<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SRV record found.Not all SRV records have IP, will need to run add in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4907482#M583494</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/8372"&gt;@drichards21&lt;/a&gt;&amp;nbsp;that's a brilliant article that explains the issue really well. The original developer who worked on the ISE AD section was a top bloke - I think there is a Cisco Live session somewhere in the archives - and I always wonder if he still works at Cisco. The trick is to get the attention of Cisco to address this issue. Feature Request, TAC case or both.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Aug 2023 21:04:18 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2023-08-17T21:04:18Z</dc:date>
    <item>
      <title>SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4004239#M454768</link>
      <description>&lt;P&gt;First of all, this post has nothing to do with&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/td-p/3927645" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/identity-services-engine-ise/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/td-p/3927645&lt;/A&gt;.&amp;nbsp; I do not have too many domain controllers or SRV records and the response is not getting truncated.&amp;nbsp; I have brought my case to TAC, and they cannot seem to get the above mentioned truncation issue out of their head - so I am looking for some assistance here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;I have scheduled my ISE servers to run Active Directory diagnostics every night to ensure that the connection to Active Directory is healthy.&amp;nbsp; Tests executed during this diagnostic routine are as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;DNS A record high level API query&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;DNS A record low level API query&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;DNS SRV record query&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;DNS SRV record size&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Kerberos check SASL connectivity to AD&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Kerberos test bind and query to ROOT DSE&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Kerberos test obtaining join point TGT&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;LDAP test - DC locator&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;LDAP test - GC locator&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;LDAP test AD site association&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;LDAP test DCs availability&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;LDAP test DCs response time&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;System health - check AD service&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;System health - check DNS configuration&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;System health - check NTP&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All tests come back as successful – except the “DNS SRV record query” test:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Warning:&lt;/EM&gt;&lt;/STRONG&gt; &lt;STRONG&gt;&lt;EM&gt;SRV record found. Not all SRV records have IP, will need to run additional query for get IP&lt;/EM&gt;&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason for this warning is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Our DNS Servers have the “Minimal-Responses” option set to “True” (see &lt;A href="https://tools.ietf.org/html/rfc8482" target="_blank" rel="noopener"&gt;https://tools.ietf.org/html/rfc8482&lt;/A&gt;).&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt; This limits the response to the ISE query so it does not include the IP addresses of the AD domain controllers.&amp;nbsp; A quick Google search of DNS and “Minimal Responses” shows that “True” is the default setting in Infoblox and Bind – and it seems to be a standard practice to maintain that setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what is the big deal:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rather innocuous warning message above in 1 out of 15 diagnostic tests generates a system-wide “Warning” level alert to be generated – stating:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Active directory diagnostic tool found issues - One or more Active Directory diagnostic tests failed during a scheduled run.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So now – we have a situation where an expected response during a schedule diagnostic test – generates a &lt;STRONG&gt;&lt;EM&gt;“failed”&lt;/EM&gt;&lt;/STRONG&gt; alert to our operations staff of a significance that would typically generate an incident report (and possible page-out).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only mitigation steps I can think of both seem to be unacceptable:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I could reduce the severity of the “&lt;STRONG&gt;&lt;EM&gt;Active Directory Diagnostics tests failed&lt;/EM&gt;&lt;/STRONG&gt;” alert; but then I will not be alerted if one of the other 14 diagnostic tests fail.&lt;/LI&gt;&lt;LI&gt;I could just “not run” a scheduled AD diagnostic test – but then I lose the ability to ensure that the ISE AD connection is healthy.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything else I can do here?&amp;nbsp; Can I somehow remove this test from the schedule, change the test, etc.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 22:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4004239#M454768</guid>
      <dc:creator>MNBob</dc:creator>
      <dc:date>2019-12-27T22:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4005399#M454769</link>
      <description>&lt;P&gt;If TAC doesn't have idea then please escalate it. This is not a replacement for TAC. Will see if any ideas can be forwarded around. Did you look at this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://ciscolive.cisco.com/on-demand-library/?search=ise%20active%20directory#/session/14525434149870017MRf" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;What's new in ISE Active Directory connector - BRKSEC-2132&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Chris Murray, Technical Leader, Cisco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Cisco Identity Services Engine (ISE) integrates with Active Directory using a new connector. We will introduce new features, concepts and troubleshooting tools as well as Best Practices to help you avoid and resolve issues. This session is a pre-requisite to any ISE deployment when you have been deploying multiple Active Directory in your Company.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2020 04:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4005399#M454769</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2020-01-02T04:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4005608#M454770</link>
      <description>&lt;P&gt;Thanks for the reply - and the link.&amp;nbsp; It was nice to get a refresher on the AD connector - though it really has nothing to do with the issue here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue actually is as follows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A single step of an ISE 15 steps diagnostic routine is assuming that a valid and expected response form a DNS query is an error condition - and it is generating a false warning alert - not just for that subset - but for the ENTIRE diagnostic routine.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;The false warning significantly reduces the value of the diagnostic routine, in that it requires human analysis to decide upon whether the alert means that an error condition actually exists or if the false positive is the only issue being reported.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Also note:&amp;nbsp; I am not trying to use this forum as a replacement for TAC.&amp;nbsp; I was guessing that this issue was somewhat prevalent - given that we are using DNS default settings - so I was wondering if anybody else might know a strategy for suppressing 1/15th of a diagnostic routine that I could not find.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will take your advice and try again with TAC - though I am certain they will point to the truncation issue again and I will try to fight my way through it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2020 15:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4005608#M454770</guid>
      <dc:creator>MNBob</dc:creator>
      <dc:date>2020-01-02T15:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4005817#M454771</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/462578"&gt;@MNBob&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interesting indeed. I learned something about DNS through your post. I hope the TAC can assist you.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The AD integration in ISE is generally very well thought out and coded. But needs some updating. Eg. If I join 1 node to AD then I must join ALL remaining nodes to AD to avoid the Alarm “ISE not joined to AD”. You cannot suppress that without turning off all AD integration Alarming (bad idea). A simple switch to tune the AD alarms would be nice. I recall putting in a feature request ages ago.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2020 23:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4005817#M454771</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-01-02T23:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4006246#M454772</link>
      <description>right and best to work with tac to get cases logged and &lt;A href="http://cs.co/ise-feedback" target="_blank"&gt;http://cs.co/ise-feedback&lt;/A&gt; into the PMs</description>
      <pubDate>Fri, 03 Jan 2020 20:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4006246#M454772</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2020-01-03T20:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4280309#M565046</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/462578"&gt;@MNBob&lt;/a&gt;&amp;nbsp;Hi, just wondering if you found any solution to this? Though this doesn't affect any of the services currently, it does however continuously generate this same alert warning message that you are experiencing (1/15 tests warning) and our AD diagnostic tool is also scheduled to run every day. Hope you can share your solution if you've found any.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running ISE 2.7 patch 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 07:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4280309#M565046</guid>
      <dc:creator>joseponceiii</dc:creator>
      <dc:date>2021-01-27T07:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run additional query for get IP.</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4280654#M565066</link>
      <description>&lt;P&gt;Unfortunately no solution yet.&amp;nbsp; Just hoping Cisco puts it into a future release.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 15:51:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4280654#M565066</guid>
      <dc:creator>MNBob</dc:creator>
      <dc:date>2021-01-27T15:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4715086#M578041</link>
      <description>&lt;P&gt;I have a different take on this "error".&amp;nbsp; It's not an error. per se, but it is an inefficiency perhaps.&amp;nbsp; I have had this issue in multiple versions of ISE, and I've essentially ignored it for at least 4 years.&amp;nbsp; Look at what the error says:&amp;nbsp; It says it could not find an IP, and that a second query would need to be run to find it. A forward DNS query looks up a name, in this case, the name of a particular SRV record, and it expects to get an IP address as the response.&amp;nbsp; That's just the way DNS works.&amp;nbsp; If you look up a name, and you&amp;nbsp; get another name, you then need to look up that second name to get an IP.&lt;/P&gt;&lt;P&gt;Assuming that SRV records exist in your DNS for each of your AD Domain controllers, you need to look at the actual data in the records.&amp;nbsp; For example,&amp;nbsp; if you have a SRV record for _ldap._tcp.dc._msdcs.foobar.org, it will have entries for Priority, Weight, Port, and Target, the Target being one of the Domain Controllers in your domain.&amp;nbsp; You'll have one of these records for each DC.&amp;nbsp; The AD guys in my group put the FQDN of the Domain Controller in the Target field.&amp;nbsp; I'm suggesting that you enter in the IP address of the Domain Controller in the field for each of the _ldap._tcp.dc._msdcs and possibly the _kerberos._tcp.dc._msdcs SRV records.&lt;/P&gt;&lt;P&gt;If you use DNS to preform a lookup and it responds with a name, it then has to perform a lookup on the response to get the IP.&amp;nbsp; That's two lookups, and that's inefficient.&amp;nbsp; I mentioned this once to our AD guys, and they looked at me like I had two heads.&amp;nbsp; I believe it's a quirk of Microsoft.&amp;nbsp; It wouldn't be the first time Microsoft didn't follow best practices.&lt;/P&gt;&lt;P&gt;So, in brief, you have a bunch of SRV records that exist to allow lookups to find one of many Domain Controllers.&amp;nbsp; When using AD as an External Identity Source, ISE expects to find a _ldap._tcp.dc._msdcs.&amp;lt;domain&amp;gt; record and a&amp;nbsp;_kerberos._tcp.dc._msdcs.&amp;lt;domain&amp;gt; for each DC.&amp;nbsp; If these records exist, and the target is the FQDN of each DC, I'm suggesting you replace the FQDN with the IP address of the DC.&amp;nbsp; I'd love to hear alternative takes on this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 18:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4715086#M578041</guid>
      <dc:creator>fitzie</dc:creator>
      <dc:date>2022-11-02T18:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4807975#M580944</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;We are now at version 3.1 Patch 5 and are still getting this alert.&lt;/P&gt;&lt;P&gt;I have a few a few days to spare so I'll log a case with TAC and post the results to here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 23:45:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4807975#M580944</guid>
      <dc:creator>jvujcich</dc:creator>
      <dc:date>2023-04-04T23:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4907360#M583492</link>
      <description>&lt;P&gt;Any answers yet?&amp;nbsp; I am on ISE 3.0 p7 and have had this issue as long as I can remember going back to at least 2.4 if not the original ISE 1.0.&amp;nbsp; It would be nice to get a fix for this.&lt;BR /&gt;&lt;BR /&gt;I had hope this would go away on version 3.x and above.&amp;nbsp; Also this blog has been around for a bit and they go over the issue.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.lookingpoint.com/blog/cisco-ise-ad-diagnostic-srv-record-query-alert" target="_blank" rel="noopener"&gt;https://www.lookingpoint.com/blog/cisco-ise-ad-diagnostic-srv-record-query-alert&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 19:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4907360#M583492</guid>
      <dc:creator>drichards21</dc:creator>
      <dc:date>2023-08-17T19:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4907482#M583494</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/8372"&gt;@drichards21&lt;/a&gt;&amp;nbsp;that's a brilliant article that explains the issue really well. The original developer who worked on the ISE AD section was a top bloke - I think there is a Cisco Live session somewhere in the archives - and I always wonder if he still works at Cisco. The trick is to get the attention of Cisco to address this issue. Feature Request, TAC case or both.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 21:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4907482#M583494</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-08-17T21:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4941152#M584623</link>
      <description>&lt;P&gt;As helpful as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/8372"&gt;@drichards21&lt;/a&gt;&amp;nbsp;linked article is, it does not truly explain the fact you will still see this warning while bound to a forest of a single AD server and a 130 bytes long message size:&lt;/P&gt;&lt;PRE&gt;# nslookup -type=srv _ldap._tcp.dc._msdcs.domain.com 192.168.9.200&lt;BR /&gt;Server: 192.168.9.200&lt;BR /&gt;Address: 192.168.9.200#53&lt;BR /&gt;&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.com service = 0 100 389 w2k19.domain.com.&lt;BR /&gt;&lt;BR /&gt;# dig @192.168.9.200 -t srv _ldap._tcp.dc._msdcs.domain.com +edns&lt;BR /&gt;&lt;BR /&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.19.17 &amp;lt;&amp;lt;&amp;gt;&amp;gt; @192.168.9.200 -t srv _ldap._tcp.dc._msdcs.domain.com +edns&lt;BR /&gt;; (1 server found)&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 50388&lt;BR /&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1&lt;BR /&gt;&lt;BR /&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 1232&lt;BR /&gt;; COOKIE: 2156a6b47d716f7b01000000652d4e6a73c60d81bb5f7e1c (good)&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;_ldap._tcp.dc._msdcs.domain.com. IN SRV&lt;BR /&gt;&lt;BR /&gt;;; ANSWER SECTION:&lt;BR /&gt;_ldap._tcp.dc._msdcs.domain.com. 600 IN SRV 0 100 389 w2k19.domain.com.&lt;BR /&gt;&lt;BR /&gt;;; Query time: 0 msec&lt;BR /&gt;;; SERVER: 192.168.9.200#53(192.168.9.200) (UDP)&lt;BR /&gt;;; WHEN: Mon Oct 16 10:53:30 EDT 2023&lt;BR /&gt;;; MSG SIZE rcvd: 130&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;#_&lt;/PRE&gt;&lt;P&gt;There must be more on this topic than just the EDNS or UDP packet size, and if TAC gave this as a suggestion, I would challenge it.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 15:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4941152#M584623</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2023-10-16T15:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4941445#M584645</link>
      <description>&lt;P&gt;I have to admit that in my lab, ISE 3.2p3 and two Windows Server 2016 Standard domain controllers (patched to the eyeballs) I don't get this AD Healthcheck issue. But I do see it with my customers who have a much larger number of domain controllers.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 23:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/4941445#M584645</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-10-16T23:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/5261597#M595040</link>
      <description>&lt;P&gt;Hi Arne!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same deployment on production, and I am seeing the issue—just FYI. I will open a TAC and keep you all posted&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 20:25:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/5261597#M595040</guid>
      <dc:creator>acazarez</dc:creator>
      <dc:date>2025-02-17T20:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: SRV record found.Not all SRV records have IP, will need to run add</title>
      <link>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/5270674#M595448</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;This is what I got from Cisco TAC&lt;/P&gt;&lt;P&gt;=====================================================================================&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Hello, Antonio,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have checked internally and identified that the issue you’re experiencing is known in &lt;STRONG&gt;version 3.x&lt;/STRONG&gt;, &lt;STRONG&gt;especially&lt;/STRONG&gt; when the domain controllers (DC) &lt;STRONG&gt;count is five or more&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;The alarm is just a warning, and it indicates that part of the SRV records does not contain the server's IP address; it contains only FQDN. Hence, ISE will need to run additional queries (for 'A' records) to get the DCs' IP addresses.&lt;/P&gt;&lt;P&gt;There is a cosmetic bug and filed as enhancement, not yet fixed. &lt;A href="https://urldefense.com/v3/__https:/bst.cisco.com/bugsearch/bug/CSCwb93856__;!!Dxphqqae7gr6Smc!sSdOIHwpUyOXR5l3lKgHmaevaZJRHpVn4EyADiWUOwBe6UPyBDBhZS6aX8KZksICCzL9kDqIPi9k0jq4KIx8yw$" target="_blank" rel="noopener"&gt;https://bst.cisco.com/bugsearch/bug/CSCwb93856&lt;/A&gt; ENH: ISE 3.X: Improve logic for "DNS SRV record query" AD alarm.&lt;/P&gt;&lt;P&gt;You may choose to disregard the warning for now. Additionally, you can subscribe to the enhancement linked above to receive updates.&lt;/P&gt;&lt;P&gt;===================================================================&lt;/P&gt;&lt;P&gt;I am planning to upgrade from 3.2 P3 later this year. I just migrated all my deployments from ESXi to AHV, so I am kind of tired of chasing this ghost now.&lt;/P&gt;&lt;P&gt;I hope this works for someone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 05:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/srv-record-found-not-all-srv-records-have-ip-will-need-to-run/m-p/5270674#M595448</guid>
      <dc:creator>acazarez</dc:creator>
      <dc:date>2025-03-13T05:02:24Z</dc:date>
    </item>
  </channel>
</rss>

