07-07-2022 08:30 AM
Hi All
I try to test user and password from ISE to AD but it show authentication result fail
but I can join Cisco ISE and AD and i can see all group user on AD from Cisco
Cisco ISE and AD can communicate with name can ping with name work and NTP is correct
try to Diag it all work correct
07-07-2022 08:43 AM
what you see on the Logs : ( ISE side and AD side ?)
some troubleshoot tips :
https://www.cisco.com/c/en/us/td/docs/security/ise/1-0/troubleshooting_guide/ise10_tsg.html
07-07-2022 09:17 AM
07-07-2022 10:30 AM
A couple of things I would check are:
a) Check the status of the domain controllers in Administration > External Identity Sources > Active Directory.
b) Check that all the required domains are set with YES under the Allowed Domains tab.
c) Enable the invalid usernames disclosure under Administration > System >L Security Settings, this will help you to see the actual username on the authentication failure log.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide