Authentication (Windows Server 2013) AD Cisco ISE problem

Background:

Has deployed two Cisco ISE 1.1.3. ISE will be used to authenticate users wireless access admin WLC and switches. Database backend is Microsoft running on Windows Server 2012 AD. Existing Cisco ACS 4.2 still running and authenticate users. There are two Cisco WLCs version 7.2.111.3.

Wireless users authenticates to AD, through works of GBA 4.2. Access admin WLC and switches to the announcement through ISE works. Authentication with PEAP-MSCHAPv2 access and admin PAP/ASCII wireless.

Problem:

Wireless users cannot authenticate to the announcement through ISE. This is the error message '11051 RADIUS packet contains invalid state attribute' & '24444 Active Directory failed because of an error that is not specified in the ISE'.

Conducted a detailed test of the AD of the ISE. The test was a success and the result seems fine except for the below:

xxdc01.XX.com (10.21.3.1)

Ping: 0 Mins Ago

Status: down

xxdc02.XX.com (10.21.3.2)

Ping: 0 Mins Ago

Status: down

xxdc01.XX.com

Last success: Thu Jan 1 10:00 1970

March 11 failure: read 11:18:04 2013

Success: 0

Chess: 11006

xxdc02.XX.com

Last success: Fri Mar 11 09:43:31 2013

March 11 failure: read 11:18:04 2013

Success: 25

Chess: 11006

Domain controller: xxdc02.xx.com:389

Domain controller type: unknown functional level DC: 5

Domain name: xx.COM

IsGlobalCatalogReady: TRUE

DomainFunctionality: 2 = (DS_BEHAVIOR_WIN2003)

ForestFunctionality: 2 = (DS_BEHAVIOR_WIN2003)

Action taken:

Log Cisco ISE and WLC by using the credentials of the AD. This excludes the connection AD, clock and AAA shared secret as the problem.

(2) wireless authentication tested using EAP-FAST, but same problem occurs.

(3) detailed error message shows below. This excludes any authentication and authorization policies. Even before hitting the authentication policy, the AD search fails.

12304 extract EAP-response containing PEAP stimulus / response

11808 extracted EAP-response containing EAP - MSCHAP VERSION challenge response to the internal method and accepting of EAP - MSCHAP VERSION such as negotiated

Evaluate the politics of identity

15006 set default mapping rule

15013 selected identity Store - AD1

24430 Authenticating user in Active Directory

24444 active Directory operation failed because of an error that is not specified in the ISE

(4) enabled the registration of debugging AD and had a look at the logging. Nothing significant, and no clue about the problem.

(5) wireless tested on different mobile phones with the same error and laptos

(6) delete and add new customer/features of AAA Cisco ISE and WLC

(7) ISE services restarted

(8) join domain on Cisco ISE

(9) notes of verified version of ISE 1.1.3 and WLC 7.2.111.3 for any open caveats. Find anything related to this problem.

10) there are two ISE and two deployed WLC. Tested a different combination of ISE1 to WLC1, ISE1 to WLC2, etc. This excludes a hardware problem of WLC.

Other possibilities/action:

1) test it on another version WLC. Will have to wait for approval of the failure to upgrade the WLC software.

(2) incompatibility between Cisco ISE and AD running on Microsoft Windows Server 2012

Did he experienced something similar to have ideas on why what is happening?

Thank you.

Update:

(1) built an another Cisco ISE 1.1.3 sever in another data center that uses the same domain but other domain controller. Thai domain controller running Windows Server 2008. This work and successful authentication.

(2) my colleague tested in a lab environment Cisco ISE 1.1.2 with Windows Server 2012. He has had the same problem as described.

This leads me to think that there is a compatibility issue of Cisco ISE with Windows Server 2012.



Yes, it seems that 1.1.3 doesn't support Server 2012 as of yet.

External identity Source OS/Version

Microsoft Windows Active Directory 2003 R2 32-bit and 64-bit

Active Directory Microsoft Windows 2008 32-bit and 64-bit

Microsoft Windows Active Directory 2008 R2 64-bit only

Microsoft Windows Active Directory 2003 32-bit only

http://www.Cisco.com/en/us/docs/security/ISE/1.1/compatibility/ise_sdt.PDF

Tags: Cisco Security

Similar Questions

  • Windows Server 2012 Foundation and SMB problems with older equipment

    Hello

    My problem would be resolved if I had Windows Server R2 2012 but I have Windows Server 2012 Foundation.

    This article describes the problem exactly: https://support.microsoft.com/en-us/kb/2896636

    But of course, the solution does work with my version of the server.

    Does anyone know if there is a similar fix available?  I got my hunting.

    This issue is beyond the scope of this site (for consumers) and to be sure, you get the best (and fastest) reply, we have to ask either on Technet (for IT Pro) or MSDN (for developers)

    If you give us a link to the new thread we can point to some resources it
  • disable authentication Windows Server 2012

    How to disable the windows on Windows Server 2012 passthrough authentication? in other words, if I try to access http://xxx.xxx.xxx.xxx/Reports/Pages/Folder.aspx, I want that he ask for login info. However, I want to say is "user"WIN randomStuff\userName"has no permissions. ...

    This issue is beyond the scope of this site (for consumers) and to be sure, you get the best (and fastest) reply, we have to ask either on Technet (for IT Pro) or MSDN (for developers)

    If you give us a link to the new thread we can point to some resources it
  • Pavilion p6110t CTO Desktop: drivers for Windows Server 2008 and HARD drive problems

    Recently, I had the hard drive with my OS failure. After replacing the hard drive and reinstall windows server 2008, I seem to have encountered some problems with drivers.  After insalling Windows, I had 3 items in my device manager that not have installed correctly. I could get the driver for the LAN port to work, but I did not get the driver to "Standard VGA Graphics Adapter" and "SM Bus controller". After a little research, I believe that the graphics card is a Radeon HD4350. With this information, I still have been unable to toinstlal the correct drivers or the other of these elements. I tried several drivers listed on the support page of the drivers on the HP website, but all fo return them the same error of not finding the right operating system. The link to the driver, I used initially on my previous installation seems is no longer valid.

    Also, I can't access two additoinal hard disks (sata connected). They were used with the previous installation of windows without any problem. They appear in the Device Manager but do not show in my computer. A removable disk appears that I don't know what it is. Previously I used the software to mirror one of the disks on the other in order to avoid the loss of data if a disk fails. Is one of the above players with not be able to access the drives causing the problem or the software used before the problem?

    Any help on these questions is greatly appreciated.

    Ok.

    I can't help you with the readers then.  It is out of my area of knowledge.  If they are healthy and active in the disk management utility, then that's all that I know these should be reported.

    As for the graphics drivers...

    Download and install this free utility for files.

    http://www.7-zip.org/

    After installing 7 - zip, right-click on the graphic driver file and select 7 - zip from the list of options.

    Choose 7-zip to extract to: and leave it to unzip the file in a folder.  I have it extracted the file name of the file.

    Then just follow the rest of my instructions to install the driver.

    Of course that you you first go to where 7 - zip extract the folder and continue from there.

  • With Windows Server 2008 R2 Standard activation problem

    Dear team,

    We try to activate windows Server 2008 R2 Standard, but it shows the error below, we already try to loging Admin Domain_Admin account & local.

    Error: 0 x 80070005 access denied: the requested action requires elevated privileges.

    This issue is beyond the scope of this site (for consumers) and to be sure, you get the best (and fastest) reply, we have to ask either on Technet (for IT Pro) or MSDN (for developers)

    If you give us a link to the new thread we can point to some resources it
  • new PowerEdge: windows server 2003 standard r2 install problem

    Hi all

    so I started with this procedure

    1. Insert the Dell Systems Build and Update Utility CD or the Dell and Documentation DVD systems management tools in the CD player.
    2. Reboot your system and boot from the CD/DVD.
    3. Select Dell Systems Build and Update Utility to go to the Dell Systems Build and Update Utility Home screen.
    4. Click the server operating system Installation.
    5. Follow the instructions step by step to set up your hardware and to install your operating system.

    Now in the select list of Os, I chose windows server 2003 sp2. When I come to the part where it asks for my o/s drives, I get a "invalid" drive, and my windows install dvd is ejected.

    I use our msdn 2939.3 disc titled "Windows Server 2003 R2, Standard Edition with Service Pack 2.

    I tried our other msdn discs, but they no longer work.

    so I'm stuck.

    All I need is to put in place the RAID-1 and windows server 2003.

    Anyone who is willing to light on that?


  • Partition Windows 10 2013 MacPro (BootCamp) Installation problem

    Greetings,

    I had some difficulties to install Windows via Boot Camp 10. As far as my system goes, please see the attached screenshot of my MacPro system. My SSD hard drive is.

    The dam is located after the "Format", when I click on the next button, I got this error:

    "We could not create a new partition or locate an existing one. For more information, see the Setup log file"(see the image attached).

    I've been Googling since yesterday and trying to apply solutions out there my problems without success (a part of it because I am not a computer savvy and do not know if their problems are the same as mine), but here are some things I've tried:

    01 unplug the stroke, including the external enclosure which houses 4 external drive and my computer screen.

    02 reset the SMC

    03 reset NVRAM

    Any help and guidance on where should I go to solve this mystery is greatly appreciated!

    Oh just Add a more, only a few things related to my MacPro are:

    -USB Flash drive (I install via USB (Windows Single iso Language has been downloaded from Microsoft))

    -Apple USB keyboard

    -Logitech mouse receiver.

    At one point only I used a keyboard, always without success.

    Thank you

  • Color LaserJet 200 M251 and Windows Server 2012 R2 installation problem

    I have a problem installing with the M251 printer on a clean install of windows server 2012 R2.

    I want to connect the printer via USB only.

    I tried installing the driver package and with the complete package. I turned on the printer of the smart install feature.

    But every time the same problem occurs.

    The printer driver is correctly installed, but the printer HP (LEDM) driver failed.

    The debugging information:

    Installed the device.

    hpbuio25l.inf _amd64_85c42d890fc & dc10\hpbuio35l .inf for the device USB \VID_03F0&PID_132A&MI_01\6&3AB71850&6&0001 instance ended up with the following status: 0xE0000219

    If I want to reinstall the driver again, I received the message:

    Setup error

    An entry in the Inf file is missing, the file may be Windows 95...

    Could you please help me, how to solve this problem?

    I need to activate the visual experience of Windows Server 2013, then the USB works

  • Blue screen of death (0x0000003b) on Windows server 2012.

    Hello! I found a problem with windows server 2012. This server runs on a VMware virtual machine, and once of the month I get this error, but the drivers can cause this error all the time different.

    For the first time this problem caused the driver AgileVpn.sys, second and third time win32k.sys. And the last pilot time named videoprt.sys caused this problem.

    I spent a lot of time to search for a patch. But I have not found a necessary updates in Windows server 2012 r1 for this problem.

    Maybe give me a little help or tell me what I need to do?

    This issue is beyond the scope of this site (for consumers) and to be sure, you get the best (and fastest) reply, we have to ask either on Technet (for IT Pro) or MSDN (for developers)
    *
  • Cisco ISE with GANYMEDE + and RADIUS both?

    Hello

    I'm wired opening of authentication on a network using Cisco ISE. I studied the conditions for this. I know that I need to enable the RADIUS on the Cisco switches on the network. The switches in the network are already programmed to GANYMEDE +. Anyone know if they can both operate on the same network at the same time?

    Bob

    I suppose that Ganymede is configured (with ACS 4.x or 5.x) for the peripheral administration via telnet/ssh, and now you need the RADIUS (radius) to authenticate 802. 1 x. Yes they can both work on the same network at the same time.

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • Adobe Reader DC contains errors and crashes with Windows Server R2 2012

    We have recently installed Adobe Reader DC Adobe version on our servers Windows Server R2 2012 and have problems since its launch. Few of the questions that we have seen are as follows:

    1. This version is a little awkward and crashes.
    2. A lot of pop up boxes that appears whenever I open a document.
    3. Whenever I open a document it is a box pop up welcome
    4. It is a little slow to respond between clicks
    5. If I click on options like file. The application hangs and then crashes. (see crash message attachment)

    Any help to solve this problem would be useful.

    Thank you


    Adobe error.PNG

    Questions for users confronted with this question:

    1. do you have the preview pane enabled in file Explorer? If so, you can temporarily disable it to see if the problem goes away? On Windows 8, in Explorer, go to the view tab, and if you press the button "Preview Pane", UN-press it. On Windows 7, upwards to the right (to the left of the help icon) there is a button "show preview pane." UN-press it.

    2. ensure that the following directories exist on your machine. If this isn't the case, please create them:

    C:\Users\USERNAME\AppData\Local\Adobe\Acrobat\DC\ToolsSearchCacheAcro

    C:\Users\USERNAME\AppData\Local\Adobe\Acrobat\DC\ToolsSearchCacheRdr

    Replace USERNAME with your username.

    Is - do this 1 or 2 to solve this problem?

  • FT-record/replay feature is not supported by this virtual machine Windows Server 2012

    Recently I came across a bug when I created a virtual machine with the latest versions of 5.1.0 - ESXi 838463, Client ver 5.1.0 - 860230, vCenter ver 5.1.0 - 880146.  If you create a virtual machine on a Server Windows 2012 farm for some reason any recording/playback is disabled and you cannot implement fault tolerance mode.  I found a good solution.  You delete the virtual machine to inventory, and then re-create the virtual machine as a Windows 2008 R2 server and use the virtual machine that you deleted from the original disc of the inventory rather than create a new one.  Then turn on FT.  Then, go into the settings and change the operating system to Windows Server 2012.   Fixed a problem.  If all goes well they will fix this soon.

    Jimmy S.

    Default adapter for windows 2012 is E1000E, which is not supported for RecordReplay FT.  If this is the case can you please try with another network card and see if it helps.

    If this is not the case, can you please upload vm-support bundle or file a support ticket.

    Thank you

    Pradeep

  • Install KB3024777 to fix a problem with KB3004394 on Windows 7 and Windows Server 2008 R2 now not authentic

    Separated from this thread.

    Joachim

    When first pose the problem? Was it before or after the December updates?

    KB3004394 and KB3024777 appear in view update history? Or do they appear in installed updates?

    Gerry, thanks for your post. I have the same problem as Joachim started this thread. I am running Windows 7 sp1. I have a Dell computer and it's certainly a legitimate copy of Windows (confirmed computer 'properties' and it is enabled).

    By your post, I saw just to update and the KB3004394 (installed on 12/10/2014) and KB3024777 (installed on 12/12/2014) show as comfortable. I usually leave the Windows download updates automatically and I install them to stop. I watched the second update and according to Microsoft.com:

    Install KB3024777 to fix a problem with KB3004394 on Windows 7 and Windows Server 2008 R2

    The KB 3004394 update which was dated December 10, 2014 can cause additional problems on computers that run Windows 7 Service Pack 1 (SP1) and Windows Server 2008 R2 SP1. This includes the inability to install future updates. This new update is available to remove KB 3004394 from your computer.

    My problem is, as of today 14/12/2014, I still get the pop up "this computer is running not windows genuine', even with KB3024777 installed.

    Any thoughts?

    Thank you

    Bob C

    Right-click on CMD

    Click on run as administrator

    At the command prompt, type the following commands:

    slmgr.vbs - ipk xxxx-xxxx-xxxx-xxxx (to replace the specified in the current product key)

    xxxx-xxxx-xxxx-xxxx - represents your product key

    Press enter on your keyboard

    Then type: slmgr.vbs - ato (this will force the activation)

    Leave the command prompt

    Restart your computer

  • Cisco ISE 1.1.1 with Windows posturing

    Hello

    We tired for configured windows posturing here's the scenario

    We saw five ise boxes 3315 with version 1.1.1 off them 2 is admin, 2 is PS and 1 MNT

    and we have local Symantec and WSUS Server.

    We make posturing for Windows where I have a few questions

    (1) is there an integration here of the local WSUS server with Cisco ISE where Cisco ISE can automatically take all the mandatory WSUS update according to the crititcality of the WSUS server.

    (2) what is advised to set up the strategy of the Posture of the posture of windows in Cisco ISE and if manually configure windows political posture using specific KB and if there is an update available on Microsoft will we be able to configure the policy for the new update.

    (3) we have configured authentication dot1x in cisco ise and asked as well as on switch port where once the user must be connected to dot1x port of the switch it invites username and password dot1x and therefore, authorization policy, it gives vlan appropriate dynamics.

    But what are the ways where we can restrict the machine which is rather than the assets of the company and even if the user's user name and password in short any employee aware how we can restrict the user making the machine rather than the assets of the company?

    (4) can configure US policy posture for antivirus which will keep us in normal mode and at the same time, we can put posturing for windows which monioring mode which only monitor policy posture and reflected in the monitoring, log in which does not restrict the network for windows posturing

    That will be great if any one can please help me to get the issues

    Thank you

    Pranav

    What follows is under the POLICY-OF ELEMENTS of STRATEGY-POSTURE-> REQUIREMENTS > >

    What follows is located under

    POLICY OF-> ELEMENTS OF STRATEGY-> POSTURE->

    REPAIR-> WINDOWS SERVER UPDATE SERVICES REMEDIATION ACTIONS

    What follows is part POLICY-> POSTURE

    These settings work ALMOST flawlessly for me by forcing her we approved on our WSUS server for our group of workstations updated (all of our laptops are members of the) which meet the criteria of severity EXPRESS (critical and Important). Now, what I've discovered in the last few days is that... MS seems a bit random in their identification of what severity level they assign to their updates. For example... I think that a service pack of the operating system would be considered IMPORTANT if not CRITICAL... however... Look at this from the identification of the server WSUS from Windows 7 Service Pack 1:

    Thus, those who updates you deleted, I'd go throgh your WSUS server to identify how they are identified by gravity, then according to your needs set the parameters of the ISE accordingly to ensure that you get updates you plan.

    Hope this helps everyone out there who has similar problems.

    Thank you

    Dirk

  • Problem of DNS in Windows server 2012

    Hi guys,.

    I'm a newbie here and I hope to get help with my question.

    I have a server DNS (192.168.1.55/24). Everything is already configured, the IP address and host names are already mapped and is already working. Now the problem is... I example. Metro.com, when I'm in the same segment (192.168.1.x 24) I am able to access example.metro.com using only his "example" hostame in run. (windows + R, then \\example). When I ping, he also responds with the correct address w/c IP is 192.168.1.11 being. Now, I have another VLAN in my network is 10.1.1.0/24 and 10.1.2.0/24, these VLANS are able to see the 192.168.1.0/24 because I have a cisco layer 3 switch. When I use the DNS 192.168.1.55 segment both 10.1.1.x and 10.1.2.x, so I am able to still ping example.metro.com and able to access. But what happens is, I'm not able to access using only the host name-example term. Is there something I need to configure on the DNS server to have it working? I might have exhausted all procedures, but still can't make it work, and I'd really appreciate that someone can give me a help and advice.

    Once again...

    1. I'm on the 10.1.1.0/24 network

    2. I use 192.168.1.55 as DNS (which I am able to ping, btw)

    3. it can translate example.metro.com to 192.168.1.11 when I ping.

    4. IM NOT in MEASUREMENT of ACCESS IT USING ONLY \\EXAMPLE term I can when I'm in the same segment as the server DNS 192.168.1.0/24.

    Thank you!!

    -BJL

    Try asking in the Windows Server forum:
    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

Maybe you are looking for

  • Get the chord progressions

    I used music notes app to listen to a song and tell me the agreements in it. Is it possible to print the progress?

  • What firefox will be able to support html embed files in the tags again?

    A previous question answered here who said that firefox does not work with the html files to embed tags. This is a problem that is currently under development, or only Firefox supports just ain't it?

  • HP 2000-2d28TU

    Why the HP website does not show my PC (HP 2000-2d28TU) I just bought 2 days back.

  • What RAM to a Pavilion DV7 series laptop

    I am upgrading a laptop Pavilion Dv7 series and information of conflict on the RAM it will run. Main RAM sites say the DV7 series will work work DDR3 but they also say that the DV7T-1000CTO uses DDR2. More research suggests that the DDR3 switch was m

  • HP ENVY tilted 23-k030 TouchSmart chart question

    I have a new HP ENVY tilted 23-k030 TouchSmart all-in-One Desktop and it has two cards graphics is the Nvidia and the other is an Intel processor.  I was wondering if I play a game do the computer automatically switch to Nvidia because it is a powerf