cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
522
Views
0
Helpful
1
Replies

ISE-PIC AD DS (global vs site based SRV request)

Samuel Vuillaume
Cisco Employee
Cisco Employee

uys

 

My client is trying to integrate ISE-PIC with AD (for Passive auth) with “FMC”.

 

In the ISE-PIC Admin guide, I read "You might not be able to join Cisco ISE-PIC with an Active Directory domain if the DNS SRV records are missing (the domain controllers do not advertise their SRV records for the domain that you are trying to join to)"

 

When I sent this to my client, he replied with "That is our problem. Not all DCs can be resolved by global DNS SRV records. But we have all SRV records based by sites"

 

I have reached my AD DS knowledge on this last one.

 

Is there a way to address that issue on ISE-PIC? 

 

Thank you

Sam

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.

View solution in original post

1 Reply 1

hslai
Cisco Employee
Cisco Employee

I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: