ā12-06-2021 05:29 AM
I have just added a our first AWS instance to you our ISE Deployment and when I join it to the Active Directory domain the following tests are failing/showing a warning:
The same tests on the physical appliances work.
On the AWS node an nslookup for _ldap._tcp.dc._msdcs for the SRV records for domain is working.
Any ideas?
Solved! Go to Solution.
ā12-10-2021 02:05 AM
The problem appears to be with the AWS based DNS server. Switching to on premise DNS servers resolves the issue.
I m getting our DNS team to check the differences.
ā12-06-2021 06:48 AM
The physical appliances are not in AWS.
Security Groups?
Network ACLs?
VPN firewall?
Other firewall?
ā12-06-2021 07:25 AM
There may be some firewall rules/ACLs but I am unclear which DNS server the ISE node is using for the tests As I said nslookup from node cli itself seems to be working but I know this DNS server is a layer below the application itself. Could the ISE application be picking up a different DNS server?
ā12-09-2021 07:56 PM
It should be using whichever DNS servers you have configured when you provisioned it.
You will need to SSH with your AWS private key to see the DNS server configuration with a `show run`.
ā12-10-2021 02:05 AM
The problem appears to be with the AWS based DNS server. Switching to on premise DNS servers resolves the issue.
I m getting our DNS team to check the differences.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide