cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1945
Views
0
Helpful
6
Replies

Passive ID and Read-Only DCs

paul
Level 10
Level 10

I am sure this is documented somewhere, but I can't find it.  Does passive ID support RO DCs?  When I bring up the DC list in ISE I don't see any of my customer's RO DCs.  The SourceFire user agent support RO DC monitoring and we are trying to replace that agent with ISE passive ID.

1 Accepted Solution

Accepted Solutions

There are no updates to that enhancement request, so this enhancement does not appear to be implemented in any current versions of ISE. The workarounds mentioned earlier in the thread are still available.

ISE 3.0, however, does support Passive ID using MS-Eventing API or Microsoft Remote Procedure Call (MSRPC) protocol as per the Release Notes. You might test if that works with your RODCs instead.

View solution in original post

6 Replies 6

hslai
Cisco Employee
Cisco Employee

CSCvr32010 is a known issue on this area.

Hsing,



That bug is not public. Can you send it over to me?


hslai
Cisco Employee
Cisco Employee

The bug has been marked customer-visible since Sept-19 so not sure why you are unable to see it.

It's an enhancement request to add Passive ID support for RODCs and the current workaround is using Windows Event Forwarding (WEF) or a syslog forwarder.

Any update for this issue pls

There are no updates to that enhancement request, so this enhancement does not appear to be implemented in any current versions of ISE. The workarounds mentioned earlier in the thread are still available.

ISE 3.0, however, does support Passive ID using MS-Eventing API or Microsoft Remote Procedure Call (MSRPC) protocol as per the Release Notes. You might test if that works with your RODCs instead.

medgaz
Level 1
Level 1

Hello, I am having the same issue, I have configured RODC to send security events to DCs, but MSRPC agent is not reading those users? Do you know why?