- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2019 08:49 PM
Is there any reason why an ISE node in my cluster would suddenly have the AD join point domain controller no longer showing listed? You can see in the image ise4 has a blank entry in Domain Controller column, however the status is operational.
Diagnostic tool test comes back with the following failed tests:
- Kerberos test obtaining join point TGT on instance
- Kerberos check SASL connectivity to AD on instance
The reason being "The password is incorrect for the given account".
In the test LDAP test DCs response time - I can see the correct domain controller was the first to respond. So ISE should use this domain controller, but the entry is blank in the table.
Only thing I can think of is the account that ISE node did the domain join has had it's password changed. Is my thinking correct and would doing a new domain join for this node resolve the issue?
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-11-2019 12:08 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-11-2019 12:08 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-11-2019 06:51 PM - edited 06-11-2019 06:52 PM
Thanks for confirming and also sharing the bug. I did a rejoin and it picked up the Domain controller.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-03-2021 06:04 AM
May I know what solution solved this?
We already tried several things suggested by this forum and other sites.
