<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE deployment with 2 different Active Directory servers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252139#M594456</link>
    <description>&lt;P&gt;I have single cluster.&lt;BR /&gt;I want migrate AD server. I want to second ISE&amp;nbsp;node use only different AD server. Then shutdown primary ISE node and promote secondary as primary with new AD server.&lt;BR /&gt;Should I setup nodes as standalone to be able to do it?&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jan 2025 11:48:47 GMT</pubDate>
    <dc:creator>victor-hugo</dc:creator>
    <dc:date>2025-01-24T11:48:47Z</dc:date>
    <item>
      <title>ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5251041#M594410</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;I am running ISE v3.1.0 with 2 nodes as PAN/PSN/MnT.&lt;BR /&gt;I need for second node to connect with different Active Directory Server in other subnet.&lt;BR /&gt;I've try with second node to Leave domain, but when I Join again is connecting to the same AD server as primary node.&lt;BR /&gt;In tab 'PassiveID' there is AD server that I want to connect to.&lt;BR /&gt;In CLI on second node I've setup new AD servers:&lt;BR /&gt;'ip name-server AD1newIPaddress AD2newIPaddress'&lt;BR /&gt;Reboot the ISE node, try to join domain again - did not work.&lt;BR /&gt;How this can be done?&lt;BR /&gt;Any ideas what I can try?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5251041#M594410</guid>
      <dc:creator>victor-hugo</dc:creator>
      <dc:date>2025-01-22T16:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5251195#M594415</link>
      <description>&lt;P&gt;if they are part of a single cluster, then the config is shared.. so all nodes will have the same AD and other configuraiton parameters.&lt;/P&gt;
&lt;P&gt;You can add a 2nd AD domain to the cluster, and have a identity source sequence to authenticate with both AD servers, or authentication policy can use one AD join point for some devices/other criteria and 2nd AD join point for other NAS/criteria.. what is your use case ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 20:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5251195#M594415</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-22T20:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252139#M594456</link>
      <description>&lt;P&gt;I have single cluster.&lt;BR /&gt;I want migrate AD server. I want to second ISE&amp;nbsp;node use only different AD server. Then shutdown primary ISE node and promote secondary as primary with new AD server.&lt;BR /&gt;Should I setup nodes as standalone to be able to do it?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 11:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252139#M594456</guid>
      <dc:creator>victor-hugo</dc:creator>
      <dc:date>2025-01-24T11:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252231#M594459</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1749614"&gt;@victor-hugo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1481123"&gt;@ccieexpert&lt;/a&gt;&amp;nbsp;already said, you are able to:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;In &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory &amp;gt;&lt;/STRONG&gt; &lt;STRONG&gt;Add&lt;/STRONG&gt; the &lt;U&gt;new&lt;/U&gt; &lt;STRONG&gt;Joint Point (Active Directory):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Active Directory New Joint Point.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238389iFA8823DFFAAD59E6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Active Directory New Joint Point.png" alt="Active Directory New Joint Point.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;In&amp;nbsp;&lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; Identity Source Sequences &amp;gt;&lt;/STRONG&gt;&amp;nbsp;select the &lt;STRONG&gt;Join Points&lt;/STRONG&gt; (both &lt;STRONG&gt;Active Directory&lt;/STRONG&gt;) to the &lt;STRONG&gt;Authentication Search List&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Identity Source Sequences.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238390iB8166FB99A4142FA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Identity Source Sequences.png" alt="Identity Source Sequences.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;After that in &lt;STRONG&gt;Policy &amp;gt; Policy Sets &amp;gt;&lt;/STRONG&gt; you should select the &lt;U&gt;new&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;Identity Source Sequence&lt;/STRONG&gt; in your &lt;STRONG&gt;Authentication Policy&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Policy Sets.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238391i2317BE764984167C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy Sets.png" alt="Policy Sets.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 14:25:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252231#M594459</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-24T14:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252477#M594474</link>
      <description>&lt;P&gt;It is not clear what you are trying to do exactly other than migrate AD server... but if you want to different AD server for each ISE, then it is best to keep them standalone. If you just need to sync the database (like NAS and policies etc), you can make them a cluster and sync from primary to secondary ,and then make them standalone after that, or you can take a backup from one device and restore on the other. Ofcourse, on the 2nd ISE BOX, you have to delete the first AD join point, and add the 2nd AD join point only... does that help ?&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 00:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252477#M594474</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-25T00:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252629#M594486</link>
      <description>&lt;P&gt;I don't believe you can manage that unless you break ISE cluster into two standalone servers. The command "ip name-server" is just to define the DNS servers on ISE, however, it does decide which AD server will be elected as the primary from ISE perspective. I'm assuming that all the old and the new AD servers are in the same forest, if so, then nothing should happen when you migrate to the new AD and you shutdown the old one. For instance, you can keep working on your AD migration without thouching anything on ISE, and once you finish the migration and the old AD servers are decommisioned, ISE will then find its way to the new AD servers.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 15:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5252629#M594486</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-25T15:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253053#M594516</link>
      <description>&lt;P&gt;Hey all, thanks for your help. I am new to ISE, so please understand my lack of experience.&amp;nbsp;&lt;BR /&gt;For now I just want to have ISE with 2 different AD server to tested.&lt;BR /&gt;End goal here is that old ADs will be shutdown as we moving to new data center with new AD servers.&lt;BR /&gt;ISE 'see' new AD servers in &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory &amp;gt; PassiveID&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="victorhugo_0-1737967011195.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238580i16E2907006490E26/image-size/medium?v=v2&amp;amp;px=400" role="button" title="victorhugo_0-1737967011195.png" alt="victorhugo_0-1737967011195.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If old ADs will be shutdown, will ISE automatically switch to AD servers that are available - the once form &lt;STRONG&gt;PassiveID&amp;nbsp;&lt;/STRONG&gt;list?&lt;BR /&gt;&lt;BR /&gt;Thank you all for your input.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 08:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253053#M594516</guid>
      <dc:creator>victor-hugo</dc:creator>
      <dc:date>2025-01-27T08:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253220#M594531</link>
      <description>&lt;P&gt;That will be what I expect. In fact when we join ISE to the domain we don't specify the individual AD servers, we just use the domain and then through DNS ISE finds all the involved domain controllers.&lt;/P&gt;
&lt;P&gt;I think you can use one of the following commands on ISE CLI to get an idea of what ISE sees in terms of the AD servers in the background:&lt;/P&gt;
&lt;P&gt;nslookup _ldap._tcp.dc._msdcs.&amp;lt; &lt;EM&gt;your-domain-name&lt;/EM&gt; &amp;gt; querytype SRV&lt;BR /&gt;&lt;SPAN&gt;nslookup _ldap._tcp.gc._msdcs.&amp;lt; &lt;EM&gt;your-domain-name&lt;/EM&gt; &amp;gt; querytype SRV&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 14:15:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253220#M594531</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-27T14:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253280#M594538</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/346262"&gt;@Aref&lt;/a&gt; thanks for your help.&lt;BR /&gt;From ISE CLI I get new AD server IP.&lt;BR /&gt;Once again thank you all for your help here.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 15:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253280#M594538</guid>
      <dc:creator>victor-hugo</dc:creator>
      <dc:date>2025-01-27T15:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with 2 different Active Directory servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253589#M594568</link>
      <description>&lt;P&gt;You are very welcome, Victor.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 09:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-2-different-active-directory-servers/m-p/5253589#M594568</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-28T09:09:16Z</dc:date>
    </item>
  </channel>
</rss>

