<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC AD Join test failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4989422#M1107533</link>
    <description>&lt;P&gt;1. DNS resloving domain name. Pinging domain name from CLI FMC&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206335i174FA6A6AA2295EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. User have super-administrator role&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.png" style="width: 442px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206338iC1439E3A7BEE2841/image-size/large?v=v2&amp;amp;px=999" role="button" title="13.png" alt="13.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3. Username FQDN&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.png" style="width: 434px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206337iF3D95EB4B09B8D09/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.png" alt="12.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2024 06:36:37 GMT</pubDate>
    <dc:creator>sherali mamatkarimov</dc:creator>
    <dc:date>2024-01-04T06:36:37Z</dc:date>
    <item>
      <title>FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988683#M1107501</link>
      <description>&lt;P&gt;Hello everyone i want to configure identity policy on FMC with Active Directory Kerberos, on&amp;nbsp;guide written &lt;SPAN&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Realm&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;you select must be configured with an&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;AD Join Username&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;AD Join Password&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to perform Kerberos captive portal active authentication. but when i testing AD Join there is error. AD Join test failed credintials are same with LDAP Realms, Group and User sync works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206255iC31DDDDE048ACD3A/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206257i59BCE571BE9640A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206256i480E2FC403854108/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 03 Jan 2024 05:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988683#M1107501</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-03T05:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988698#M1107502</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;System-&amp;gt;Integration&lt;BR /&gt;then add realm and directory&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 06:51:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988698#M1107502</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-03T06:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988881#M1107507</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206268i34B5FF4330070DD8/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Realm already added, screenshots higher are settings of exsisting realm&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 09:25:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988881#M1107507</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-03T09:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988882#M1107508</link>
      <description>&lt;P&gt;Are the AD server and FMC on the same subnet?&amp;nbsp; If not make sure that access rule allows the connection between FMC and AD.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 09:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988882#M1107508</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-01-03T09:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988884#M1107509</link>
      <description>&lt;P&gt;Can you from AD ping FMC mgmt IP?&lt;/P&gt;
&lt;P&gt;I think it reachability issue&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 09:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988884#M1107509</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-03T09:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988890#M1107510</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206269i728BEB2D059652B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;No problem with access rule i can load groups and users&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 09:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988890#M1107510</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-03T09:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988891#M1107511</link>
      <description>&lt;P&gt;&lt;SPAN&gt;No problem with access rule i can load groups and users&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 09:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988891#M1107511</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-03T09:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988894#M1107512</link>
      <description>&lt;P&gt;The first step of AD joint test is resolved the AD fqdn to IP.&lt;/P&gt;
&lt;P&gt;So check this step&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 09:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988894#M1107512</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-03T09:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988927#M1107513</link>
      <description>&lt;P&gt;Keep in mind that the username on the Realm Configuration page is not LDAP, it is Kerberos.&amp;nbsp; Be sure that tcp/udp 88 and 464 is permitted.&lt;/P&gt;
&lt;P&gt;Other things to consider are from the following output of the 7.2.x administration guide:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;AD Join Username and AD Join Password&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;(Available on the Realm Configuration tab page when you edit a realm.)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;For Microsoft Active Directory realms intended for Kerberos captive portal active authentication, the distinguished username and password of any Active Directory user with appropriate rights to create a Domain Computer account in the Active Directory domain.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Keep the following in mind:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;DNS must be able to resolve the domain name to an Active Directory domain controller's IP address.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The user you specify must be able to join computers to the Active Directory domain.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The user name must be fully qualified (for example, administrator@mydomain.com, not administrator).&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you choose Kerberos (or HTTP Negotiate, if you want Kerberos as an option) as the Authentication Protocol in an identity rule, the Realm you select must be configured with an AD Join Username and AD Join Password to perform Kerberos captive portal active authentication.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/identity-realms.html#task_F9ED2AF84F604438ACDC2124237DC518" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/identity-realms.html#task_F9ED2AF84F604438ACDC2124237DC518&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 11:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4988927#M1107513</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-01-03T11:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4989422#M1107533</link>
      <description>&lt;P&gt;1. DNS resloving domain name. Pinging domain name from CLI FMC&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206335i174FA6A6AA2295EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. User have super-administrator role&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.png" style="width: 442px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206338iC1439E3A7BEE2841/image-size/large?v=v2&amp;amp;px=999" role="button" title="13.png" alt="13.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3. Username FQDN&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.png" style="width: 434px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206337iF3D95EB4B09B8D09/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.png" alt="12.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 06:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4989422#M1107533</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-04T06:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4989424#M1107534</link>
      <description>&lt;P&gt;if i ping AD fqdn from CLI FMC hostname resolving and ping is success&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 06:40:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/4989424#M1107534</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-04T06:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5087729#M1112026</link>
      <description>&lt;P&gt;Were you able to resolve this issue?&amp;nbsp; I have the same problem.&amp;nbsp; I think the last change I made that broke this was to disable some older cipher suite (3DES) on our Windows DC.&amp;nbsp; &amp;nbsp; Not sure it is related but authenticated via Kerberos for Remote Storage doesn't work either.&amp;nbsp; I opened a TAC on that one and they said feature doesn't exist in 7.2.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 13:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5087729#M1112026</guid>
      <dc:creator>dotran</dc:creator>
      <dc:date>2024-05-02T13:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5122424#M1113214</link>
      <description>&lt;P&gt;haven't resolved yet&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2024 09:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5122424#M1113214</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-06-01T09:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5135880#M1113776</link>
      <description>&lt;P&gt;still not&amp;nbsp;&lt;SPAN&gt;resolved&amp;nbsp;?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 14:21:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5135880#M1113776</guid>
      <dc:creator>Yordan1</dc:creator>
      <dc:date>2024-06-25T14:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5143492#M1114214</link>
      <description>&lt;P&gt;&lt;SPAN&gt;still not&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;resolved&amp;nbsp;?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 10:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5143492#M1114214</guid>
      <dc:creator>jesper riisbjerg hansen</dc:creator>
      <dc:date>2024-07-11T10:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5311960#M1121924</link>
      <description>&lt;P&gt;I have the same problem, however it seems like its only the test that fails. I am able to retrieve groups and sync users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KasperElsborg_2-1753117012446.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248749i3E55789D4F87DFC5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KasperElsborg_2-1753117012446.png" alt="KasperElsborg_2-1753117012446.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 16:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5311960#M1121924</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2025-07-21T16:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5311963#M1121925</link>
      <description>&lt;P&gt;strange after a few tries it actually works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KasperElsborg_3-1753117094637.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248750i2C832180898B6FF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KasperElsborg_3-1753117094637.png" alt="KasperElsborg_3-1753117094637.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 16:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5311963#M1121925</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2025-07-21T16:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5355755#M1123871</link>
      <description>&lt;P&gt;I had the same problem; how did you solve it?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 05:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5355755#M1123871</guid>
      <dc:creator>IT VHW</dc:creator>
      <dc:date>2025-12-17T05:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: FMC AD Join test failed</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5375486#M1124679</link>
      <description>&lt;P&gt;Check your Active Directory to see if that device has not already joined.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2026 16:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ad-join-test-failed/m-p/5375486#M1124679</guid>
      <dc:creator>Bo J</dc:creator>
      <dc:date>2026-03-09T16:18:52Z</dc:date>
    </item>
  </channel>
</rss>

