<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE redirect to the wrong domain name in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317687#M148990</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kind of weird logic is here ? What does redirect have to do with certificate? &lt;/P&gt;&lt;P&gt;Moreover, when I try to generate the new certificate I can't use it because the old ones are associated with a protocol HTTPS and EAP and can't disable them because these check boxes are greyed out&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 05 Oct 2013 01:34:54 GMT</pubDate>
    <dc:creator>zheka_pefti</dc:creator>
    <dc:date>2013-10-05T01:34:54Z</dc:date>
    <item>
      <title>ISE redirect to the wrong domain name</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317681#M148761</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;We changed a domain name of the ISE appliance and it started giving us grief. It was configured to redirect wireless users to the web registration and authentication portal. We properly added all required A records in DNS server and looked everywhere but didn't find anything that could give any clue.&lt;/P&gt;&lt;P&gt;Perhaps the old FQDN get stuck somewhere in the database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea? Please help !!!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317681#M148761</guid>
      <dc:creator>zheka_pefti</dc:creator>
      <dc:date>2019-03-11T03:57:36Z</dc:date>
    </item>
    <item>
      <title>ISE redirect to the wrong domain name</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317682#M148777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the configuration of Active Directory in the Admin portal and the DNS&lt;SUP&gt; &lt;/SUP&gt;configuration in the Cisco ISE CLI. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 09:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317682#M148777</guid>
      <dc:creator>Muhammad Munir</dc:creator>
      <dc:date>2013-10-04T09:44:12Z</dc:date>
    </item>
    <item>
      <title>ISE redirect to the wrong domain name</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317683#M148806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, Muhammad,&lt;/P&gt;&lt;P&gt;ISE CLI was already taken care of but AD portal settings was a good pointer. I'll have it changed and will try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eugene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 16:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317683#M148806</guid>
      <dc:creator>zheka_pefti</dc:creator>
      <dc:date>2013-10-04T16:04:32Z</dc:date>
    </item>
    <item>
      <title>ISE redirect to the wrong domain name</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317684#M148839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Case Solution:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Connecting to the Active Directory Domain &lt;/P&gt;&lt;P&gt;To reconnect with Active Directory domain, complete the following steps: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Choose Administration &amp;gt; Identity Management &amp;gt; External Identity Sources. &lt;/P&gt;&lt;P&gt;Step 2&amp;nbsp;&amp;nbsp;&amp;nbsp; From the External Identity Sources navigation pane on the left, click Active Directory. &lt;/P&gt;&lt;P&gt;Step 3&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter the domain name in the Domain Name text box. &lt;/P&gt;&lt;P&gt;Step 4&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter a friendly name in the Identity Store Name text box for your Active Directory identity source (by default, this value will be AD1). &lt;/P&gt;&lt;P&gt;Step 5&amp;nbsp;&amp;nbsp;&amp;nbsp; Clicks Save Configuration. &lt;/P&gt;&lt;P&gt;Step 6&amp;nbsp;&amp;nbsp;&amp;nbsp; To verify if your Cisco ISE node can be connected to the Active Directory domain, click Test Connection. A dialog box appears and prompts you to enter the Active Directory username and password. &lt;/P&gt;&lt;P&gt;Step 7&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter the Active Directory username and password and click OK. &lt;/P&gt;&lt;P&gt;A dialog box appears with the status of the test connection operation. &lt;/P&gt;&lt;P&gt;Step 8&amp;nbsp;&amp;nbsp;&amp;nbsp; Click OK. &lt;/P&gt;&lt;P&gt;Step 9&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Join to join the Cisco ISE node to the Active Directory domain. &lt;/P&gt;&lt;P&gt;The Join Domain dialog box appears. &lt;/P&gt;&lt;P&gt;Step 10&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter your Active Directory username and password, and click OK. &lt;/P&gt;&lt;P&gt;Step 11&amp;nbsp;&amp;nbsp;&amp;nbsp; Check the Enable Password Change check box to allow the user to change their password. &lt;/P&gt;&lt;P&gt;Step 12&amp;nbsp;&amp;nbsp;&amp;nbsp; Check the Enable Machine Authentication check box to allow machine authentication. &lt;/P&gt;&lt;P&gt;Step 13&amp;nbsp;&amp;nbsp;&amp;nbsp; Check the Enable Machine Access Restrictions (MARs) check box to ensure that the machine authentication results are tied to the user authentication and authorization results. If you check this check box, you must enter the Aging Time in hours. &lt;/P&gt;&lt;P&gt;Step 14&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter the Aging Time in hours if you have enabled MARs. &lt;/P&gt;&lt;P&gt;This value specifies the expiration time for machine authentication. If the time expires, the user authentication fails. For example, if you have enabled MARs and enter a value of 2 hours, the user authentication fails if the user tries to authenticate after 2 hours. &lt;/P&gt;&lt;P&gt;Step 15&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Save Configuration. &lt;/P&gt;&lt;P&gt;Step 16. Create Certificate Authentication Profile&lt;/P&gt;&lt;P&gt;Step 17: Import CA Certificates into ISE Certificate Trust Store&lt;/P&gt;&lt;P&gt;Step 18: Configure CA Certificates for Revocation Status Check &lt;/P&gt;&lt;P&gt;Step 19: Enable Client Certificate-Based Authentication &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check below link for certificates configurations&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_admin.html#wp1122804"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_admin.html#wp1122804&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 17:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317684#M148839</guid>
      <dc:creator>aqjaved</dc:creator>
      <dc:date>2013-10-04T17:44:41Z</dc:date>
    </item>
    <item>
      <title>ISE redirect to the wrong domain name</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317685#M148879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you please check if your device is pointing towards the right server and that is IP address of ISE? so that right domain can be pointed to..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 19:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317685#M148879</guid>
      <dc:creator>Abha Jha</dc:creator>
      <dc:date>2013-10-04T19:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE redirect to the wrong domain name</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317686#M148948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zheka,&lt;/P&gt;&lt;P&gt;I guess we saw the similar query in this forum before as well.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2218780" rel="nofollow"&gt;https://supportforums.cisco.com/thread/2218780&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's because certificate presented to the client is still OLD. You need to generate a new cert and install it on ISE and make sure DNS is updated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 22:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317686#M148948</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-04T22:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE redirect to the wrong domain name</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317687#M148990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kind of weird logic is here ? What does redirect have to do with certificate? &lt;/P&gt;&lt;P&gt;Moreover, when I try to generate the new certificate I can't use it because the old ones are associated with a protocol HTTPS and EAP and can't disable them because these check boxes are greyed out&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Oct 2013 01:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirect-to-the-wrong-domain-name/m-p/2317687#M148990</guid>
      <dc:creator>zheka_pefti</dc:creator>
      <dc:date>2013-10-05T01:34:54Z</dc:date>
    </item>
  </channel>
</rss>

