ISE problem "Joined to domain but disconnected"

                   Hi all experts.
I recently have experienced this issue.
I have been using ISE1.1.2.145 and joined to AD since the ISE was released, but never seen this error before.
I did not touch any configuration and I was trying to test CWA with multiple WLCs.
I finished all configuration about CWA, and I was verifing if it is working.
while I was trying to login as user on AD, I could not. so I looked up on External Identity Source and it apears.
does anyone know why it is giving me that error ?
the ISE and AD both see the same NTP and time difference between them is only 1 minute, timezone is same.
even though they are looking at the same NTP, it's outside of private network and it is isolated.
also, I am able to ping each other. DNS is working. I don't see why it is not working......
can anyone help me with this problem ?

I had this issue as well but my NTP settings were correct and the time was not slipped at all.
I logged into the cli and ran this: #sh logging application ad_agent.log tail
which led me to this error:
2013-11-15T07:55:57.177566-06:00 host-psn1 adclient[10469]: INFO  base.bind.healing Lost connection to DVN.COM(GC). Running in disconnected mode: KDC refused skey: Preauthentication failed
2013-11-15T07:55:57.282448-06:00 host-psn1 adclient[10469]: ERROR base.adagent Can't use default machine password. Please reset computer account in Active Directory.
Go into Active Directory Users and Computers and right click on the computer account object and click reset account.
Which resulted in these log entries:
2013-11-15T07:57:57.473370-06:00 host-psn1 adclient[10469]: INFO  samba.interop Attempting interoperability with untested Samba version .
2013-11-15T07:57:58.266485-06:00 host-psn1 adclient[10469]: INFO  base.bind.healing Reconnected to odcmsadrw002p.dvn.com(GC).  Running in connected
mode.
2013-11-15T07:58:25.006230-06:00 host-psn1 adclient[10469]: INFO  daemon.main Start trusted domain discovery
2013-11-15T07:58:25.058151-06:00 host-psn1 adclient[10469]: INFO  daemon.main Trusted domain discovery complete : 4 domains found
2013-11-15T07:58:25.058189-06:00 host-psn1 adclient[10469]: INFO  daemon.main Have new domain info map: flushing all negative objects
2013-11-15T07:58:25.100676-06:00 host-psn1 adclient[10469]: INFO  base.kerberos.krb5conf Wrote /etc/krb5.conf
That fixed me up. Hope this helps someone else out there.

Similar Messages

  • Active Directory, Can Join the Domain but some accounts can't log in

    We can put our Macs in AD just like we could in 10.7.4, but some users can login and some can't.  The ones that cant get an error message about an invalid Primary Group. All users in question have their Primary group set to "Domain Users"
    We called Apple Support and the Tech checked with his supervisor and then told us AD isn't supported in Mountain Lion.
    BTW, all these users can login on our 10.7.5 systems.

    Sorry to resurrect an old thread but I just moved to Mountain Lion and have encountered this error.
    I just tested the ID command on a number of user accounts and most of my Tech accounts are coming back "No such user".
    I've got a 10.7.5 system right beside me and when I run the ID <user> on it they all come back reporting normally.
    I've also verified that all the dsconfigad settings match and the Authentication & Search paths are identical.
    Is indicative of the 10.8.2 AD plug in being the problem? or is there something I'm missing?

  • USB drives not accessible until I join a domain

    Hi,
    I´ve been struggling with this problem for a loong time now.
    Simply put, I want to use a usb drive in a laptop running Windows 7, and the device is detected correctly but Windows says that I need to format it. And in My Computer the drive has got a letter but when I doubleclick it it says it´s unaccessible. But if
    I join the laptop to my customers AD it suddenly works as it should.
    Since I discovered that, I just ignored it since all computers would join the domain, but now I need to install several laptops that´s not going to be ad-joined. So I need help solving this usb problem.
    The customers uses laptops(Dall Latitude Exxx models) only and we install these using WDS. I think that all models of laptops have this issue and all usb drives. I haven´t been able to narrow it down to a certain model or anything else.
    Everything else works as they should. The usb ports works fine using mouse and keyboard and similar. It´s only usb drives that are the problem.
    I know that the hardware isn´t faulty since I can boot up using Linux and everything is fine, plus when I join the domain everything is also fine.
    I have tried reinstalling chipset/usb drivers but nothing has helped. Also sfc /scannow doesn´t help.
    Using gpedit.msc I set everything in "Users/Administrative/System/Access to removable storage" to inactive but this makes no difference.
    I have not had this problem outside this customer.
    Does anyone have any ideas? If so, please help!
    Regards,
    //Andreas..

    Hi,
    we should figure out what’s the difference between the two situations.  I have the following thoughts to narrow down this cause:
    Do you have preinstalled any security applications in your image?
    Does this issue occur to all USB devices?
    After  you join the domain, can you log on with a local account to access USB devices?
    You can get the security policies via rsop.msc as well.
    If you have any feedback on our support, please click
    here
    Alex Zhao
    TechNet Community Support

  • Win 10 TP join a domain greyed out

    Did a fresh install of Win 10 TP 9926 on a Dell Latitude 10 tablet with an Atom processor
    Want to join a domain but the choice is greyed out?
    Why is that?
    Thanks!

    Hi City High Tech,
    You may choose to use Windows Update to upgrade to Windows 10 build 10041, or download the Windows 10 build 10041 ISO through the link below:
    http://windows.microsoft.com/en-us/windows/preview-iso
    You should first click the check box of Domain, then the box should be ready to input the domain name:
    Or you may click the Start Button, select Settings, then navigate to system->About, on the right side, click join a domain:
    Best regards
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Windows live mail having problum after joining in domain examples incoming is good but sent or outgoing is not there and also send mails are not exporting at the time of live mail exporting time?

    windows live mail having problem after joining in domain examples incoming is good but sent or outgoing is not there and also send mails are not exporting at the time of live mail exporting time?

    This is not usually related to AD issues, but it may be more of a DNS issue. I posted a request in your other thread to post an unedited ipconfig /all of the DC and of the client.
    This may help use diagnose this issue and your other thread's printer issues.
    Thank you,
    Ace Fekay
    MVP, MCT, MCSE 2012, MCITP EA & MCTS Windows 2008/R2, Exchange 2013, 2010 EA & 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
    Microsoft Certified Trainer
    Microsoft MVP - Directory Services
    Complete List of Technical Blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
    This posting is provided AS-IS with no warranties or guarantees and confers no rights.

  • I created a website with iWeb but use GoDady for hosting it rather than MobileMe. The images on my Gallery page do not show at all on the external domain but they DO show when seen on MobileMe. Has anyone encountered this problem before? Many thanks!

    Hello al!
    I created a website with iWeb but use GoDady for hosting it rather than MobileMe. The images on my Gallery page do not show at all on the external domain but they DO show when seen on MobileMe. Has anyone encountered this problem before? Many thanks!

    Just create a new page (or use the existing photo page) on your external site and use html to add an iframe sized to the page and link it to the mobilme gallery page. Works for me just fine when showing my gallery from a yahoo site.
    like this
    <iframe scrolling="off" allowTransparency="true" frameborder="0" scrolling="yes" style="width:100%;height:100%;border:none" src="http://gallery.me.com/your_account_name"></iframe>

  • I have an ipad3(wifi  cellular). Now i want to upgrade my iOS5.1 to ios 7. But download speed in our country is too slow(100kbps). It can be disconnected anytime. Is there any problem if net connection get disconnected while upgrading ios? Please ans me.

    I have an ipad3(wifi +cellular). Now i want to upgrade my iOS5.1 to ios 7. But download speed in our country is too slow(100kbps). It can be disconnected anytime. Is there any problem if net connection get disconnected while upgrading ios? Please ans me.

    haha, so now i'm thinking. I'm learning the terminal as fast as i can but there are several lines of codes and commands in there that throws up red flags to me that i don't fully understand. It just looks fishy too me. It would be highly appreciated if someone could just check this out just to tell me that i don't need to worry about it. Or point me in the right direction. I just feel un easy about this. ha.

  • HT1766 I have an ipad3(wifi +cellular). Now i want to upgrade my iOS5.1 to ios 7. But download speed in our country is too slow(100kbps). It can be disconnected anytime. Is there any problem if net connection get disconnected while upgrading ios? Please a

    I have an ipad3(wifi +cellular). Now i want to upgrade my iOS5.1 to ios 7. But download speed in our country is too slow(100kbps). It can be disconnected anytime. Is there any problem if net connection get disconnected while upgrading ios? Please ans me.

    There is something Definitely wrong with iOS 7 regarding DATA USAGE being logged to wireless carrier in for WIFI instead.
    I read all the previous replies and same issue.
    I rarely use my mac to sync....its all wifi sync for the last 2 years....never had this issue before... and i know it began with iOS7.... here is why....
    My iPhone was at home when I updated to iOS7 connected to wifi...but it logged Data Usage to Rogers Wireless (700MB approx)...data will never do an update over 50mb in app store (it gives the warning to use wifi) I play a lot of games and pay for them so I always update through App Store.  2 weeks later, simposons halloween update (650mb)...at home, using wifi.
    Rogers told me there was 700+mb data usage on the day of update and 650+mb data on oct 1.st (tapped out).
    Went over my 6GB plan and paid the fees.
    This has never happened before...It must come to apples attention by now...

  • Windows 7 can not joinng to domain but windows Xp does in Virtual Box Manager

    Dear all,
    I need your support and thanks in advance.
    I have installed Windows 7 and Windows 2008 server in a Virtual Box. Windows 2008 server is my Domain Controller and DNS is configured. Please find my configuration below.
    Domain Controller FQDN name - bbi.in
    IP addrees - 192.168.10.14
    subnet mask- 255.255.255.0
    gateway-   192.168.10.254
    Preferred Dns - 192.168.10.14
    Windows 7  having IP address 192.168.10.2
    Ping connectivity is working from both end
    My Problem is  my windows 7 machine is not joining to domain.
    while doing Nslookup command from windows 7 command prompt I am getting default server and Ip address of the domain controller.
    I have been trying a lot and did lots of trouble shooting but can not get any solution plz.... help

    On Fri, 14 Nov 2014 17:55:41 +0000, biswajeetpattnaik wrote:
    When I join the domain I use bbi and and I get authentication asking for user name and password.
    Please find the attached error screen shot<https://social.technet.microsoft.com/Forums/getfile/567235><https://social.technet.microsoft.com/Forums/getfile/567236>
    This forum is for issues relating to Windows Server 10 Technical Preview
    only, and not for Windows Server 2008, Windows 7 nor Windows XP. Please
    post your question a forum that is for the correct topic.
    Paul Adare - FIM CM MVP
    All that blue light from Orthanc at night? That was
    Saruman, trying to moderate
    -- news.admin.palantir-abuse.sightings.

  • Tecra A9: Cannot join a domain or view websites wirelessly - Vista

    I'm having a problem with wireless networking on this new installation of Vista.
    I can view & connect to a wireless router no problem but when I try to join a domain or view most web pages it just will not play ball.
    I can ping both local and external addresses and some web pages work with no problem at all.
    I have tried updating the wireless drivers from the toshiba web site and when that did not make a difference from the intel website but to no avail.
    If i plug in a network cable everything works fine.
    I have another notebook running XP which connects to the same wireless router and has none of these problems.
    Help!
    Stu

    Seems that there is nothing wrong with your wireless lan device at all. I think there are some settings of Vista, that prevent some internet pages from working, maybe built in firewall or antivirus program. Internet Explorer 7 has built in some security features as well, so you might take a look at this.
    Perhaps the first thing you could try is to use another internet browser, like firefox and check firewall settings.

  • Windows 8.1 VPN Functionality dissappears after joining a domain

    Hello!
    I can not seem to Identify the cause behind the following problem, I assume it is GP or permission related but I can not discover where.
    Summary:
    -New Tablet purchased from dell (Venue 11 pro series) started as windows 8.1 and the 8,1 pro pack update key was applied to enable domain functionality
    -Setup and create network connections and establish a VPN connection as the local Admin ( Everything works)
    -Join a domain
    -Log on as a domain Admin
    -Attempt to setup a VPN connection and an error is displayed in Charms saying "There is a problem with your modem or network adapter"
    -Sign off and log on as the local administrator
    -Attempt the same VPN setup, and the connection works and I receive the login credentials window in charms and the VPN can be established.
    If anyone has any knowledge about this please let me know, I have yet to find 1 case similar to this.
    ****Update-
    The VPN Connection appears in the Internet Options window Under the connections Tab, but when opening settings and properties I receive the following error:
    "Cannot Load the remote access connection manger service.
      error 5: Access Is denied"
    In services the accounts appear to be correct for the log-on as local system
    Attempting to change this to a domain admin account or local admin account proved to cause addition problems with other services because they did not have the same log-on accounts being used in the same process... 
    Again a search on this has yielded results for other OS but not Windows 8.1, Any fixes for these other OS that were attempted resulted in more log-on confilcts.
    Any help would be appreciated.

    Hi,
    According to your description, it seems like there was a problem with remote access connection manager service, please access to the path below to check RasMan rights, make sure all the user have write rights.
    1. WIN+R, open Run, type regedit, press Enter.
    2. Narrow to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RasMan
    If problem persists, please contact Domain Adminstrator to check if there any limits with VPN.
    Roger Lu
    TechNet Community Support

  • Windows 7 Computer refuses to join 2003 Domain.

    Hey guys, I'm having a slight problem over here on my end connecting two new windows 7 pro PC's to the 2003 R2 server downstairs.
    What's happening is that the domain name 'Name.root' is not found by either computer, but if I type in 'Name' I get a prompt to join the domain with a valid username and password associated.  I've tried every username I have and even created
    one on the server for myself to test with, but it still gives me an error that the password/username is incorrect.
    As far as I know, the server and clients are all using DHCP and the DNS suffix is pointing to the same name. I can even ping the server from the computers upstairs, but if I use NSLookup, it only shows the router that's being used.
    There are other windows XP pro units that will all connect using the same exact settings, so at this time I'm completely stumped as to what my next steps are.  Any help with this would be greatly appreciated.

    Hi,
    To find out what's your network environment, please upload the ipconfig /all results from Windows 7 client and Windows server 2003 R2.
    I recommend you to manually assign IP address and DNS for Windows clients and Windows server 2003 R2 instead of using DHCP.
    Also, please check if SRV record is created in DNS manager.
    You can refer to the article below:
    http://support.microsoft.com/kb/816587
    And recommend add such an entry: <FQND of domain> <server ip> to host file in windows client.
    The path for host file is in %windir%\system32\drivers\etc\hosts.
    Andy Altmann
    TechNet Community Support

  • Solaris 11 - can't join AD domain

    I've upgraded to Solaris 11 from 11 Express and am trying to join the system to an Active Directory domain. I first joined workgroup, then tried to rejoin the domain, at which time I get the following (names changed to protect the anonymous):
    myuser@ganesh:~# smbadm join -u "DomainAdmin" lothlorien.domain.com
    After joining lothlorien.domain.com the smb service will be restarted automatically.
    Would you like to continue? [no]: yes
    Enter domain password:
    Locating DC in lothlorien.domain.com ... this may take a minute ...
    Joining lothlorien.domain.com ... this may take a minute ...
    failed to join lothlorien.domain.com: UNSUCCESSFUL
    Please refer to the system log for more information.
    /var/adm/messages shows this:
    Nov 11 00:46:17 ganesh smbd[641]: [ID 270243 daemon.error] smb_ads_update_dsattr: ldap_sasl_interactive_bind_s Local error
    Nov 11 00:46:35 ganesh smbd[641]: [ID 702911 daemon.error] smbns_kpasswd: KPASSWD protocol exchange failed (Cannot contact any KDC for requested realm)
    Nov 11 00:46:35 ganesh smbd[641]: [ID 702911 daemon.notice] Machine password update failed
    Nov 11 00:46:35 ganesh smbd[641]: [ID 702911 daemon.error] unable to join lothlorien.domain.com (UNSUCCESSFUL)
    I know for sure the system is locating the DC and trying to register itself - I can see the events in the Windows event log. Having deleted the previous computer account, if I watch the Computers node of the AD Users & Computers MMC snap-in, I can see the Solaris system appear briefly as disabled, then disappear a few seconds later (with corresponding events in the DC's Security event log).
    I can't find any documentation specific to S11 (as opposed to SE11) that addresses what might be different (if anything) in the smb join protocols. I know by now that S11 can autogenerate your /etc/krb5/krb5.conf so the fact that I can delete/rename that file and it will reappear with valid information validates the fact that it does locate and connect to the (K)DC and get relevant config info, not to mention that I can type garbage for my domain password and the behavior is different so it can do kerberos authentication.
    I think the key error here is the "ldap_sasl_interactive_bind_s Local error" but it's not enough information for me to determine causality. I've already gone through Google searches and implemented changes related to the NTLM levels and so forth, but unlike with SE11 which I did have working, these did not solve the issue.
    I'm still trying to go through the S11 documentation including the End of Feature Notices for what's changed but I didn't see anything revelatory in the Interop guide. I know this could also be something that's in my AD/GP configuration on the Windows side (e.g. I've implemented a PKI and strengthened system authentication among certain domain members). Has anyone run into anything similar? Do you have S11 (as opposed to SE11) joined to your domain?

    I finally got this figured out. It's a problem with client_lmauth_level on the smb service. the below script snippet configures Solaris 11 to join an AD domain on Windows 2008 R2:
    echo *** Installing SMB system
    pkg install system/file-system/smb
    echo *** Installing SMB service
    pkg install service/file-system/smb
    echo server $TIMESERVER > /etc/inet/ntp.conf
    svcadm enable ntp
    echo *** Joining domain: $DOMAIN
    svccfg -s smb setprop smb/client_lmauth_level=2
    svcadm enable -r smb/server
    smbadm join -u $DOMAIN/$DOMAINADMIN
    Obviously, you should set the various variables for your local environment and probably a good idea to sync the clock explicitly instead of assuming ntpd will do it for you.
    In addition, I had to set the auth level on the Windows 2008 domain:
    Start -> Admin Tools -> Local Secuity Policy: Security Settings -> Local Policies -> Security Optiopns:
    Network Security: LAN Manager authentication Level = Send LM & NTLM - Use NTLMv2 security session if negotiated

  • 7410 CIFS/NFS cannot join AD domain

    I've been asked to help on this issue but I know little about the 7410 configuration, and the Admin Guide available wasn't much help with some of the errors I've seen.
    This is a Sun Storage 7410 Version ak/SUNW,[email protected],1-1.17
    CIFS and NFS are enabled, and appear to be configured correctly as far as controller names, IP addresses, etc. DNS is working and nslookup from the CLI does work. Lan Man Compatibility Level is set to 2. Looking in the logs, I noticed that in the log labled system-identity:node, there is a line that says:
    aksh fatal error: could not connect to akd; is it both enabled and running?
    What does this refer to?
    Also, in the top title bar of the 7410 GUI, there is an error which says:
    An attempt to import the resource 'ak:/ad/da0f40fc-014e-ca1f-880d-892ff109361c' has failed
    Was this error as a result of someone trying to join a domain, or is it some other indicative error? When an administrator attempts to join a domain, the message "no such domain" appears, but the domain does indeed exist.
    What else can I look at to find out the source of this problem?
    Edit: I should add that we can ping to this 7410 by IP, but not by host name.
    much thanks
    Edited by: mdinaz on Jul 29, 2009 12:23 PM

    I would recomend sticking the latest patch on - there's a fix in there for AD 2008 domains - though not sure if this is your issue. Also, I don't think the box will show in DNS until it is added to the domain (unless manually added to the DNS server).
    http://wikis.sun.com/display/FishWorks/Sun+Storage+7000+Series+Software+Updates
    hth. Chris

  • WinXP computers can't join the domain

    Hi, I'm setting up my first Xserve and I'm having troubles making WinXP machines join the domain.
    With OS X and Win98 clients I have no problems with the tests accounts I have created, but with with WinXP machines I get the error that they can't Join the domain becouse Access is Denied. I don't think is a configuration error on the server's services or the WinXP boxes becouse I can join the domain and access the account for diradmin OK from the WinXP boxes, so it may be an account configuration problem.
    Also the accounts have network home folders, don't know if this might also cause a problem, I did try with no home assigned and still got the same error.
    Any help would be appreciated

    Fixed the problem myself....
    Creted a new account and dindn't move anything on it, nothing managed and nothing changed on the account windows tab.
    Joined the domain with the diradmin account, and after the reboot used the new test user, logged in fine and home folder was mounted as a Network drive perfectly.
    Hope this helps someone in the future

Maybe you are looking for