01-26-2017 11:40 AM
Getting the error below when using PassiveID and trying to add Windows 2012R2 DC:
"The connection was tested on 'isemain.cyber.lab' PassiveID active node.
Connection to 'maindc' failed.
Unable to connect to the machine, please check the DC state"
Test user is member of domain admins group, it seems that it failed to run WMI commands.
PassiveID log file:
2017-01-26 20:19:35,197 INFO [qtp1343441044-10 - /][] com.cisco.cpm.cda- Ident
ity mapping service applied configuration. Identity Mapping.number-of-domain-con
trollers = 1 , Identity Mapping.server = isemain ,
2017-01-26 20:19:36,838 ERROR [Thread-18][] com.cisco.cpm.cda- Cannot get Domai
n Controller NetBIOS. Identity Mapping.wmi-class = Win32_NTDomain , Identity Map
ping.exception-message = Access is denied, please check whether the [domain-user
name-password] are correct , Identity Mapping.dc-domainname = test.lab , Identi
ty Mapping.dc-name = maindc , Identity Mapping.dc-host = maindc.test.lab/192.16
8.103.105 , Identity Mapping.server = isemain , Identity Mapping.wmi-property =
DomainName ,
ISE version is 2.1 with patch 2
Solved! Go to Solution.
01-26-2017 12:23 PM
Have you configured the Domain Controller to allow for this? Check out this section on Easy Connect in the ISE Admin Guide:
01-26-2017 12:23 PM
Have you configured the Domain Controller to allow for this? Check out this section on Easy Connect in the ISE Admin Guide:
01-26-2017 01:08 PM
Hi Charles,
Thanks for your help.
It is working for me until I moved to Windows 2012R2, I used your link and it solved the problem.
I just add "Domain Admins" permission (full control) to below registry keys which related to WMI permissions:
HKEY_CLASSES_ROOT\CLSID\{76A64158-CB41-11D1-8B02-00600806D9B6}
HKLM\Software\Classes\Wow6432Node\CLSID\{76A64158-CB41-11D1-8B02-00600806D9B6}
Thanks,
Nir
01-26-2017 01:12 PM
Great! I'm glad this helped.
Thanks for posting the exact fix.
03-31-2017 05:04 AM
Nir, working with the same issue during my ISE version 2.2 buildout. Our network admins are asking exactly what do these registry key have to do with the logs. We are also running 2012R2 domain controllers.
Do you know?
Thanks,
Dave
04-02-2017 01:39 AM
Enabling DCOM for Windows 7, 8 and Server 2012 might help.
04-03-2017 03:59 AM
hslai, thanks for the link. This is very helpful.
Dave
05-12-2021 11:12 AM
is there a way to setup email alerting for this event in ISE 2.4
Work Centres > Passive ID > Reports > Passive ID
Severity : Error
Provider Type: WMI
Domain : xyz
Event: Cannot get Domain Controller NetBIOS
05-12-2021 04:43 PM
Duplicate question answered in the following post:
https://community.cisco.com/t5/network-access-control/passive-id-provider-down-alerting/m-p/4402128
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide