cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

380
Views
0
Helpful
1
Replies
Samuel Vuillaume
Cisco Employee

ISE-PIC AD DS (global vs site based SRV request)

uys

 

My client is trying to integrate ISE-PIC with AD (for Passive auth) with “FMC”.

 

In the ISE-PIC Admin guide, I read "You might not be able to join Cisco ISE-PIC with an Active Directory domain if the DNS SRV records are missing (the domain controllers do not advertise their SRV records for the domain that you are trying to join to)"

 

When I sent this to my client, he replied with "That is our problem. Not all DCs can be resolved by global DNS SRV records. But we have all SRV records based by sites"

 

I have reached my AD DS knowledge on this last one.

 

Is there a way to address that issue on ISE-PIC? 

 

Thank you

Sam

1 ACCEPTED SOLUTION

Accepted Solutions
hslai
Cisco Employee

I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.

View solution in original post

1 REPLY 1
hslai
Cisco Employee

I hope you already engaged TAC to troubleshoot this. If I were you, I would enable DEBUG on the AD component and perform a packet capture of DNS requests from ISE-PIC and check what specific records are missing.

Create
Recognize Your Peers
Content for Community-Ad

ISE Webinars


Miss a previous ISE webinar?
Never miss one again!

CiscoISE on YouTube