<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Connector had to be restarted. Server=isepsn1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839297#M581844</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please try to find a clue by "debugging" the &lt;STRONG&gt;ad_agent.log&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;GUI&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Logging &amp;gt; Debug Log Configuration &amp;gt;&lt;/STRONG&gt; select the &lt;STRONG&gt;PSN&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Active Directory&lt;/STRONG&gt; from &lt;STRONG&gt;Warn&lt;/STRONG&gt; to &lt;STRONG&gt;Debug&lt;/STRONG&gt; or &lt;STRONG&gt;Trace&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;CLI&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;ise/admin# show logging application ad_agent.log&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Sat, 20 May 2023 04:08:37 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2023-05-20T04:08:37Z</dc:date>
    <item>
      <title>AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839138#M581837</link>
      <description>&lt;P&gt;I am running ISE 3.0 patch-3.&amp;nbsp; For the past two weeks, I see this message in ISE from one of my PSN nodes&lt;/P&gt;&lt;P&gt;AD Connector had to be restarted. Server=isepsn1&lt;/P&gt;&lt;P&gt;The tcpdump on the network showed that the rst package come from the Active Directory server at the exact time I see this message in ISE.&amp;nbsp; Is this an issue with ISE or ADs?&amp;nbsp; Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 15:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839138#M581837</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-05-19T15:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839143#M581838</link>
      <description>&lt;P&gt;I would probably install the latest patch for 3.0 before spending too much time troubleshooting.&amp;nbsp; Patch 3 is quite old at this point.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/td-p/4839138" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/td-p/4839138&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/identity-service-engine-software-3-0.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/identity-service-engine-software-3-0.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 15:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839143#M581838</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-05-19T15:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839175#M581839</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;:&amp;nbsp; you sound like true Cisco TAC engineer with the "upgrade to the latest patch" comment instead of trying to figure out what the issue is, LOL....&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 16:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839175#M581839</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-05-19T16:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839183#M581840</link>
      <description>&lt;P&gt;lol they do have a point though.&amp;nbsp; Patch 3 was released July 27, 2021 so almost two full years ago.&amp;nbsp; That's an ancient time in software lifecycle with zero vulnerability or bug fixes.&amp;nbsp; Within that timeframe two new major releases of ISE have also been released.&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 17:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839183#M581840</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-05-19T17:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839206#M581842</link>
      <description>&lt;P&gt;LOL...Yes, but ISE 3.2 is severely "broken" and not too many people are using it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You don't know if upgrading to the latest patch will fix the issue instead of investigating the actual issue and confirm whether the latest patch will fix it.&amp;nbsp; Not hoping the latest patch will fix it.&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 18:39:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839206#M581842</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-05-19T18:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839213#M581843</link>
      <description>&lt;P&gt;Can you elaborate on "Severely broken"?&amp;nbsp; I know of several deployments running 3.2 Patch 1 expressly for the Azure AD integration for EAP-TLS authorization without issue.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's true I don't know that; I'm just offering a potential fix that might save time troubleshooting.&amp;nbsp; Its something that should be done anyways...&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 19:04:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839213#M581843</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-05-19T19:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839297#M581844</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please try to find a clue by "debugging" the &lt;STRONG&gt;ad_agent.log&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;GUI&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Logging &amp;gt; Debug Log Configuration &amp;gt;&lt;/STRONG&gt; select the &lt;STRONG&gt;PSN&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Active Directory&lt;/STRONG&gt; from &lt;STRONG&gt;Warn&lt;/STRONG&gt; to &lt;STRONG&gt;Debug&lt;/STRONG&gt; or &lt;STRONG&gt;Trace&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;CLI&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;ise/admin# show logging application ad_agent.log&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2023 04:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4839297#M581844</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-05-20T04:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4842750#M581954</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;:&amp;nbsp; Severely broken as:&amp;nbsp; 1- Integration with Active Directory doesn't work; 2- External authentication with radius server (the external radius is another Cisco ISE) does not work; 3- ssh stops working for no reason (tcpdump showed ssh requests get to the ISE server but no ssh reply).&amp;nbsp; I am sure there are other things that are not working but I am still stuck on item #1 and #2 because it is a show stopper for me so far.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 11:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4842750#M581954</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-05-25T11:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4842785#M581955</link>
      <description>&lt;P&gt;Interesting do you have TAC cases open for these?&amp;nbsp; I have several 3.2 deployments joined to on-prem AD without issue.&amp;nbsp; I haven't tested the external RADIUS sever configuration on 3.2 but I am curious on the the use-case for relaying to another ISE deployment.&amp;nbsp; Is this for a migration?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 12:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4842785#M581955</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-05-25T12:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4842893#M581957</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;:&amp;nbsp; Yes, my ISE 3.2 patch-2 does NOT have issue with joining Active Directory.&amp;nbsp; It joins just fine and I can also test the user.&amp;nbsp; However, when I attempted to create a wireless guest user with AD credential, I didn't see any communications between ISE and AD servers.&amp;nbsp; Yes, I have multiple tickets open with TAC on many issues regarding ISE 3.2, and they are very slow in responding so far.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 14:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4842893#M581957</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-05-25T14:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: AD Connector had to be restarted. Server=isepsn1</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4931779#M584312</link>
      <description>&lt;P&gt;A colleague of mine opened a TAC case with Cisco for this exact issue and the TAC is not very helpful.&amp;nbsp; It looks like not even TAC is very knowledgable with this product.&amp;nbsp; Cisco's response:&amp;nbsp; please upgrade to patch-8.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 21:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-connector-had-to-be-restarted-server-isepsn1/m-p/4931779#M584312</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-09-29T21:25:01Z</dc:date>
    </item>
  </channel>
</rss>

