cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1936
Views
5
Helpful
3
Replies

Integration of ISE to AD Per Site

fatalXerror
Level 5
Level 5

Hi Guys,

I have multiple ADs worldwide and my ISE is located in Los Angeles and when I integrate ISE to my AD domain ("us.example.com"), I want to make sure that it is connecting to my LA AD. 

For me to do this, I need to have SRV record in my DNS right?

Thanks

1 Accepted Solution

Accepted Solutions

When the ISE nodes join the AD domain, they create computer accounts in the domain. This allows the ISE nodes to use Active Directory's built in high-availability and redundancy mechanisms. With an AD-integrated MS DNS server, it automatically builds SRV records based upon the model defined within AD Sites and Services.

Although you might be able to manually create SRV records in DNS (I've never tried it), you should be using AD's built-in mechanisms.

If you're not familiar with the AD functions, I would highly suggest discussing this topic with your AD administrators and referencing my comments around AD Sites and Services.

View solution in original post

3 Replies 3

Greg Gibbs
Cisco Employee
Cisco Employee

It sounds like you're talking about integrating ISE with a single Forest and Domain (join point) and you want the ISE nodes to communicate with the local Domain Controller in LA. Is that correct?

If so, you would do this using AD Sites and Services by ensuring that your DC is associated with a Site and adding the subnet used by the ISE nodes to that Site.

Hi @Greg Gibbs , thanks for the feedback. Sorry but I cannot understand much in terms of AD terminologies but all I wanted to do is integrate my ISE to my domain (e.g. us.example.com) and I want to make sure that my L.A. AD should be the one to be integrate to my ISE.

My domain (e.g. us.example.com) consist of multiple ADs across the US that is why I want to make sure that my nearest AD will be the one that will be replying back to my ISE in L.A. that is why I was thinking if it is something to do with the SRV record that needs to be configured in the DNS to point the domain controller to L.A.

Thanks

When the ISE nodes join the AD domain, they create computer accounts in the domain. This allows the ISE nodes to use Active Directory's built in high-availability and redundancy mechanisms. With an AD-integrated MS DNS server, it automatically builds SRV records based upon the model defined within AD Sites and Services.

Although you might be able to manually create SRV records in DNS (I've never tried it), you should be using AD's built-in mechanisms.

If you're not familiar with the AD functions, I would highly suggest discussing this topic with your AD administrators and referencing my comments around AD Sites and Services.