<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nodes and external AD are in different domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699086#M577600</link>
    <description>&lt;P&gt;&lt;FONT face="georgia,palatino" color="#003300"&gt;Yes, the AD object has been removed, but still the errors persists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="georgia,palatino" color="#003300"&gt;While I did try to do a nslookup from .net domain, was able to resolve the DNS and AD servers fine.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 08:57:41 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2022-10-06T08:57:41Z</dc:date>
    <item>
      <title>Nodes and external AD are in different domain</title>
      <link>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699062#M577597</link>
      <description>&lt;P&gt;&lt;FONT face="book antiqua,palatino" color="#003300"&gt;Hi Experts,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" color="#003300"&gt;Issue:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" color="#003300"&gt;ISE nodes in deployment are in .com domain while AD integration has been done with .net domain.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" color="#003300"&gt;Now, there is this one node that was re-imaged is no long able to join AD domain again.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" color="#003300"&gt;The logs are throwing the following errors: 40022, 31 and while joining, error 60113.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" color="#003300"&gt;Could anyone assist me understand why these are errors...&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 08:06:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699062#M577597</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2022-10-06T08:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes and external AD are in different domain</title>
      <link>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699073#M577598</link>
      <description>&lt;P&gt;Assuming all DNS records are still created for this node, including the reverse DNS record, did you try to remove the computer object of that node from AD and try again?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 08:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699073#M577598</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-06T08:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes and external AD are in different domain</title>
      <link>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699086#M577600</link>
      <description>&lt;P&gt;&lt;FONT face="georgia,palatino" color="#003300"&gt;Yes, the AD object has been removed, but still the errors persists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="georgia,palatino" color="#003300"&gt;While I did try to do a nslookup from .net domain, was able to resolve the DNS and AD servers fine.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 08:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699086#M577600</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2022-10-06T08:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes and external AD are in different domain</title>
      <link>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699096#M577601</link>
      <description>&lt;P&gt;Can you please share the screenshot of the error for review? Also, when you run these commands, do you see the resolution happening as expected:&lt;/P&gt;
&lt;P&gt;nslookup _ldap._tcp.dc._msdcs.&amp;lt;your-domain-name&amp;gt; querytype SRV&lt;BR /&gt;nslookup _ldap._tcp.gc._msdcs.&amp;lt;your-domain-name&amp;gt; querytype SRV&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 09:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699096#M577601</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-06T09:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes and external AD are in different domain</title>
      <link>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699785#M577631</link>
      <description>&lt;P&gt;&lt;FONT size="3"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="georgia,palatino" size="3" color="#003366"&gt;Was able to capture the following output of the commands:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;&amp;lt;Node_with_Issue&amp;gt;# nslookup _ldap._tcp.gc._msdcs.&amp;lt;ISE_node_domain&amp;gt; querytype SRV&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.gc._msdcs.&amp;lt;ISE_node_domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Received 119 bytes from &amp;lt;DNS_Server&amp;gt;#53 in 1 ms&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.gc._msdcs.&amp;lt;ISE_node_domain&amp;gt;.&amp;lt;ISE_node_domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Host _ldap._tcp.gc._msdcs.&amp;lt;ISE_node_domain&amp;gt; not found: 3(NXDOMAIN)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Received 133 bytes from &amp;lt;DNS_Server&amp;gt;#53 in 1 ms&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;&amp;lt;Node_with_Issue&amp;gt;# nslookup _ldap._tcp.dc._msdcs.&amp;lt;ISE_node_domain&amp;gt; querytype SRV&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.dc._msdcs.&amp;lt;ISE_node_domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Received 119 bytes from &amp;lt;DNS_Server&amp;gt;#53 in 1 ms&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.dc._msdcs.&amp;lt;ISE_node_domain&amp;gt;.&amp;lt;ISE_node_domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Host _ldap._tcp.dc._msdcs.&amp;lt;ISE_node_domain&amp;gt; not found: 3(NXDOMAIN)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Received 133 bytes from &amp;lt;DNS_Server&amp;gt;#53 in 1 ms&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;&amp;lt;Node_with_Issue&amp;gt;# nslookup _ldap._tcp.dc._msdcs.&amp;lt;AD_Domain&amp;gt; querytype SRV&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.dc._msdcs.&amp;lt;AD_Domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;;; Truncated, retrying in TCP mode.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.dc._msdcs.&amp;lt;AD_Domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 20412&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 49, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;&amp;lt;Node_with_Issue&amp;gt;# nslookup _ldap._tcp.gc._msdcs.&amp;lt;AD_Domain&amp;gt; querytype SRV&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.gc._msdcs.&amp;lt;AD_Domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;;; Truncated, retrying in TCP mode.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;Trying "_ldap._tcp.gc._msdcs.&amp;lt;AD_Domain&amp;gt;"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 40003&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#003366"&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 47, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="georgia,palatino" size="3" color="#003366"&gt;So there is a response from the domain where the nodes are being joined and failing.&lt;BR /&gt;This is error reported while adding back node&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dgaikwad_2-1665128880203.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/164286i4755F6596661E05F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dgaikwad_2-1665128880203.png" alt="dgaikwad_2-1665128880203.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 07:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699785#M577631</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2022-10-07T07:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes and external AD are in different domain</title>
      <link>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699832#M577632</link>
      <description>&lt;P&gt;It looks like the DNS SRV entries are not created for this ISE node that you are trying to join, and this is why it is failing imo, or, this ISE node is not configured with the right DNS servers.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 09:22:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nodes-and-external-ad-are-in-different-domain/m-p/4699832#M577632</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-07T09:22:01Z</dc:date>
    </item>
  </channel>
</rss>

