cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2843
Views
2
Helpful
3
Replies

ISE ports (TCP 464) with AD

saghisha
Cisco Employee
Cisco Employee

We have a customer that is asking if port TCP 464 “KPASS” is required to be opened between the ISE and AD. If yes, what is the exact purpose of opening this port and is it required during the authentication phase ?

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

It is not specifically needed, but could alleviate some headaches.  KPASS is used on TCP Port 464 for Kerberos based password changes.  Starting in Vista, Microsoft used this as the default password change method.  However, if KPASS is not accessible (as in the port is closed), it will default back to NTLM for password changes.

This article goes more in-depth:

https://blogs.technet.microsoft.com/askds/2011/09/30/friday-mail-sack-super-slo-mo-edition/

Charles Moreton

View solution in original post

3 Replies 3

Charlie Moreton
Cisco Employee
Cisco Employee

It is not specifically needed, but could alleviate some headaches.  KPASS is used on TCP Port 464 for Kerberos based password changes.  Starting in Vista, Microsoft used this as the default password change method.  However, if KPASS is not accessible (as in the port is closed), it will default back to NTLM for password changes.

This article goes more in-depth:

https://blogs.technet.microsoft.com/askds/2011/09/30/friday-mail-sack-super-slo-mo-edition/

Charles Moreton

kthiruve
Cisco Employee
Cisco Employee

HI Samer,

Please see the ports that need to be open between ISE nodes. ISE PSN talks to AD using certain functionalities.

For ISE to work correctly the ports need to be open.

http://www.cisco.com/c/dam/en/us/td/i/400001-500000/410001-420000/413001-414000/413702.jpg

Thanks

Krishnan

saghisha
Cisco Employee
Cisco Employee

Thanks Charles. Much appreciated.