<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cisco ise in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874774#M36821</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am using an evaluation of cisco ise 2.0 .&amp;nbsp; I have&amp;nbsp; two ssid .One using &amp;nbsp; EAP-PEAP ,&amp;nbsp; another using&amp;nbsp;&amp;nbsp; EAP-TLS authentication and i have local microft CA. So how can&amp;nbsp; i do the certificate process&amp;nbsp; in ISE&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:38:45 GMT</pubDate>
    <dc:creator>wyfy-2015</dc:creator>
    <dc:date>2019-03-11T06:38:45Z</dc:date>
    <item>
      <title>cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874774#M36821</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am using an evaluation of cisco ise 2.0 .&amp;nbsp; I have&amp;nbsp; two ssid .One using &amp;nbsp; EAP-PEAP ,&amp;nbsp; another using&amp;nbsp;&amp;nbsp; EAP-TLS authentication and i have local microft CA. So how can&amp;nbsp; i do the certificate process&amp;nbsp; in ISE&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:38:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874774#M36821</guid>
      <dc:creator>wyfy-2015</dc:creator>
      <dc:date>2019-03-11T06:38:45Z</dc:date>
    </item>
    <item>
      <title>I would recommend starting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874775#M36822</link>
      <description>&lt;P&gt;I would recommend starting with these two things:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Lab Minutes video on EAP-TLS:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.labminutes.com/sec0186_ise_13_wireless_dot1x_eap-tls_peap_1"&gt;http://www.labminutes.com/sec0186_ise_13_wireless_dot1x_eap-tls_peap_1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;EAP-TLS Deployment Guide (Cisco):&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a008009256b.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a008009256b.shtml&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;ISE Design Guides:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-implementation-design-guides-list.html"&gt;http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-implementation-design-guides-list.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 23:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874775#M36822</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-05T23:28:03Z</dc:date>
    </item>
    <item>
      <title>Nobody expects the Spanish</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874776#M36823</link>
      <description>&lt;P&gt;Nobody expects the Spanish Inquisition!&lt;/P&gt;
&lt;P&gt;https://www.youtube.com/watch?v=7WJXHY2OXGE&lt;/P&gt;
&lt;P&gt;(Mentioned two things then listed three. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 01:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874776#M36823</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-04-06T01:50:55Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874777#M36824</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you Neno and Marvin . Here is another scenario. My inside &amp;nbsp;domain &amp;nbsp;is test.local .So&amp;nbsp;the fqdn is like ise01.test.local and ise02.test.local . For the guest portal , if i want to use an external CA .( I' ll create another &amp;nbsp;A record in zone test.com,ise01.test.com) .&lt;/P&gt;
&lt;P&gt;So how &amp;nbsp;can i use &amp;nbsp;ise01.test.com &amp;nbsp;for guest portal instead of &amp;nbsp;ise01.test.local&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And in this do i need to import both &amp;nbsp;certificate &amp;nbsp;(local and external)?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 03:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874777#M36824</guid>
      <dc:creator>wyfy-2015</dc:creator>
      <dc:date>2016-04-06T03:43:41Z</dc:date>
    </item>
    <item>
      <title>Ha ha, good catch Marvin! :)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874778#M36825</link>
      <description>&lt;P&gt;Ha ha, good catch Marvin! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 16:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874778#M36825</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-06T16:23:43Z</dc:date>
    </item>
    <item>
      <title>I have faced this issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874779#M36826</link>
      <description>&lt;P&gt;I have faced this issue before and it can be done. The important thing to remember is that the domain that ISE is joined to (For groups and users querying) can be different than the domain defined in the CLI. So, you will need to:&lt;/P&gt;
&lt;P&gt;1. Change the domain name in CLI from test.local to test.com&lt;/P&gt;
&lt;P&gt;2. Change the FQDN in CLI to match your external DNS record&lt;/P&gt;
&lt;P&gt;3. Make the necessary DNS entries so the FQDN of ISE can be resolved to ise01.test.com&lt;/P&gt;
&lt;P&gt;Also, in the future, never use .local domain &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Perhaps .net instead &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 16:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874779#M36826</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-06T16:56:23Z</dc:date>
    </item>
    <item>
      <title>Hi Neno</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874780#M36829</link>
      <description>&lt;P&gt;Hi Neno&lt;/P&gt;
&lt;P&gt;Thanks a million .&lt;/P&gt;
&lt;P&gt;After changing &amp;nbsp;the domain name from .local to .com &amp;nbsp;, still i will be able to pull the groups and users &amp;nbsp;from the .local domain .( for us test.com is just a zone in dns ) .&lt;/P&gt;
&lt;P&gt;After &amp;nbsp;changing the fqdn ("&lt;B class="cBold"&gt;ip host&lt;/B&gt; a.b.c.d sales sales.amer.xyz.com" &amp;nbsp;) I &amp;nbsp;can create certificate for &amp;nbsp;ise-01.test.com (multiuse) &amp;nbsp;or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;create &amp;nbsp;certificate for portal( ise-01.test.com ) ,eap-tls and keep the self signed &amp;nbsp;certificate ?&lt;/P&gt;
&lt;P&gt;Now both ise are in a group , after &amp;nbsp;importing new certificate &amp;nbsp;register the node again ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;I have another problem . (at present for guest portal i am using &amp;nbsp;ip address instead of fqdn) . When people are accessing guest portal from the &amp;nbsp;laptops the pages taking ages to load&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did tcpdump on ise , i can find a lot of &amp;nbsp; &amp;nbsp; RST&amp;nbsp;Flags&lt;/P&gt;
&lt;P&gt;below is the sample trace&lt;/P&gt;
&lt;P&gt;1851&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;15.364956&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;10.0.109.24&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;192.168.10.40&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;TCP&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;60&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;51978 → 8443 [RST, ACK] Seq=162 Ack=932 Win=0 Len=0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks again&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 21:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874780#M36829</guid>
      <dc:creator>wyfy-2015</dc:creator>
      <dc:date>2016-04-06T21:23:44Z</dc:date>
    </item>
    <item>
      <title>Hmm, I am not sure about this</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874781#M36832</link>
      <description>&lt;P&gt;Hmm, I am not sure about this. Question though: Why use IP address vs DNS with FQDN entry?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 06:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874781#M36832</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-08T06:17:16Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874782#M36834</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Instead of &amp;nbsp;fqdn on the guest portal i used static ip .Thats what i mean&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sorry for the confusion&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 22:04:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/2874782#M36834</guid>
      <dc:creator>wyfy-2015</dc:creator>
      <dc:date>2016-04-08T22:04:13Z</dc:date>
    </item>
  </channel>
</rss>

