cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

3250
Views
10
Helpful
4
Replies
Daniel Martins
Beginner

SRV Record Found. Not All SRV Records Have IP, Will Need To Run Additional Query For Get IP.

Hi Gang,

 

ISE has been fine and recently, this warning has occurred:

 

"SRV Record Found. Not All SRV Records Have IP, Will Need To Run Additional Query For Get IP."

 

I've checked our AD SRV records by using:

  1. NSLOOKUP > set type=all
  2. _LDAP._TCP.DC._MSDCS.domain_name.com
  3. I see 8 SRV records as expected, all up-to-date. However, the returned internet addresses seem to be truncated i.e. only 5 internet addresses are returned for the 8 SRVs? Is this what ISE is referring to? That it needs to do an additional lookup to obtain the IP addresses?

What exactly is happening here and how does one resolve this error? 

 

We are running ISE 2.4 with Patch 9. 

 

Thanks Gang!


Dan

1 ACCEPTED SOLUTION

Accepted Solutions
hslai
Cisco Employee

Yes, you are correct about the DNS records. If possible, please reduce the number of records to make it more efficient.

View solution in original post

4 REPLIES 4
hslai
Cisco Employee

Yes, you are correct about the DNS records. If possible, please reduce the number of records to make it more efficient.

View solution in original post

Thanks for getting back yo me hslai!

 

Thank you for confirming this expected bevahiour.

Mike.Cifelli
VIP Advocate

Adding comments:

If using AD as an external ID source a good troubleshooting tool via your PAN gui can be found here: Administration->Identity Management->External ID Stores-><your respective source>

Click one of you nodes & run the Diagnostic tool

 

This can allow you to check whether or not things such as SRV records, etc. are good from ISE perspective. 

Romzy
Cisco Employee

You may need to check AD debugs on ISE as well to confirm the response is "ok" for SRV test.

 

DNSDiag::resQueryDomainSRVrecordsInAllNS() - Query response is ok for _ldap._tcp.dc._msdcs.Domain_Name

DNSDiag::doTest() - Completed running test DNS SRV record query

 

Create
Recognize Your Peers
Content for Community-Ad

ISE Webinars



Did you miss a previous ISE webinar?

CiscoISE YouTube Channel