cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
 
ISE 2.3 Patch 7 has been posted. This will be the last patch for the ISE 2.3 release!
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

111
Views
0
Helpful
4
Replies
Cisco Employee

Cannot join AD in ISE 2.4 | CLOCK_SKEW

Hi,

 

I'm trying to join my AD in ISE but getting an error.

ISE is at 2.4

AD is Microsoft Server 2016

 

Here is the complete error:

Result for ISE node: ise.securitydemo.net.

Status: Join Operation Failed: Clock skew detected with active directory server

 

 

Error Description: Clock Skew Detected With Active Directory Server

Support Details...

Error Name: LW_ERROR_CLOCK_SKEW

Error Code: 40087

 

Detailed Log:

08:53:12 Joining To Domain MXXXAKI.COM Using User Administrator

08:53:12   Searching For DC In Domain MXXXAKI.COM

08:53:12   Found DC: WIN-3CE3A93D7R1.mxxxaki.com , Client Site Is Default-First-Site-Name , Dc Site Is Default-First-Site-Name

08:53:12   Checking Credentials For User Administrator

08:53:12     Getting TGT For Account Administrator@MXXXAKI.COM

 

I've set up my AD as the NTP and DNS.

 

Here's a screen capture of show NTP in ISE.

I've also set Root Dispersion to zero already, please see attached.

 

Thank you,

Brian

 

4 REPLIES 4
Cisco Employee

Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW

Your ISE isn't in Sync with your NTP server as you can see that the selected time source is not your NTP server. Check if your NTP server is up and running. Are there any devices that are in sync with your NTP server? Check this if it helps . https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119371-technote-ise-00.html
Cisco Employee

Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW

Hi Serendra,

I tried using google NTP server already, but my current time source is still 127.127.1.0.
Any idea how to force the ISE NTP to my configured google ntp server?
Screenshot below.

[cid:image001.png@01D547DB.DF7C8FB0]

Thanks,
Brian

Highlighted
VIP Engager

Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW

127.127.1.0 is always listed first.

 

ntp.png

Cisco Employee

Re: Cannot join AD in ISE 2.4 | CLOCK_SKEW

Closing out on this one. I was able to successfully integrate AD by manually adjusting ISE clock in the CLI using the command "clock set"