02-10-2021 09:01 PM
ISE cannot join AD. I got below error messages. One of them mentions "Unreachable Server List:", its right. the dns ip address already changed. but I do not know where i can change the ip address in ISE accordingly. If this is case, can you show where to change the ip address in ISE? Thank you
Detailed Log:
Error Description :
Cannot retrieve TGT for account administrator@ABC.LOCAL , Invalid username or password
Error Resolution :
please check machine account : administrator@ABC.LOCAL password in dc DC3.ABC.local , this error might occur due to replication errors
Join steps :
23:36:35 Joining to domain ABC.LOCAL using user administrator
23:36:35 Searching for DC in domain ABC.LOCAL
23:36:35 Found DC: DC3.ABC.local , client site is Default-First-Site-Name , dc site is Default-First-Site-Name
23:36:35 Checking credentials for user administrator
23:36:35 Getting TGT for account administrator@ABC.LOCAL
23:36:36 Cannot retrieve TGT for account administrator@ABC.LOCAL , Invalid username or password
-------------------------------
Result And Remedy...
The Following Servers Could Not Be Reached, Please Check DNS And Network Configuration. Unreachable Server List:
10.0.10.200
---------------------------------
Test Name :Kerberos check SASL connectivity to AD
Description :Checks secure connectivity to AD (using SASL mechanism)
Instance :DC3
Status :Failed
Start Time :23:54:01 10.02.2021 EST
End Time :23:54:01 10.02.2021 EST
Duration :<1 sec
Result and Remedy...
Could not get Machine account info : Machine is not joined to AD. PBIS error code: NERR_SetupNotJoined. Check Kerberos configuration and network settings
Solved! Go to Solution.