Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Recently we are trying to add new DCs into PassiveID list to use WMI monitoring.
The problems how ISE find the DCs, in our Dev environment, we found some DCs are missing from the list. and we have no way to add them.
when use :
nltest /dclist:dev ...
Hi,
if we are using WMI to monitor all our DCs( over 100 in 2 forests), the account we used for WMI has to change the password every year .....
Is there a way to do a bulk edit to update the password?
2nd question, we have local PSN cluster and DC...
i m following the PIC document: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/pic_admin_guide/PIC_admin/PIC_admin_chapter_01000.html#task_784A7…when we talk to our Corp Sec and ID team for changing registry key to allow our account with full...
i got TS agent working with ISE 2.2 .on ISE 2.2, I can see the User ID, IP and Port range mapping in live session table.But on FMC, it doesnt show these information.If i use TS agent directly sent to FMC, it will work. Is this some kind of bug betwe...
Hi folks,we are going to enabled PIC feature and pxgrid feature on our production ISE.What is the best practice of deployment PIC feature and pxgrid ?Do we need dedicated PSN for PIC features? And do we need dedicated nodes for pxgrid?
what if we deploy PSN to each "Site", witll ISE use site based DNS resolution to find all DC?
we do have all site based DNS resolution. If ISE is using this way, it should be able to see all DC at the "site".
checked with our AD admin, our DNS only resolve some of DC based on domain
but ISE seems not to use API or similar cmd like" nltest /dclist:xxx.com" to resolve the DCs.
if this is the case, PassiveID wont work for lots cases especially when large a...
Opened a ticket with TAC wait for some updates.
Psn with passive ID enabled only see the "site" DC which are auto associated with.
Passive wmi should see everything ..
i see. thank you.
Do you know if there is a session limitation?
Like Agent method, in the document mentions that each agent can monitor 10 ADs.
Is there a limitation for WMI to monitor ADs ?