Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Error Joining Clearpass to AD

This thread has been viewed 6 times
  • 1.  Error Joining Clearpass to AD

    Posted Nov 29, 2017 08:04 PM

    Hi there.

     

    I'm getting an error while I try to join Clearpass to AD.

     

    Scenario:

    Clearpass hostname: cppm_enp

    IP address: 10.5.0.4

    Active directory IP: 10.5.0.10

    Domain Controller name (FQDN): PocociAD.seguridadpublica.go.cr as you can see on the following capture:Join AD 3.png

    If I go to the command line an put nslookup I get that: Join AD 4.png

    Also I have created a new entry on the DNS service for the clearpass server.

    Both servers (Clearpass and AD) ping each others.

     

    Then, I go to Administration-> Server Manager--> Server configuration and then to Join AD domain option and fullfil the fields as you can see on the following capture: AD Join.PNG

    As you can see the NetBios field obtain the value automatically after I write the complete Domain Controller name, then I write the password and Click Save and the process starts. And then it shows the next error: AD Join 2.PNGJust to clarify the time on both servers are synchronized.

     

    Thank you in advance!



  • 2.  RE: Error Joining Clearpass to AD

    Posted Nov 29, 2017 08:35 PM
    Have you tried doing an NSLOOKup from ClearPass CLI ?

    Get Outlook for iOS


  • 3.  RE: Error Joining Clearpass to AD

    Posted Nov 30, 2017 10:39 AM

    Hi Victor, yes, I have tried, look: Join AD 5.PNG



  • 4.  RE: Error Joining Clearpass to AD

    EMPLOYEE
    Posted Nov 29, 2017 08:35 PM

    Is there a firewall between ClearPass and the domain controllers? Are the required ports allowed between them?



  • 5.  RE: Error Joining Clearpass to AD

    Posted Nov 30, 2017 10:44 AM

    Hi Tim, I have created a new rule on Windows Firewall allowing port TCP/UDP 389 and nothing happened.



  • 6.  RE: Error Joining Clearpass to AD
    Best Answer



  • 7.  RE: Error Joining Clearpass to AD

    Posted Nov 30, 2017 11:16 AM

    Thank you Tim, I think it was necessary to disable and enable again the firewall to "apply changes". Now its joined.

     

    Thanks Victor too.