cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2216
Views
10
Helpful
4
Replies

RODC with ISE-PIC (wmi or agent)

Spyros Kasapis
Level 1
Level 1

Hello ,

 

it is clear that it is not supported but is there any workaround ?

1 Accepted Solution

Accepted Solutions

Talk to your AD admins. They can do whatever they want to the controllers, but you can only read group memberships from them - hence the name Read Only Domain Controller.

View solution in original post

4 Replies 4

thomas
Cisco Employee
Cisco Employee

The ISE PIC 3.1 Admin guide says

Cisco ISE does not support Read-only Domain Controller for authentication flows.

But ISE PIC does not perform authentication - it is passive and only receives events for username to IP login/mapping events.

Hello Thomas ,

 

can we deploy agents in Read-Only Domain Controllers and learn active connections from there ?

 

Thank you in advance.

Talk to your AD admins. They can do whatever they want to the controllers, but you can only read group memberships from them - hence the name Read Only Domain Controller.

Hi thomas ,

I am not asking about under ISE PIC. To join RODC with ISE do we need to join RODC as active directory or under LDAP? Is it possible to join RODC as Active directory (not under LDAP) for the authentication purpose? Because I see some authentication protocol limitations under LDAP.