300-715 · Question #183
Users in an organization report issues about having to remember multiple usernames and passwords. The network administrator wants the existing Cisco ISE deployment to utilize an external identity…
The correct answer is C. Establish access to one Global Catalog server. D. Provide domain administrator access to Active Directory. Verify that you have the privileges of a Super Admin or System Admin in ISE. Use the Network Time Protocol (NTP) server settings to synchronize the time between the Cisco server and Active Directory. The maximum allowed time difference between ISE and AD is 5 The configured DNS…
Question
Users in an organization report issues about having to remember multiple usernames and passwords. The network administrator wants the existing Cisco ISE deployment to utilize an external identity source to alleviate this issue. Which two requirements must be met to implement this change? (Choose two.)
Options
- AEnable IPC access over port 80.
- BEnsure that the NAT address is properly configured
- CEstablish access to one Global Catalog server.
- DProvide domain administrator access to Active Directory.
- EConfigure a secure LDAP connection.
How the community answered
(32 responses)- A3% (1)
- B9% (3)
- C84% (27)
- E3% (1)
Explanation
Verify that you have the privileges of a Super Admin or System Admin in ISE. Use the Network Time Protocol (NTP) server settings to synchronize the time between the Cisco server and Active Directory. The maximum allowed time difference between ISE and AD is 5 The configured DNS on ISE must be able to answer SRV queries for DCs, GCs, and KDCs with or without additional Site information. Ensure that all the DNS servers can answer forward and reverse DNS queries for any possible Active Directory DNS domain. AD must have at least one global catalog server operational and accessible by Cisco, in the domain to which you join Cisco. service-engine-ise-and-active.html
Topics
Community Discussion
No community discussion yet for this question.