01-02-2026 03:07 AM
ISE Version 3.3
DNS Server (windows 2025 server) 192.168.3.5
Please see the error message
Error Description: Failed to find domain controller, please check network connectivity
Support Details...
Error Name: LW_ERROR_FAILED_FIND_DC
Error Code: 40049
Hello Boss,
Can you help me to fix this issue ?
Thanks a lot
Detailed Log:
Error Description :
Failed to find domain controller in domain CN.TT.COM : domain does not exists in DNS
Error Resolution :
Please make sure that your DNS contains records for domain : CN.TT.COM, For further information please refer to the AD DNS diagnostic tools
Join steps :
18:30:45 Joining to domain CN.TT.COM using user ISE_Join
18:30:45 Searching for DC in domain CN.TT.COM
18:30:45 Failed to find domain controller in domain CN.TT.COM : domain does not exists in DNS
01-02-2026 04:31 AM
What details do you get from the error screenshot? Join operation status (click here for further details).
ISE 3.3 with what patch?
Check Port Connectivity - Verify that ports 53 (DNS), 88 (Kerberos), 389 (LDAP), and 445 (SMB) are not blocked by a firewall between ISE and the DC
Hope the account you're using has the necessary permissions to join the domain.
Check FN, is that affecting you :
https://www.cisco.com/c/en/us/support/docs/field-notices/743/fn74321.html
check some other steps to test :
https://learningnetwork.cisco.com/s/question/0D53i00000KstwtCAB/ise-integration-with-ad
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
01-02-2026 04:58 AM
Hi Boss @balaji.bandi ,
Please kindly find info from firewall and ISE.
Could you please kindly take a look ? Thanks a lot
Firewall has been allowed all for inbound.
Test command error
01-02-2026 06:22 AM
i was asking firewall not on the windows Server, any other Firewall which is blocking to reach AD from ISE.
your nslookup fails, check is the ISE have correct DNS and NTP entries ?
show running-config | include name-server
ping <DNS-server-IP>
nslookup google.com
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
01-04-2026 09:03 AM
Hi,
Based on provided information, it looks to be a misconfiguration on DNS server side; please check this post and find the solution (did you add DNS service before enabling AD DS services on the server, or is AD DS services enabled at all?): https://learningnetwork.cisco.com/s/question/0D53i00000KstwtCAB/ise-integration-with-ad
Thanks,
Cristian.
01-04-2026 11:50 AM
IMO, support for Windows Server 2025 started officially with ISE 3.5 (with some extra patches):
But it should also work with older ISE versions after applying the hotfixes outlined in CSCwn62873.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide