cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5479
Views
0
Helpful
6
Replies

ISE AD Integration Fails

NiTech
Level 1
Level 1

We have ISE 2.7 and tried to integrate with AD. Unfortunately following error occurred 

 

Error Description: Request Timed Out

Support Details...
Error Name: LW_ERROR_RPC_LSA_TIMEOUT
Error Code: 60000

Detailed Log:

 

Checked the following :

Time on ISE and DNS are same

Firewall ports are open and verified

Confirmed the reachability between  ISE and Domain controller.Screenshot (7).png 

1 Accepted Solution

Accepted Solutions

Issue has been resolved after the latest patch 4 installation 

View solution in original post

6 Replies 6

Mike.Cifelli
VIP Alumni
VIP Alumni

Have you attempted to verify AD side firewall as well? Capture traffic on AD side from ISE? Try taking a look at the following:

Identity Service Engine (ISE) and Active Directory (AD) Communications; Protocols, Filters and Flow. - Cisco

Thanks for the responds, 

 

Sure we will check the tcp dump,

As per my initial tshoot,we allowed all port on firewall.

Issue has been resolved after the latest patch 4 installation 

harishbau084
Level 1
Level 1

We have faced same issue on ISE 3.2 patch 3, and its fixed on patch 4

We also faced the same issue while joining the PSN node to AD error was " LW_ERROR_RPC_LSA_TIMEOUT error code 60000" on ISE 3.2 patch 3, and after applying patch 4, the issue was resolved.

a soft reboot will also fix the issue.