<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Integrate AD fail in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358687#M599440</link>
    <description>&lt;P&gt;i was asking firewall not on the windows Server, any other Firewall which is blocking to reach AD from ISE.&lt;/P&gt;
&lt;P&gt;your nslookup fails, check is the ISE have correct DNS and NTP entries ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show running-config | include name-server&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ping &amp;lt;DNS-server-IP&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nslookup google.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jan 2026 14:22:20 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2026-01-02T14:22:20Z</dc:date>
    <item>
      <title>ISE Integrate AD fail</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358645#M599437</link>
      <description>&lt;P&gt;ISE Version 3.3&lt;BR /&gt;DNS Server (windows 2025 server)&amp;nbsp; &amp;nbsp;192.168.3.5&lt;/P&gt;&lt;P&gt;Please see the error message&lt;/P&gt;&lt;P&gt;Error Description: Failed to find domain controller, please check network connectivity&lt;BR /&gt;&lt;BR /&gt;Support Details...&lt;BR /&gt;Error Name: LW_ERROR_FAILED_FIND_DC&lt;BR /&gt;Error Code: 40049&lt;/P&gt;&lt;P&gt;Hello Boss,&lt;/P&gt;&lt;P&gt;Can you help me to fix this issue ?&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;Detailed Log:&lt;/P&gt;&lt;P&gt;Error Description :&lt;BR /&gt;Failed to find domain controller in domain CN.TT.COM : domain does not exists in DNS&lt;/P&gt;&lt;P&gt;Error Resolution :&lt;BR /&gt;Please make sure that your DNS contains records for domain : CN.TT.COM, For further information please refer to the AD DNS diagnostic tools&lt;/P&gt;&lt;P&gt;Join steps :&lt;BR /&gt;18:30:45 Joining to domain CN.TT.COM using user ISE_Join&lt;BR /&gt;18:30:45 Searching for DC in domain CN.TT.COM&lt;BR /&gt;18:30:45 Failed to find domain controller in domain CN.TT.COM : domain does not exists in DNS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jacky88_0-1767351753441.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257215iAE252C173C05B7CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jacky88_0-1767351753441.png" alt="Jacky88_0-1767351753441.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jacky88_1-1767351780775.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257216i3891A0E49EE1ACC7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jacky88_1-1767351780775.png" alt="Jacky88_1-1767351780775.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jacky88_2-1767351796105.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257217i0D82AD48ACD3C790/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jacky88_2-1767351796105.png" alt="Jacky88_2-1767351796105.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jacky88_3-1767351825771.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257218iD19A69AA9FEDE8F8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jacky88_3-1767351825771.png" alt="Jacky88_3-1767351825771.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jacky88_4-1767351853061.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257219i6EF3EB2690F6A011/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jacky88_4-1767351853061.png" alt="Jacky88_4-1767351853061.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 11:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358645#M599437</guid>
      <dc:creator>Jacky88</dc:creator>
      <dc:date>2026-01-02T11:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integrate AD fail</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358662#M599438</link>
      <description>&lt;P&gt;What details do you get from the error screenshot? Join operation status (click here for further details).&lt;/P&gt;
&lt;P&gt;ISE 3.3 with what patch?&lt;/P&gt;
&lt;P&gt;Check Port Connectivity -&amp;nbsp;&amp;nbsp;Verify that ports&amp;nbsp;53 (DNS),&amp;nbsp;88 (Kerberos),&amp;nbsp;389 (LDAP), and&amp;nbsp;445 (SMB)&amp;nbsp;are not blocked by a firewall between ISE and the DC&lt;/P&gt;
&lt;P&gt;Hope the account you're using has the necessary permissions to join the domain.&lt;/P&gt;
&lt;P&gt;Check FN, is that affecting you :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/743/fn74321.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/field-notices/743/fn74321.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;check some other steps to test :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learningnetwork.cisco.com/s/question/0D53i00000KstwtCAB/ise-integration-with-ad" target="_blank"&gt;https://learningnetwork.cisco.com/s/question/0D53i00000KstwtCAB/ise-integration-with-ad&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 12:31:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358662#M599438</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-01-02T12:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integrate AD fail</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358669#M599439</link>
      <description>&lt;P&gt;Hi Boss&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Please kindly find info from firewall and ISE.&lt;BR /&gt;Could you please kindly take a look ? Thanks a lot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall has been allowed all for inbound.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jacky88_0-1767357961611.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257222iDCB2DDAB38907428/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jacky88_0-1767357961611.png" alt="Jacky88_0-1767357961611.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Test command error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jacky88_0-1767358671771.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257223i350661C24913E012/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jacky88_0-1767358671771.png" alt="Jacky88_0-1767358671771.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 12:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358669#M599439</guid>
      <dc:creator>Jacky88</dc:creator>
      <dc:date>2026-01-02T12:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integrate AD fail</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358687#M599440</link>
      <description>&lt;P&gt;i was asking firewall not on the windows Server, any other Firewall which is blocking to reach AD from ISE.&lt;/P&gt;
&lt;P&gt;your nslookup fails, check is the ISE have correct DNS and NTP entries ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show running-config | include name-server&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ping &amp;lt;DNS-server-IP&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nslookup google.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 14:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358687#M599440</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-01-02T14:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integrate AD fail</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358916#M599449</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Based on provided information, it looks to be a misconfiguration on DNS server side; please check this post and find the solution (did you add DNS service before enabling AD DS services on the server, or is AD DS services enabled at all?):&amp;nbsp;&lt;A href="https://learningnetwork.cisco.com/s/question/0D53i00000KstwtCAB/ise-integration-with-ad" target="_blank"&gt;https://learningnetwork.cisco.com/s/question/0D53i00000KstwtCAB/ise-integration-with-ad&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jan 2026 17:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358916#M599449</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-04T17:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integrate AD fail</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358934#M599451</link>
      <description>&lt;P&gt;IMO, support for Windows Server 2025 started officially with ISE 3.5 (with some extra patches):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/compatibility_doc/b_ise_sdt_35.html#externalidstores" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/compatibility_doc/b_ise_sdt_35.html#externalidstores&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;But it should also work with older ISE versions after applying the hotfixes outlined in CSCwn62873.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jan 2026 19:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integrate-ad-fail/m-p/5358934#M599451</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2026-01-04T19:50:44Z</dc:date>
    </item>
  </channel>
</rss>

