<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot  join ISE to Acive Directory(Cannot Join with DC) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-join-ise-to-acive-directory-cannot-join-with-dc/m-p/4830112#M581588</link>
    <description>&lt;P&gt;Hopefully you are not actually using &lt;FONT face="courier new,courier"&gt;dc.example.com&lt;/FONT&gt; since that is not real.&lt;/P&gt;
&lt;P&gt;It is good you can ping the domain but maybe other protocols (LDAP, Kerberos) are filtered by a firewall between ISE and your AD?&lt;/P&gt;
&lt;P&gt;I suggest calling TAC for troubleshooting at this point.&lt;/P&gt;</description>
    <pubDate>Sun, 07 May 2023 17:24:09 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2023-05-07T17:24:09Z</dc:date>
    <item>
      <title>Cannot  join ISE to Acive Directory(Cannot Join with DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ise-to-acive-directory-cannot-join-with-dc/m-p/4822863#M581404</link>
      <description>&lt;P&gt;I am trying to add ISE(version 2.6) to Active Directory(WS 2019) with domain administrator credentials. The user has domain groups admin and domain user I get the response:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error Description: Join failed, reached the maximum number of failover attempts&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Support Details...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error Name: LW_ERROR_JOIN_FAILED_REACHED_MAX_RETRIES&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error Code: 60113&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Detailed Log:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error Description : &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Join to EXAMPLE.COM failed : reached maximum number of failovers&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error Resolution : &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Please check for domain controllers connectivity replication problems in domain EXAMPLE.COM&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Join steps : &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Joining to domain EXAMPLE.COM using user domain_admin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Checking credentials for user domain_admin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Getting TGT for account domain_admin@EXAMPLE.COM &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 TGT for account domain_admin@EXAMPLE.COM was retrieved successfully &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Credentials for user domain_admin were verified &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:48:21 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Joining to domain EXAMPLE.COM using user domain_admin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Checking credentials for user domain_admin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Getting TGT for account domain_admin@EXAMPLE.COM &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 TGT for account domain_admin@EXAMPLE.COM was retrieved successfully &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Credentials for user domain_admin were verified &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC2.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC2.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC2.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC2.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC2.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC2.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC2.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC2.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Found DC: DC.example.com , client site is Default-First-Site-Name , dc site is Default-First-Site-Name &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Cannot Join with DC DC.example.com , searching another DC to join with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10:16:13 Searching for DC in domain EXAMPLE.COM&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;DNS and NTP servers have been configured to ISE, ISE ping the domain, nslookup also sees the domain. I also added an entry in the ISE domain DNS.&lt;BR /&gt;I think the problem lies in : &lt;EM&gt;Cannot Join with DC DC.example.com.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;But I don't know what the problem is or if any of you have encountered the problem.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 10:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ise-to-acive-directory-cannot-join-with-dc/m-p/4822863#M581404</guid>
      <dc:creator>aquku</dc:creator>
      <dc:date>2023-04-27T10:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot  join ISE to Acive Directory(Cannot Join with DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ise-to-acive-directory-cannot-join-with-dc/m-p/4822974#M581408</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Checkout :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-security/ise-cannot-join-active-directory/m-p/4290258#M1078414" target="_blank"&gt;https://community.cisco.com/t5/network-security/ise-cannot-join-active-directory/m-p/4290258#M1078414&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 12:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ise-to-acive-directory-cannot-join-with-dc/m-p/4822974#M581408</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-04-27T12:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot  join ISE to Acive Directory(Cannot Join with DC)</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-join-ise-to-acive-directory-cannot-join-with-dc/m-p/4830112#M581588</link>
      <description>&lt;P&gt;Hopefully you are not actually using &lt;FONT face="courier new,courier"&gt;dc.example.com&lt;/FONT&gt; since that is not real.&lt;/P&gt;
&lt;P&gt;It is good you can ping the domain but maybe other protocols (LDAP, Kerberos) are filtered by a firewall between ISE and your AD?&lt;/P&gt;
&lt;P&gt;I suggest calling TAC for troubleshooting at this point.&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2023 17:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-join-ise-to-acive-directory-cannot-join-with-dc/m-p/4830112#M581588</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-05-07T17:24:09Z</dc:date>
    </item>
  </channel>
</rss>

