<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE PIC 3.4 RPC connect to domain controller failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213544#M592593</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have installed Cisco ISE PIC 3.4 version and use RPC agent as connection with AD. Made integration with FMC and create rule to filter URL per user. I have noticed that FMC don't get information when user log off and FMC alone in some time make logoff user, then tomorrow when i make login in PC, ISE PIC and FMC don't get that info, when i found live session my IP and manually run check current user i get info in FMC that user is login then URL filtering continue working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what i noticed in log .&lt;/P&gt;
&lt;P&gt;RPC connect to domain controller failed&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="farukzaimovic_0-1729678220196.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232108i4E09825F7217C05D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="farukzaimovic_0-1729678220196.png" alt="farukzaimovic_0-1729678220196.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anybody have same problem, please share.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Oct 2024 10:10:32 GMT</pubDate>
    <dc:creator>faruk.zaimovic</dc:creator>
    <dc:date>2024-10-23T10:10:32Z</dc:date>
    <item>
      <title>Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213544#M592593</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have installed Cisco ISE PIC 3.4 version and use RPC agent as connection with AD. Made integration with FMC and create rule to filter URL per user. I have noticed that FMC don't get information when user log off and FMC alone in some time make logoff user, then tomorrow when i make login in PC, ISE PIC and FMC don't get that info, when i found live session my IP and manually run check current user i get info in FMC that user is login then URL filtering continue working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what i noticed in log .&lt;/P&gt;
&lt;P&gt;RPC connect to domain controller failed&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="farukzaimovic_0-1729678220196.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232108i4E09825F7217C05D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="farukzaimovic_0-1729678220196.png" alt="farukzaimovic_0-1729678220196.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anybody have same problem, please share.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 10:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213544#M592593</guid>
      <dc:creator>faruk.zaimovic</dc:creator>
      <dc:date>2024-10-23T10:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213554#M592594</link>
      <description>&lt;P&gt;Did you check if the agent is running as expected on the DC?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216512-configure-evt-based-identity-services-en.html" target="_blank"&gt;Configure EVT-Based Identity Services Engine Passive ID Agent - Cisco&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 10:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213554#M592594</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-23T10:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213571#M592595</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for answer.&lt;/P&gt;
&lt;P&gt;Agent are correct installed and in running mode. I have primary and secondary agent same as u send link for Passive ID Agent, When I made run test to AD i got strange messages. Picture below. Could not obtain TGT..... i dont know how to set it in AD,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="farukzaimovic_0-1729681145024.png" style="width: 395px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232110iAAD936E0E94BDEBA/image-dimensions/395x222?v=v2" width="395" height="222" role="button" title="farukzaimovic_0-1729681145024.png" alt="farukzaimovic_0-1729681145024.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 10:59:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213571#M592595</guid>
      <dc:creator>faruk.zaimovic</dc:creator>
      <dc:date>2024-10-23T10:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213600#M592597</link>
      <description>&lt;P&gt;To me it looks like an issue with kerberos on the AD. Do you see any interesting logs on the AD related to ISE diagnostics?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 11:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5213600#M592597</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-23T11:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5214905#M592665</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thank you very much for your response.&lt;/P&gt;
&lt;P&gt;I have same opinion that problem is in AD, I just check that problem is not connected for ISE PIC.&lt;/P&gt;
&lt;P&gt;It works if i have that problem, I can see users in my FMC over PxGrid normaly, but what I noticed that ISE PIC agent over PxGrid send all users from AD to FMC. Does anybody do it, in User activity I can see all users from AD, If i do passive authetication only for one AD group. Is there any way to limit users . I treid it over REALM authetication and limit that group, but it is works only when I create policy which group and which users I can see and add in rule.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for help.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 05:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5214905#M592665</guid>
      <dc:creator>faruk.zaimovic</dc:creator>
      <dc:date>2024-10-25T05:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5214996#M592669</link>
      <description>&lt;P&gt;When you say tried to limit the groups was that from the Realm config under the "User Download &amp;gt; Groups to include" page?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 08:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5214996#M592669</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-25T08:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5215421#M592694</link>
      <description>&lt;P&gt;Aref,&lt;/P&gt;
&lt;P&gt;Yes, in user activity I can see all users from AD, i would like to see only users from one AD groupe, in that user i would apply passive atuhetication. I dont know it is possible. I could not find any options.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aref as u said, in Realm options for dowload users a only type one AD group, and again i can see all users from AD in user activity.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Oct 2024 05:45:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5215421#M592694</guid>
      <dc:creator>faruk.zaimovic</dc:creator>
      <dc:date>2024-10-26T05:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5216279#M592734</link>
      <description>&lt;P&gt;I got the feeling that what you see is expected. Maybe&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;can help on this.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 16:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5216279#M592734</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-28T16:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PIC 3.4 RPC connect to domain controller failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5216981#M592798</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/460213"&gt;@faruk.zaimovic&lt;/a&gt; I don't believe that is possible.&lt;/P&gt;
&lt;P&gt;The only filtering we can do is to limit via a network filter in the FMC ISE integration. Such a filter causes ISE to report data from the networks within that filter. No such option for AD user or groups is currently available.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 18:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pic-3-4-rpc-connect-to-domain-controller-failed/m-p/5216981#M592798</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-10-29T18:20:38Z</dc:date>
    </item>
  </channel>
</rss>

