active_directory_integration/b_ISE_AD_integration_2x.html#reference_42F562CACEA745348AE47B601A29E151" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/ise_active_directory_integration/b_ISE_AD_integration_2x.html#reference_42F562CACEA745348AE47B601A29E151&lt;/A&gt;&amp;nbsp;but it does not immediately clear-up the subject.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 16:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4510096#M571292</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-11-29T16:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 AD join - remove 2008 DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4510245#M571296</link>
      <description>&lt;P&gt;The Primary DC that the ISE nodes communicate with is controlled by the configuration in AD Sites and Services. If the Site showing in the ISE AD section says 'Default-First-Site' then you have not configured Sites correctly. You should have a Site that represents the physical/logical location(s) of the ISE nodes. The closet Domain Controller should be associated with that Site as should the IP address or subnet for the respective ISE nodes. After updating Sites, ISE will automatically begin communication with the relevant (non-2008) DC.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 23:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4510245#M571296</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-11-29T23:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 AD join - remove 2008 DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4511244#M571346</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;Thanks for your suggestions. We don't have Default-First-Site and all DC's show under there relative site names. I however looked into SRV records and all our DC's for this site were set to default priority and weight. I lowered the priority of 2008 server and now I see ldap and kerberos going to our preferred DC's. I then blocked all traffic to our DC's and everything still works. yay..&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 15:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-ad-join-remove-2008-dc/m-p/4511244#M571346</guid>
      <dc:creator>rajitoor55</dc:creator>
      <dc:date>2021-12-01T15:12:39Z</dc:date>
    </item>
  </channel>
</rss>

