cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
772
Views
0
Helpful
3
Replies

ISE Issue with AD

Hello all, 

We completed the integration between the Ise and Active Directory, but  I can't access any device by  radel@internal.XXXXXX.com should be use internal\radel . Despite the fact that I can open any PC by  radel@internal.XXXXXXX.com 

 

Ise version : 3.1.0.518

 

Abdelrahmansalah_0-1668771243830.png

 

How to solve it

 

3 Replies 3

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @Abdelrahman salah,

Could you please post another screenshot, as this one is barelly visible?

Usually, upon AD integration, Test User option works out of the box.

Kind regards,

Milos

1- error from Cisco ise

Test Username : adel@internal.XXXXXX.com
ISE NODE : ISE1.internal.XXXXXXX.com
Scope : Default_Scope
Instance : ISE

Authentication Result : FAILED

Error : Identity not found; some of the domains were not available


Processing Steps:
14:57:49:713: Resolving identity - adel@internal.XXXXX.com
14:57:49:713: Search for matching accounts at join point - internal.XXXXX.com
14:57:49:715: DNS server returned error - internal.XXXXX.com,ERROR_DNS_ERROR_DOMAIN_NOT_FOUND
14:57:49:715: LDAP search in forest failed - internal.XXXXXX.com,ERROR_DOMAIN_IS_OFFLINE
14:57:49:715: Identity resolution detected no matching account
14:57:49:715: Identity resolution failed - ERROR_NO_SUCH_USER_SOME_DOMAINS_NOT_AVAILABLE

2-

Abdelrahmansalah_0-1668786935415.png

3-

Abdelrahmansalah_1-1668787210990.png

4-

 

Abdelrahmansalah_3-1668787657746.png

 

hslai
Cisco Employee
Cisco Employee

@Abdelrahman salah As I mentioned in your other discussion thread, this seems some issue with the DNS server(s) that you configured on ISE. Please work with Cisco TAC to troubleshoot further.