<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE server will not join AD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166738#M591445</link>
    <description>&lt;P&gt;Thanks for the response, Rob!&amp;nbsp; the DC's and ISE servers are all in sync timewise.&amp;nbsp; It will go through the point of creating an object in AD&amp;gt;&amp;nbsp; It will then give an error "Cannot Join with DC (name of device), searching for another DC"&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Creds are valid and the user appears to have access if it is creating the object.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Idea what is causing this? I cannot create the Dot1x policies without this&lt;/P&gt;</description>
    <pubDate>Tue, 27 Aug 2024 19:35:09 GMT</pubDate>
    <dc:creator>kyle311</dc:creator>
    <dc:date>2024-08-27T19:35:09Z</dc:date>
    <item>
      <title>ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166622#M591439</link>
      <description>&lt;P&gt;I have a client who has 2 cisco ise 3.2 servers.&amp;nbsp; When we try to join the first server to AD, it will fail out halfway through.&amp;nbsp; There is connectivity between the ISE server and AD, as the network object will be created.&amp;nbsp; However, the process dies out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions on what may be causing this?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 16:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166622#M591439</guid>
      <dc:creator>kyle311</dc:creator>
      <dc:date>2024-08-27T16:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166624#M591440</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1576730"&gt;@kyle311&lt;/a&gt; is ISE and Active Directory time in sync, the maximum time difference between AD and ISE can be is 5 minutes. &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215233-identity-service-engine-ise-and-active.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215233-identity-service-engine-ise-and-active.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Does ISE provide an error?&lt;/P&gt;
&lt;P&gt;Can ISE resolve the AD DNS names?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 16:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166624#M591440</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-08-27T16:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166738#M591445</link>
      <description>&lt;P&gt;Thanks for the response, Rob!&amp;nbsp; the DC's and ISE servers are all in sync timewise.&amp;nbsp; It will go through the point of creating an object in AD&amp;gt;&amp;nbsp; It will then give an error "Cannot Join with DC (name of device), searching for another DC"&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Creds are valid and the user appears to have access if it is creating the object.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Idea what is causing this? I cannot create the Dot1x policies without this&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 19:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166738#M591445</guid>
      <dc:creator>kyle311</dc:creator>
      <dc:date>2024-08-27T19:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166748#M591447</link>
      <description>&lt;P&gt;Also, yes, ISE can resolve DNS names.&amp;nbsp; devices can resolve the servers by FQDN, also&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 19:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166748#M591447</guid>
      <dc:creator>kyle311</dc:creator>
      <dc:date>2024-08-27T19:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166993#M591462</link>
      <description>&lt;P&gt;Hi Kyle311,&lt;/P&gt;&lt;P&gt;I once ran into this issue as well. Is there a firewall between the ISE servers and AD? If so, make sure that all mentioned ports are allowed in the firewall. Besides that, you mentioned that there are DNS entries created, did you also created the pointer records?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best of luck.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 09:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5166993#M591462</guid>
      <dc:creator>Abdullah@LTI</dc:creator>
      <dc:date>2024-08-28T09:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5167148#M591474</link>
      <description>&lt;P&gt;Hey Abdullah!&lt;/P&gt;&lt;P&gt;Thank you for your response.&amp;nbsp; Unfortunately, there doesn't appar to be a firewall between the ISE Servers and the AD servers.&amp;nbsp; The DNS and pointers are in place.&amp;nbsp; I can ping the DC's fqdn from the servers command line.&amp;nbsp; I can ping the ise server from the dc by fqdn. It makes absolutely no sense to me&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5167148#M591474</guid>
      <dc:creator>kyle311</dc:creator>
      <dc:date>2024-08-28T13:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5167161#M591478</link>
      <description>&lt;P&gt;Can you share some screenshots and maybe the errors?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5167161#M591478</guid>
      <dc:creator>Abdullah@LTI</dc:creator>
      <dc:date>2024-08-28T14:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE server will not join AD</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5167168#M591483</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217351-ad-integration-for-cisco-ise-gui-and-cli.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217351-ad-integration-for-cisco-ise-gui-and-cli.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Use cli debug and share result here&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-server-will-not-join-ad/m-p/5167168#M591483</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-28T14:23:25Z</dc:date>
    </item>
  </channel>
</rss>

