<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to Join AD to multiple domains in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5125573#M589859</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have ISE 3.2 two node deployment. I have joined them to domain &lt;STRONG&gt;abc.com&lt;/STRONG&gt;. ISE uses DNS servers of abc.com domain.&lt;/P&gt;
&lt;P&gt;Now I want to join ISE nodes to another independent domain &lt;STRONG&gt;efg.com&lt;/STRONG&gt;. I have created host aliases for efg.com pointing IP addresses of efg.com domain controller (&lt;STRONG&gt;ip host 192.168.1.2 efg.com&lt;/STRONG&gt;). Ping to efg.com is successful but I am not able to join ISE.&lt;BR /&gt;&lt;BR /&gt;I have started tcp dump on ISE and when I try to join to efg.com it does not send any traffic to efg.com.&lt;/P&gt;
&lt;P&gt;This is the result of tests from ISE:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="llomjaria_0-1717575424467.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/220074i1DD8B0785B89A6A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="llomjaria_0-1717575424467.png" alt="llomjaria_0-1717575424467.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 08:17:10 GMT</pubDate>
    <dc:creator>llomjaria</dc:creator>
    <dc:date>2024-06-05T08:17:10Z</dc:date>
    <item>
      <title>How to Join AD to multiple domains</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5125573#M589859</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have ISE 3.2 two node deployment. I have joined them to domain &lt;STRONG&gt;abc.com&lt;/STRONG&gt;. ISE uses DNS servers of abc.com domain.&lt;/P&gt;
&lt;P&gt;Now I want to join ISE nodes to another independent domain &lt;STRONG&gt;efg.com&lt;/STRONG&gt;. I have created host aliases for efg.com pointing IP addresses of efg.com domain controller (&lt;STRONG&gt;ip host 192.168.1.2 efg.com&lt;/STRONG&gt;). Ping to efg.com is successful but I am not able to join ISE.&lt;BR /&gt;&lt;BR /&gt;I have started tcp dump on ISE and when I try to join to efg.com it does not send any traffic to efg.com.&lt;/P&gt;
&lt;P&gt;This is the result of tests from ISE:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="llomjaria_0-1717575424467.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/220074i1DD8B0785B89A6A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="llomjaria_0-1717575424467.png" alt="llomjaria_0-1717575424467.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 08:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5125573#M589859</guid>
      <dc:creator>llomjaria</dc:creator>
      <dc:date>2024-06-05T08:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to Join AD to multiple domains</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5126123#M589869</link>
      <description>&lt;P&gt;I am not an AD expert, but if the other efg.com domain is not sharing/exchanging some of its DNS records with abc.com, then ISE (sitting on abc.com?) won't be able to resolve all the DNS records for efg.com (SRV records etc.).&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 20:13:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5126123#M589869</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-06-05T20:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to Join AD to multiple domains</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5126451#M589883</link>
      <description>&lt;P&gt;These two domain controllers are independent of each other, they do NOT have any trust between them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to know how to add second active directory in ISE. I could not find technical information about it.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 11:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5126451#M589883</guid>
      <dc:creator>llomjaria</dc:creator>
      <dc:date>2024-06-06T11:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to Join AD to multiple domains</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5126501#M589885</link>
      <description>&lt;P&gt;You need configured DNS server(s) that able to resolve all of the second domain's records. Simply putting a host record for the domain controller will not suffice. Look, for example, at all the tests that run during an AD daily health check. Those should be able to&amp;nbsp; pass for both domains.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 12:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5126501#M589885</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-06-06T12:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to Join AD to multiple domains</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5127385#M589922</link>
      <description>&lt;P&gt;i have done it.. its just like defining the first one... but as Marvin says you need to have DNS resolve both domains..&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2024 05:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-join-ad-to-multiple-domains/m-p/5127385#M589922</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-06-08T05:57:19Z</dc:date>
    </item>
  </channel>
</rss>

