08-04-2023 04:13 AM - last edited on 08-04-2023 05:59 AM by rupeshah
Hi Guys,
I wanted to join the ISE to a new domain, since my company is currently migrating the AD domain. But upon joining the ISE nodes to the AD, I stumbled upon the following error:
Error Name: LW_ERROR_LDAP_NAMING_VIOLATION
Error Code: 40336
Detailed Log:
17:53:46 Joining to domain NEWDOMAIN.COM using user ServiceAccount
17:53:46 Searching for DC in domain NEWDOMAIN.COM
17:53:46 Found DC: ServerName.NEWDOMAIN.com , client site is XX , dc site is YY
17:53:46 Checking credentials for user ServiceAccount
17:53:46 Getting TGT for account ServiceAccount@NEWDOMAIN.COM
17:53:46 TGT for account ServiceAccount@NEWDOMAIN.COM was retrieved successfully
17:53:46 Credentials for user ServiceAccount were verified
17:53:46 Searching for DC in domain NEWDOMAIN.COM
17:53:46 Found DC: ServerName.NEWDOMAIN.com , client site is XX , dc site is YY
17:53:46 Generating account name for ISE machine in NEWDOMAIN.COM
17:53:46 Searching for an existing machine account
17:53:46 Searching object by filter : (&(objectCategory=computer)(servicePrincipalName=host/ISENODE02.NEWDOMAIN.com))
17:53:46 Account: ISENODE02 was not found
17:53:46 Searching for an existing machine account
17:53:46 Searching object by filter : (&(objectClass=computer)(sAMAccountName=xxx))
17:53:46 Account: xxx was found
17:53:46 ISE Machine account name is : xxx
17:53:46 Creating machine account xxx in OU : CN=xxx,OU=V,OU=W,OU=X,OU=Y,DC=Z,DC=com
I tried to Googled it but did not find any similar error. What I did was to create the object first on the Domain Controller first and specify the DN of the ISE nodes.
Any idea why I got this error? Thank you.
Solved! Go to Solution.
08-04-2023 06:16 AM
- Some of these requirements might be applicable : https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876825#M39194
M.
08-04-2023 06:16 AM
- Some of these requirements might be applicable : https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-fails/m-p/2876825#M39194
M.
08-06-2023 09:34 PM
Hi Marce,
Thank you, I will take a look into it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide