<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069221#M24009</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;basically I am not changing the hostname(ise01,ise02) or domain name (test.local).&lt;BR /&gt;The purpose is , to avoid the certificate error when guest portal accessing . &lt;BR /&gt;So for guest portal I will use certificate from external CA ,and for the EAP from the our local internal ca&lt;BR /&gt;Could you provide detailes&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2017 06:59:14 GMT</pubDate>
    <dc:creator>muhsi_2015</dc:creator>
    <dc:date>2017-02-14T06:59:14Z</dc:date>
    <item>
      <title>Changing domain name  in the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069219#M24006</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I have two ise primary and secondary .Both are already joined to test.local . with self signed certificate &lt;BR /&gt;Now want to use external CA&lt;/P&gt;
&lt;P&gt;In my DNS i have zone for test.com&lt;/P&gt;
&lt;P&gt;So here is the step I am going to use&lt;/P&gt;
&lt;P&gt;Create an A record for ise01.test.com ,ise02.test.com in the DNS forward zone&lt;/P&gt;
&lt;P&gt;Go to deployment deregister the second ise .&lt;/P&gt;
&lt;P&gt;goto ise console : type ip domain-name test.com&lt;/P&gt;
&lt;P&gt;Do it in both ise&lt;/P&gt;
&lt;P&gt;generate csr&lt;/P&gt;
&lt;P&gt;Please tell me the above steps are valid&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069219#M24006</guid>
      <dc:creator>muhsi_2015</dc:creator>
      <dc:date>2019-03-11T07:27:33Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069220#M24008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Recommendation is to separate the nodes and change the hostname accordingly.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Following things need to be take care of :&lt;/P&gt;
&lt;P&gt;1) Please note that we would need to re-generate the internal CA certificate chain after the hostname change for the ISE internal CA to continue issuing certificates.&lt;/P&gt;
&lt;P&gt;2) Disjoin and rejoin the ISE -AD for new connection.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Changing hostname on ISE:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_011.html#ID686&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS: rate if it helps!!!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 00:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069220#M24008</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-14T00:03:50Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069221#M24009</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;basically I am not changing the hostname(ise01,ise02) or domain name (test.local).&lt;BR /&gt;The purpose is , to avoid the certificate error when guest portal accessing . &lt;BR /&gt;So for guest portal I will use certificate from external CA ,and for the EAP from the our local internal ca&lt;BR /&gt;Could you provide detailes&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 06:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069221#M24009</guid>
      <dc:creator>muhsi_2015</dc:creator>
      <dc:date>2017-02-14T06:59:14Z</dc:date>
    </item>
    <item>
      <title>During Portal communication,</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069222#M24011</link>
      <description>&lt;P&gt;During Portal communication, PSN sends the portal certificate. In order to avoid certificate warning, you need to trust the CA with intermediate by putting it in the trusted list of client.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let me know if you need anything specific to that.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS : rate if it helps!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 18:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069222#M24011</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-14T18:36:51Z</dc:date>
    </item>
    <item>
      <title>If you are only changing the</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069223#M24013</link>
      <description>&lt;P&gt;If you are only changing the domain in CLI then you don't need to remove the AD integration inside the ISE application. With that said, the steps that you have listed are correct. A couple of things to note here:&lt;/P&gt;
&lt;P&gt;- The nodes will restart when you deregister them from the cluster&lt;/P&gt;
&lt;P&gt;- The nodes will restart when you register them back in&lt;/P&gt;
&lt;P&gt;- The nodes will restart when you change the domain name&lt;/P&gt;
&lt;P&gt;- If you are getting a wildcard certificate, you won't be able to use it for EAP based authentications&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 18:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069223#M24013</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2017-02-14T18:39:30Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069224#M24014</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you all ,I have elaborated the steps a bit . Please need your feedback &lt;BR /&gt;The purpose is changing the domain name (test.local ) to test.com while ise remain joined in test.local like a member server .&lt;BR /&gt;So the guest users won't get certificate warning .&lt;/P&gt;
&lt;P&gt;Presently installed self signed certificate &lt;BR /&gt;Domain Name :test.local &lt;BR /&gt;ise joined in test.local&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;step 1 :&lt;/STRONG&gt; &lt;BR /&gt;creating A records and CNAME records in the forward lookup zone test.com&lt;/P&gt;
&lt;P&gt;create A records in ise01 192.168.10.100(ise01.test.com)&lt;BR /&gt;verify ise01.test.com will resolve to 192.168.10.100&lt;/P&gt;
&lt;P&gt;create A records in ise01 192.168.10.101 (ise02.test.com) &lt;BR /&gt;verify ise01.test.com will resolve to 192.168.10.101&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;SAN -DNS CNAME&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;for SAN create a DNS CNAME record ise.test.com 192.168.10.100&lt;BR /&gt;verify ise.test.com will resolve to 192.168.10.100&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;step 2&lt;/STRONG&gt; :&lt;/P&gt;
&lt;P&gt;Removing the node from the cluster (ise02 ) &lt;BR /&gt;-------------------------------------&lt;BR /&gt;Deregister ise02 from the cluster ,The node will restart&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;step 3 :&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Changing Domain name using cli &lt;BR /&gt;------------------------------------&lt;/P&gt;
&lt;P&gt;once back go to cli type : ip domain-name test.com , the node will restart&lt;/P&gt;
&lt;P&gt;Generate csr ise02 . Here I will choose Admin Type ,So I can use for EAP and portal ( guest and admin portal )&lt;/P&gt;
&lt;P&gt;go to ISE01 &lt;BR /&gt;cli type : ip domain-name test.com , the node will restart&lt;/P&gt;
&lt;P&gt;Generate csr ise02 . Here I will choose Admin Type ,So I can use for EAP and portal ( guest and admin portal )&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;step 4 :&lt;/STRONG&gt; &lt;BR /&gt;Importing certificate to ise and Bind&lt;/P&gt;
&lt;P&gt;ise01 &lt;BR /&gt;go back into the “Certificate Signing Requests” page. Select the CSR saved and click “Bind Certificate”.&lt;/P&gt;
&lt;P&gt;ise02 &lt;BR /&gt;go back into the “Certificate Signing Requests” page. Select the CSR saved and click “Bind Certificate”.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://i.imgur.com/DGGW0r4.png" alt="" width="624" height="415" /&gt;&lt;/P&gt;
&lt;P&gt;We don't import root CA since ise already has the external CA certificate .&lt;/P&gt;
&lt;P&gt;step5 :&lt;/P&gt;
&lt;P&gt;Reregister to the cluster .&lt;BR /&gt;When reregistering what should be the name ? ise02.test.local or ise02.test.com &lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Finally am i missing something&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 08:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069224#M24014</guid>
      <dc:creator>muhsi_2015</dc:creator>
      <dc:date>2017-02-15T08:44:41Z</dc:date>
    </item>
    <item>
      <title>I think you are good !!! It</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069225#M24015</link>
      <description>&lt;P&gt;I think you are good !!! It should work for you as per steps mentioned by you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;rate if it helps!!!!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 02:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069225#M24015</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-17T02:53:19Z</dc:date>
    </item>
    <item>
      <title>Dear gagan ,</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069226#M24016</link>
      <description>&lt;P&gt;Dear gagan ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am stuck at this point &amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;step 3 :&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Changing Domain name using cli &lt;BR /&gt;------------------------------------&lt;/P&gt;
&lt;P&gt;once back go to cli type : ip domain-name test.com , the node will restart&lt;/P&gt;
&lt;P&gt;Generate csr ise02 . Here I will choose Admin Type ,So I can use for EAP and portal ( guest and admin portal )&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I tried to create csr here , but there is no option for csr&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 07:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069226#M24016</guid>
      <dc:creator>muhsi_2015</dc:creator>
      <dc:date>2017-02-17T07:46:10Z</dc:date>
    </item>
    <item>
      <title>You can generate certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069227#M24017</link>
      <description>&lt;P&gt;You can generate certificate for Multi-use. Using Multi-use, you can assign&amp;nbsp;&lt;SPAN&gt;a single certificate for multiple services.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Certificate Signing REquests&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Once you generate the CSTR, present it to external CA and get server certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Come at same page and bind it by selecting the CSR.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Gagan&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PS: rate if it helps!!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2017 19:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/changing-domain-name-in-the-ise/m-p/3069227#M24017</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-18T19:52:17Z</dc:date>
    </item>
  </channel>
</rss>

