Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass joining AD timeout problem

This thread has been viewed 7 times
  • 1.  ClearPass joining AD timeout problem

    Posted Jan 07, 2017 06:36 AM

    Hi all,

     

    Hope someone will be able to point me in right direction. We are trying to join customer's ClearPass server to an ADs. Joining it to the first one went perfectly OK (in scenario where both boxes have interfaces on the same subnet). When trying to join second AD (in scenario where there is a firewall between them, **but not saying that this is firewall issue, just explaining setup!**) we run into problems. ClearPass attempts to join new AD and fails showing this message:

     

    "Adding host to AD domain...
    INFO - Fetched REALM 'XXXXX.COM' from domain FQDN
    'ltcs.XXXXX.com'
    INFO - Fetched the NETBIOS name 'XXXXX'
    INFO - Creating domain directories for 'XXXXX'
    Enter CPPMService's password:
    cli_rpc_pipe_open_noauth: rpc_pipe_bind for pipe
    etlogon failed
    with error NT_STATUS_IO_TIMEOUT
    libnet_join_ok: failed to get schannel session key from server
    ltcs.XXXXX.com for domain XXXXX. Error was NT_STATUS_IO_TIMEOUT
    Failed to join domain: failed to verify domain membership after
    joining: NT_STATUS_IO_TIMEOUT
    INFO - Restoring smb configuration
    INFO - Restoring krb5 configuration file
    INFO - Deleting domain directories for 'XXXXX'
    ERROR - CPPM004 failed to join the domain XXXXX.COM with
    domain controller as ltcs.XXXXX.com
    Join domain failed"

     

    Packet capture on firewall shows traffic between nodes passing through (at least the one that is allowed by initial request: kerberos, Active Directory, ms-ds-smb, mspc, netbios-s).

     

    Any thoughts are more than welcome. Thanks, 

     

    NesaM



  • 2.  RE: ClearPass joining AD timeout problem

    EMPLOYEE
    Posted Jan 07, 2017 09:48 AM

    Make sure that the time on the ClearPass box and the domain box are the same.



  • 3.  RE: ClearPass joining AD timeout problem

    Posted Jan 07, 2017 11:42 AM

    Thanks Colin,

     

    Will check and confirm on Monday.

     

    NesaM



  • 4.  RE: ClearPass joining AD timeout problem

    Posted Jan 09, 2017 05:46 AM

    Hi Colin,

     

    TIme checked on both boxes, and it is in sync. Any thoughts where to look next? Thanks.

     

     

    Regards,

    NesaM



  • 5.  RE: ClearPass joining AD timeout problem

    Posted Jan 09, 2017 06:50 AM
    Can you do an NSLOOKUP to that domain controller from ClearPass CLI
    network nslookup

    Get Outlook for iOS


  • 6.  RE: ClearPass joining AD timeout problem

    Posted Jan 09, 2017 07:27 AM

    Hi Victor,

     

    Checked and it is coming back with the server IP. I asked customer to double-confirm if all the right ports are opened on fw, and will try to get hold of Event Log from AD controller.

     

    NOTE: Case opened now with TAC, will keep you updated on what it was (though it must be something silly)

     

    Thanks,

    NesaM



  • 7.  RE: ClearPass joining AD timeout problem
    Best Answer

    Posted Jan 10, 2017 01:05 PM

    Right, problem was after all related to Palo Alto. Original request was to allow these applications:

    kerberos, Active Directory,ms-ds-smb, msrpc, netbios-ss, ldap

    When observing traffic going through firewall no traffic was dropped. However, someone from that team noticed that MS logon protocol was not added by default (though this was apparently expected when you allow Active Directory on PA).

     

    After adding MS logon all clicked nicely, and we now have happy customer. Thanks everyone who contributed with suggestions.

     

     

    NesaM



  • 8.  RE: ClearPass joining AD timeout problem

    Posted Jan 09, 2017 06:50 AM
    Can you do an NSLOOKUP to that domain controller from ClearPass CLI
    network nslookup

    Get Outlook for iOS