<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE with ldap (Active Directory) authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816743#M581233</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a problem with Cisco iSE in Active Directory domain as well as adding to the domain. I don't have much experience with ISA and RADIUS.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Join to Active Directory:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When I try to add ISE to a domain I get the message:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error Description: The DC closed an LDAP connection in the middle of a query&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Support Details...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error Name: LW_ERROR_LDAP_SERVER_DOWN&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error Code: 40286&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;- DNS are configured correctly, nslookup sees the server, ping works for the domain, ntp server is configured.&lt;BR /&gt;- I'm using the domain administrator account for credentials&lt;/P&gt;&lt;P&gt;I did not configure anything on the domain controller&lt;/P&gt;&lt;P&gt;Are you able to help in the case of joining ActiveDirectory?&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 08:26:56 GMT</pubDate>
    <dc:creator>aquku</dc:creator>
    <dc:date>2023-04-18T08:26:56Z</dc:date>
    <item>
      <title>ISE with ldap (Active Directory) authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816743#M581233</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a problem with Cisco iSE in Active Directory domain as well as adding to the domain. I don't have much experience with ISA and RADIUS.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Join to Active Directory:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When I try to add ISE to a domain I get the message:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error Description: The DC closed an LDAP connection in the middle of a query&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Support Details...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error Name: LW_ERROR_LDAP_SERVER_DOWN&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error Code: 40286&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;- DNS are configured correctly, nslookup sees the server, ping works for the domain, ntp server is configured.&lt;BR /&gt;- I'm using the domain administrator account for credentials&lt;/P&gt;&lt;P&gt;I did not configure anything on the domain controller&lt;/P&gt;&lt;P&gt;Are you able to help in the case of joining ActiveDirectory?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 08:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816743#M581233</guid>
      <dc:creator>aquku</dc:creator>
      <dc:date>2023-04-18T08:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with ldap (Active Directory) authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816777#M581234</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- This seems somewhat similar :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm87060" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm87060&lt;/A&gt;&amp;nbsp;, what is your ISE&lt;STRONG&gt; version&lt;/STRONG&gt; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 09:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816777#M581234</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-04-18T09:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with ldap (Active Directory) authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816784#M581235</link>
      <description>&lt;P&gt;Version: 2.6.0.156&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 09:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816784#M581235</guid>
      <dc:creator>aquku</dc:creator>
      <dc:date>2023-04-18T09:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with ldap (Active Directory) authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816854#M581238</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Following these info's you may want to debug the issue :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html#anc24" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html#anc24&lt;/A&gt;&amp;nbsp; &amp;nbsp; and&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=z0OzlulOnsw" target="_blank"&gt;https://www.youtube.com/watch?v=z0OzlulOnsw&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; Possible use microsoft eventvwr and watch for related LDAP events , or else raise a &lt;STRONG&gt;TAC&lt;/STRONG&gt; case ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 10:28:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816854#M581238</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-04-18T10:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with ldap (Active Directory) authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816984#M581248</link>
      <description>&lt;P&gt;LDAP or LDAPS?&amp;nbsp; Make sure the DC isn't expecting a secure connection and rejecting because it's not.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 14:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4816984#M581248</guid>
      <dc:creator>Christopher Bell</dc:creator>
      <dc:date>2023-04-18T14:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with ldap (Active Directory) authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4821934#M581383</link>
      <description>&lt;P&gt;I think that may be the problem. I did not create an encrypted connection between the ISE and the DC.&lt;BR /&gt;Is there documentation somewhere showing how to connect the ISE using LDAPS? Because in the settings I don't see the option to encrypt/add a certificate when adding or do I need to configure an external LDAPS connection and then try to add to the domain?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Domain Control is Windows Server 2019&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I thought now if the problem could be "ip domain-name"? Because the person configuring ISE set ip domain-name to "cisco.com", host name "ise". When trying to add to the domain and see ise.cisco.com. Maybe this is the problem? What should I do in this case?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-active-directory-authentication/m-p/4821934#M581383</guid>
      <dc:creator>aquku</dc:creator>
      <dc:date>2023-04-26T13:56:00Z</dc:date>
    </item>
  </channel>
</rss>

