11-21-2018 05:06 PM - edited 11-21-2018 05:11 PM
uys
My client is trying to integrate ISE-PIC with AD (for Passive auth) with “FMC”.
In the ISE-PIC Admin guide, I read "You might not be able to join Cisco ISE-PIC with an Active Directory domain if the DNS SRV records are missing (the domain controllers do not advertise their SRV records for the domain that you are trying to join to)"
When I sent this to my client, he replied with "That is our problem. Not all DCs can be resolved by global DNS SRV records. But we have all SRV records based by sites"
I have reached my AD DS knowledge on this last one.
Is there a way to address that issue on ISE-PIC?
Thank you
Sam
Solved! Go to Solution.
12-15-2018 07:50 PM
I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.
12-15-2018 07:50 PM
I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide