cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
770
Views
0
Helpful
1
Replies

ISE - how to test migration from AD 2003 to 2012

jphilp
Level 1
Level 1

My customer is migrating from Active Directory 2003 servers to AD 2012 servers.

They have the 2003 and 2012 servers running in parallel.

I need to point my ISE's at just the new 2012 servers to ensure everything works ok. 

How can I do this?

At present I understand that when I join the domain, a list of servers comes back and I have no control over which ones I connect to.

Any help would be appreciated.

1 Accepted Solution

Accepted Solutions

Surendra
Cisco Employee
Cisco Employee
You can do so by pointing it to a specific DC for one of the PSNS as below if both of them are in the same domain.

External-ID-Stores -> Active Directory -> Advanced Tools -> Advanced Tuning
Select the ISE node you want to change
The 'Name' field gets the specific REGISTRY string given below.
REGISTRY.Services\lsass\Parameters\Providers\ActiveDirectory\PreferredDCs\<Domain Name>
The 'Value' field is where you indicate the DC, or list of DCs separated by a space.
Type any description. Required before next step.
Click 'Update Value' button
Click 'Restart Active Directory Connector'

This node on which you make this change will not be able to server AD authentications for a minute or so. Once you make this change, check if the authentications meant for AD on this node are working or not from the Live logs. Alternatively, do a test authentication from the External-ID-Stores -> Active Directory selecting the PSN on which the chance is made.

Note : Try this in the lab first please. I haven't tried it myself but by logic this should work.

View solution in original post

1 Reply 1

Surendra
Cisco Employee
Cisco Employee
You can do so by pointing it to a specific DC for one of the PSNS as below if both of them are in the same domain.

External-ID-Stores -> Active Directory -> Advanced Tools -> Advanced Tuning
Select the ISE node you want to change
The 'Name' field gets the specific REGISTRY string given below.
REGISTRY.Services\lsass\Parameters\Providers\ActiveDirectory\PreferredDCs\<Domain Name>
The 'Value' field is where you indicate the DC, or list of DCs separated by a space.
Type any description. Required before next step.
Click 'Update Value' button
Click 'Restart Active Directory Connector'

This node on which you make this change will not be able to server AD authentications for a minute or so. Once you make this change, check if the authentications meant for AD on this node are working or not from the Live logs. Alternatively, do a test authentication from the External-ID-Stores -> Active Directory selecting the PSN on which the chance is made.

Note : Try this in the lab first please. I haven't tried it myself but by logic this should work.