cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

712
Views
0
Helpful
1
Replies
Capricorn
Beginner

Alarm Name : Active Directory forest is unavailable

Hello All!

 

I am running version 2.4.0.357 patch 8. 

 

I saw the following critical alert and after that I saw that few Radius error as below.

Alarm Name :

Details :

Active-Directory forest is unavailable  Forest=Domain Name, ISE01

Description :

Active Directory forest GC (Global Catalog) is unavailable, and cannot be used for authentication, authorization and group and attribute retrieval.

 

Severity :

Critical

 

Suggested Actions :

Check DNS configuration, Kerberos configuration, error conditions, and network connectivity.

 

*** This message is generated by Cisco Identity Services Engine (ISE) ***

 

Event5405 RADIUS Request dropped
Failure Reason24708 User not found in Active Directory. Some authentication domains were not available

 

The user were able to connect after few mins.

I can see that connection to AD is healthy.

 

Anyone seen this kind of issue and possible fix?

 

Thanks

1 REPLY 1
Damien Miller
VIP Advisor

This is usually caused by three things not specific to ISE, DNS issues, network communication issues, and last but not least, an issue with AD itself.

If it started working again on its own, then It's likely one of those three.
Content for Community-Ad