cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
692
Views
1
Helpful
4
Replies

How to Join AD to multiple domains

llomjaria
Level 1
Level 1

Hello,

I have ISE 3.2 two node deployment. I have joined them to domain abc.com. ISE uses DNS servers of abc.com domain.

Now I want to join ISE nodes to another independent domain efg.com. I have created host aliases for efg.com pointing IP addresses of efg.com domain controller (ip host 192.168.1.2 efg.com). Ping to efg.com is successful but I am not able to join ISE.

I have started tcp dump on ISE and when I try to join to efg.com it does not send any traffic to efg.com.

This is the result of tests from ISE:

llomjaria_0-1717575424467.png

 

Am I missing something?

 

4 Replies 4

Arne Bier
VIP
VIP

I am not an AD expert, but if the other efg.com domain is not sharing/exchanging some of its DNS records with abc.com, then ISE (sitting on abc.com?) won't be able to resolve all the DNS records for efg.com (SRV records etc.).   

These two domain controllers are independent of each other, they do NOT have any trust between them. 

I want to know how to add second active directory in ISE. I could not find technical information about it.

i have done it.. its just like defining the first one... but as Marvin says you need to have DNS resolve both domains..

Marvin Rhoads
Hall of Fame
Hall of Fame

You need configured DNS server(s) that able to resolve all of the second domain's records. Simply putting a host record for the domain controller will not suffice. Look, for example, at all the tests that run during an AD daily health check. Those should be able to  pass for both domains.