cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

162
Views
0
Helpful
1
Replies
Highlighted
Beginner

ISE - how to test migration from AD 2003 to 2012

My customer is migrating from Active Directory 2003 servers to AD 2012 servers.

They have the 2003 and 2012 servers running in parallel.

I need to point my ISE's at just the new 2012 servers to ensure everything works ok. 

How can I do this?

At present I understand that when I join the domain, a list of servers comes back and I have no control over which ones I connect to.

Any help would be appreciated.

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Cisco Employee

You can do so by pointing it to a specific DC for one of the PSNS as below if both of them are in the same domain.

External-ID-Stores -> Active Directory -> Advanced Tools -> Advanced Tuning
Select the ISE node you want to change
The 'Name' field gets the specific REGISTRY string given below.
REGISTRY.Services\lsass\Parameters\Providers\ActiveDirectory\PreferredDCs\<Domain Name>
The 'Value' field is where you indicate the DC, or list of DCs separated by a space.
Type any description. Required before next step.
Click 'Update Value' button
Click 'Restart Active Directory Connector'

This node on which you make this change will not be able to server AD authentications for a minute or so. Once you make this change, check if the authentications meant for AD on this node are working or not from the Live logs. Alternatively, do a test authentication from the External-ID-Stores -> Active Directory selecting the PSN on which the chance is made.

Note : Try this in the lab first please. I haven't tried it myself but by logic this should work.

View solution in original post

1 REPLY 1
Highlighted
Cisco Employee

You can do so by pointing it to a specific DC for one of the PSNS as below if both of them are in the same domain.

External-ID-Stores -> Active Directory -> Advanced Tools -> Advanced Tuning
Select the ISE node you want to change
The 'Name' field gets the specific REGISTRY string given below.
REGISTRY.Services\lsass\Parameters\Providers\ActiveDirectory\PreferredDCs\<Domain Name>
The 'Value' field is where you indicate the DC, or list of DCs separated by a space.
Type any description. Required before next step.
Click 'Update Value' button
Click 'Restart Active Directory Connector'

This node on which you make this change will not be able to server AD authentications for a minute or so. Once you make this change, check if the authentications meant for AD on this node are working or not from the Live logs. Alternatively, do a test authentication from the External-ID-Stores -> Active Directory selecting the PSN on which the chance is made.

Note : Try this in the lab first please. I haven't tried it myself but by logic this should work.

View solution in original post

Content for Community-Ad