cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
922
Views
5
Helpful
1
Replies

ISE and AD integration

mgaspero
Cisco Employee
Cisco Employee

Hi ISE experts, 

I'm working in a SDA project and my customer, Italian Broadcaster, wants to use ISE with external AD.

 

They raised us a question: what happen if external AD fails while ISE is running properly? Is ISE able to cache AD DB, synchronize all the info in local ISE DB and grant authentication even if external AD is down?

 

Can you please confirm that ISE doesn't cache AD credentials. However, customer can setup the ISE to work with up to 50 ADs.

https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_20.html

 

"DC Failover

Domain controller (DC) failover can be triggered by the following conditions:

 

The AD connector detects if the currently selected DC becomes unavailable during the LDAP, RPC, or Kerberos communication attempt. The DC might be unavailable because it is down or has no network connectivity. In such cases, the AD connector initiates DC selection and fails over to the newly selected DC.

The DC is up and responds to the CLDAP ping, but AD connector cannot communicate with it for some reason, for example if the RPC port is blocked, the DC is in the broken replication state, or the DC has not been properly decommissioned. In such cases, the AD connector initiates DC selection with a black list ("bad" DC is placed in the black list) and tries to communicate with the selected DC. Neither the DC selected with the blacklist nor the blacklist is cached."

 

Is it the suggest way to go?

 

Please let me know

 

best Regards

 

Marco

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee
ise doesn't cache the AD database, if its down then it will fail. You will need to make sure sites and services has a proper configuration and backup. For more information see cisco live content by chris murray https://www.ciscolive.com/global/on-demand-library/?search=murray#/session/14525434149870017MRf

View solution in original post

1 Reply 1

Jason Kunst
Cisco Employee
Cisco Employee
ise doesn't cache the AD database, if its down then it will fail. You will need to make sure sites and services has a proper configuration and backup. For more information see cisco live content by chris murray https://www.ciscolive.com/global/on-demand-library/?search=murray#/session/14525434149870017MRf