This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
uys
My client is trying to integrate ISE-PIC with AD (for Passive auth) with “FMC”.
In the ISE-PIC Admin guide, I read "You might not be able to join Cisco ISE-PIC with an Active Directory domain if the DNS SRV records are missing (the domain controllers do not advertise their SRV records for the domain that you are trying to join to)"
When I sent this to my client, he replied with "That is our problem. Not all DCs can be resolved by global DNS SRV records. But we have all SRV records based by sites"
I have reached my AD DS knowledge on this last one.
Is there a way to address that issue on ISE-PIC?
Thank you
Sam
Solved! Go to Solution.
I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.
I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.