01-28-2022 04:13 AM
Hello all,
after upgrading our Active directory environment from Windows 2012 to Windows 2019 and installing the latest security updates from Microsoft (KB5004442), logs on the DC show the following error regarding the connections from ISE.
The server-side authentication level policy does not allow the user domain\user SID (S-1-5-21-9321468-1570001470-2076119496-113405) from address ISE_ip_address to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.
According to Microsoft a temp solution would be to change the registry on the DC. But from June2022 this hardening will be permanent (https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c)
Is there something that can be done on ISE side to fix the problem?
Thank you in advance,
Katerina
Solved! Go to Solution.
01-28-2022 08:25 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz97194
M.
01-28-2022 08:25 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz97194
M.
01-28-2022 11:07 AM
Is this about ISE-SCCM server integration (external MDM / Desktop Management) ? It’s always been a nightmare to set up the DCOM and registry privileges.
01-30-2022 01:58 PM
It's affecting the Active Directory as a PassiveID provider via WMI.
02-01-2022 10:06 AM
What if you stopped using ISE-PIC and just use Active Identity instead? We have ISE-PIC tied into our AD environment and using PXGRID services for USER to IP mapping for FMC firewall policies to work correctly. Is there a downside to switching over to active identity? And no longer using passive-id?
02-02-2022 03:58 AM
Hello,
this is an interesting approach... I will have to contact our partner and see what their thoughts are on the matter.
Thank you for the suggestion
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide