cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
17855
Views
33
Helpful
24
Replies

Active Directory diagnostic tool found issues

John Vierra
Cisco Employee
Cisco Employee

I have received this error message a few times and I'm trying to find out what it means and what to do about it. If I follow the instructions in the alert and manually run the test it always comes back as passing. I'm running 2.4.0.357 with patch 1.

Thanks

Alarm Name :

Active Directory diagnostic tool found issues

Details :

AcsSyslogContentAaaDiagnostics:: ACTIVE_DIRECTORY_DIAGNOSTIC_TOOL_ISSUES_FOUND need to complete

Description :

One or more Active Directory diagnostic tests failed during a scheduled run.

Severity :

Warning

Suggested Actions :

Run the Active Directory Diagnostic Tool to check current status and view details of issues. Go to External Identity Sources, Active Directory and activate from Advanced Tools.

*** This message is generated by Cisco Identity Services Engine (ISE) ***

Sent By Host : vierra-ise

24 Replies 24

What is the status of tac case now ? Was it resolved by now ?

Error is still showing up on ISE 3.1, patch 3 .....

Still happening on 3.1 patch 3, but the alert can be disabled.  Go to hamburger button, System > Settings > Alarm Settings.  Under Alarm Configuration, find "Active directory diagnostic tool found issues" and edit to disable.

Still same even with patch 4 on 3.1 version.

Same issue on ISE 3.2 patch 4 ....

Hi @marco.merlo ,

 at Administration > Identity Management > External Identity Sources > select Active Diretory > select your AD > select the Node and click Diagnostic Tool button to check for the issue.

 You are also able to click the Run Test Now button to check again.

Hope this helps !!!

If we manual test by change to " Disabled". 

Is there any impact with ISE and AD services or not?

Thanks,

Kakada Sao

Hi @kakada Atada ,

 if you "manual disable" the Active Directory Diagnostic Tool by unchecking the Run Schedule Tests checkmark, attention to CSCvw81130 Unable to disable Active Directory Diagnostic Tool scheduled tests

CSCvw81130 00.png

 

Hope this helps !!!

@marco.merlo 

Please drill-into this alarm, check the details on some of the entries and see what tests failed recorded for the alarm entry.

Minnesotakid
Level 1
Level 1

I vaguely recall experiencing this issue back when we were on 2.6 and we were told since we had a "grandfathered in" old TACACS license in the new smart-licensing world, this alarm would get caused and it was simply an aesthetic issue (ie. false positive). Hope that helps some of you.