cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1362
Views
0
Helpful
7
Replies

PassiveID add Domain Controller (missing DC)

csco11552159
Level 5
Level 5

Recently we are trying to add new DCs into PassiveID list to use WMI monitoring.

The problems how ISE find the DCs, in our Dev environment, we found some DCs are missing from the list. and we have no way to add them.

 

when use :

nltest /dclist:dev  

We will see 4 DCs.

But from PassiveID "Add Domain Controllers" list, cannot find all of them.

Then we test our production DCs, we have same issues, some "site" DCs are totally missing.

Is some kind reasons about DC"Site" ? 

How does ISE find all DCs available  to add? 

 

 

1 Accepted Solution

Accepted Solutions

I would suspect some issue with AD sites and services and misconfiguration of AD infrastructure since ISE cannot see them. I would open a TAC case to start and work with Microsoft as well to see where the problem lies

View solution in original post

7 Replies 7

Timothy Abbott
Cisco Employee
Cisco Employee

Hi,

 

It sounds like a configuration issue with AD. ISE gets the list of domain controllers when it joins the domain. There is no way to manually add DCs in ISE today. 

 

Regards,

Tim

we saw the same result for other domains. it seems site impacted PassiveID DCs....

 

 

I would suspect some issue with AD sites and services and misconfiguration of AD infrastructure since ISE cannot see them. I would open a TAC case to start and work with Microsoft as well to see where the problem lies

Opened a ticket with TAC wait for some updates. 

 

Psn with passive ID enabled only see the "site" DC which are auto associated with.

 

Passive wmi should see everything .. 

checked with our AD admin, our DNS only resolve some of DC based on domain

but ISE seems not to use API or similar cmd like" nltest /dclist:xxx.com" to resolve the DCs.

 

if this is the case, PassiveID wont work for lots cases especially when large amount DCs in the enterprise.

No one will display 100 DCs based on domain name ....

 

 

 

 

 

I would think that ISE needs all domains in DNS to be able to resolve and work with them. @Timothy Abbott is our SME will await for him to confirm. Right now it sounds like as before will need to tune AD to work with ISE. 

what if we deploy PSN to each "Site", witll ISE use site based DNS resolution to find all DC? 

we do have all site based DNS resolution. If ISE is using this way, it should be able to see all DC at the "site".