cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1464
Views
0
Helpful
4
Replies

Cisco FMC does not receive information about AD users from ISE

alyautdinov
Level 1
Level 1

Hi,

 

I made an integration between FMC 7.0 and ISE3.0 through pxgrid. Connection works fine.

Primary host:
[INFO]: PXGrid v2 is enabled
[INFO]: pxgrid 2.0: account activate succeeded
[INFO]: Successful connection to ********:8910
[INFO]: These ISE Services are up: SessionDirectory, SXP, EndpointProfile, SecurityGroups, AdaptiveNetworkControl
[INFO]: All requested ISE Services are online.

 

But FMC does not receive any information about Users in Analysis - Users tab.

When i perform the command "adi_cli session" from FMC CLI I see next:

received realm information: operation REALM_DELETE_ALL, Null realm info
received realm information: operation REALM_ADD, realm name eiu.lab, short name EIU, id 2
ADI is connected
received security group operation: DELETE ALL
received security group operation: ADD id: 92bb1950-8c01-11e6-996c-525400b48521 name: ANY fullyQualifiedName: Any Security Group tag: 65535
received security group operation: ADD id: 934557f0-8c01-11e6-996c-525400b48521 name: Auditors fullyQualifiedName: Auditor Security Group tag: 9
received security group operation: ADD id: 935d4cc0-8c01-11e6-996c-525400b48521 name: BYOD fullyQualifiedName: BYOD Security Group tag: 15
received security group operation: ADD id: 9370d4c0-8c01-11e6-996c-525400b48521 name: Contractors fullyQualifiedName: Contractor Security Group tag: 5
received security group operation: ADD id: 93837260-8c01-11e6-996c-525400b48521 name: Developers fullyQualifiedName: Developer Security Group tag: 8
received security group operation: ADD id: 9396d350-8c01-11e6-996c-525400b48521 name: Development_Servers fullyQualifiedName: Development Servers Security Group tag: 12
received security group operation: ADD id: 93ad6890-8c01-11e6-996c-525400b48521 name: Employees fullyQualifiedName: Employee Security Group tag: 4
received security group operation: ADD id: 93c66ed0-8c01-11e6-996c-525400b48521 name: Guests fullyQualifiedName: Guest Security Group tag: 6
received security group operation: ADD id: 93e1bf00-8c01-11e6-996c-525400b48521 name: Network_Services fullyQualifiedName: Network Services Security Group tag: 3
received security group operation: ADD id: 93f91790-8c01-11e6-996c-525400b48521 name: PCI_Servers fullyQualifiedName: PCI Servers Security Group tag: 14
received security group operation: ADD id: 940facd0-8c01-11e6-996c-525400b48521 name: Point_of_Sale_Systems fullyQualifiedName: Point of Sale Security Group tag: 10
received security group operation: ADD id: 9423aa00-8c01-11e6-996c-525400b48521 name: Production_Servers fullyQualifiedName: Production Servers Security Group tag: 11
received security group operation: ADD id: 9437a730-8c01-11e6-996c-525400b48521 name: Production_Users fullyQualifiedName: Production User Security Group tag: 7
received security group operation: ADD id: 944b2f30-8c01-11e6-996c-525400b48521 name: Quarantined_Systems fullyQualifiedName: Quarantine Security Group tag: 255
received security group operation: ADD id: 94621290-8c01-11e6-996c-525400b48521 name: Test_Servers fullyQualifiedName: Test Servers Security Group tag: 13
received security group operation: ADD id: 947832a0-8c01-11e6-996c-525400b48521 name: TrustSec_Devices fullyQualifiedName: TrustSec Devices Security Group tag: 2
received security group operation: ADD id: 92adf9f0-8c01-11e6-996c-525400b48521 name: Unknown fullyQualifiedName: Unknown Security Group tag: 0

 

This is lab environment I can not make a case with TAC.

 

Any suggestions?

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

It appears you're only getting SGTs.

Are you subscribed to Session Directory topic (in the FMC integration settings for ISE)?

Does your ISE server have user-IP mapping data to export?

Hi Marvin,

Yes I have subscribed to Session Directory topic and I see in Operation-Radius-Live Logs successful authentications.

It is working on my another lab with ISE2.4 and FMC6.4 but it is not working with ISE3.0 and FMC7.0, maybe some additional settings I have to do?

alyautdinov
Level 1
Level 1

I have figured it out. There were not accounting settings on NAD so after I set it information started receiving.

@alyautdinov  Thanks for the update.

Review Cisco Networking for a $25 gift card