Unable to join Edge SWG(ProxySG) or ASG to domain with error "NERR_DCNotFound"
search cancel

Unable to join Edge SWG(ProxySG) or ASG to domain with error "NERR_DCNotFound"


Article ID: 170339


Updated On:


Advanced Secure Gateway Software - ASG ProxySG Software - SGOS


The Edge SWG(ProxySG) or Advanced Secure Gateway(ASG) is unable to join the Active Directory(AD) domain after upgrading to SGOS versions,, or higher.

"NERR_DCNotFound" error would popup upon joining domain.


Current versions of Edge SWG or ASG will contact Domain Controllers (DCs) in the local AD Site where Edge SWG belongs to, if AD site is configured. This feature is called "site awareness". Site awareness was added to avoid any network related issues between sites when contacting to remote DCs which would result in performance problems. If the site has only a Read-Only Domain Controller, the Edge SWG would contact the Read-Only DC as it also belongs to the same local AD site as the Edge SWG.  Joining the Edge SWG or ASG to the domain would then fail since Read-Write DCs are required, but not available locally.

Earlier SGOS versions would worked because the Edge SWG or ASG would contact remote DCs in addition to local DCs during joining process.


In SGOS versions,, and, and later introduce a parameter to toggle site awareness behavior now present in previous SGOS versions in order to allow the Edge SWG or ASG to join remote domains if required.

From the CLI:

conf t
security windows-domains
site-aware disable

By default site awareness is enabled that is, the Edge SWG or ASG would query only local DCs from a specific Active Directory Site. However once site awareness is disabled, the Edge SWG or ASG would revert to previous behavior and query all sites for DCs during joining process which would alleviate this issue.

Another workaround would be to introduce a Read-Write DC to the local AD site.