<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE authentication question for global uses in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990885#M455354</link>
    <description>&lt;P&gt;Thanks for the detailed explanation&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/624773"&gt;@Colby LeMaire&lt;/a&gt;&amp;nbsp;.&amp;nbsp; &amp;nbsp;Just out of curosity, taking into account that ISE is on .local, would it be possible to use a .com public wildcard certificate as an option for the EAP authentication?&amp;nbsp; Or will it definitely need the .local?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2019 18:05:23 GMT</pubDate>
    <dc:creator>BrianPersaud</dc:creator>
    <dc:date>2019-11-28T18:05:23Z</dc:date>
    <item>
      <title>ISE authentication question for global uses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990307#M455345</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have multiple standalone ISE instances and WLC's worldwide.&amp;nbsp; Users travel between sites.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to do a&amp;nbsp; SSID with the same name at all sites that has the same setting for computer authentication that would allow computers in the Domain Computers AD group to be allowed on the internal LAN.&lt;/P&gt;&lt;P&gt;The issue I face presently is that each ISE instance has their own certificate.&amp;nbsp; So users would have to "forget the network" and reconnect to the SSID when they travel to a different location.&lt;/P&gt;&lt;P&gt;What would be the best approach to accomplish this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently on ISE 2.4 Patch 10 and AIROS 8.5&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 19:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990307#M455345</guid>
      <dc:creator>BrianPersaud</dc:creator>
      <dc:date>2019-11-27T19:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication question for global uses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990315#M455346</link>
      <description>&lt;P&gt;What PKI is being used to sign the EAP certificate?&lt;/P&gt;&lt;P&gt;If you are using the same PKI to sign the EAP certificate for the nodes worldwide, you can simply export the EAP certificate with private key from one node and then import into the other nodes and check the box to utilize it for the EAP role. It is a common practice to use the same EAP certificate on multiple PSNs for this very reason.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 19:33:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990315#M455346</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2019-11-27T19:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication question for global uses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990344#M455348</link>
      <description>&lt;P&gt;Hi We use a Windows CA to sign the certs.&amp;nbsp; Got a question about the process.&amp;nbsp; Every ISE node has a different hostname.&amp;nbsp; Ex mine is torontoise.domain.local and another may be montrealise.domain.local.&amp;nbsp; I know when generating a certificate, the FQDN has to be in the CN.&amp;nbsp; Can I export this torontoise.domain.local cert and use it in the montreal ISE for EAP authentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 20:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990344#M455348</guid>
      <dc:creator>BrianPersaud</dc:creator>
      <dc:date>2019-11-27T20:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication question for global uses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990362#M455351</link>
      <description>&lt;P&gt;Issue the certificate using one of the ISE node's as the Subject/CN and then put each other ISE node's FQDN in the SAN field of the certificate.&amp;nbsp; Then you can install and use the certificate for EAP authentication on all of your ISE nodes.&amp;nbsp; If the FQDN of the node that is doing the authentication isn't located somewhere within the certificate (i.e. SAN field), then the client will not trust it.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 20:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990362#M455351</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-11-27T20:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication question for global uses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990885#M455354</link>
      <description>&lt;P&gt;Thanks for the detailed explanation&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/624773"&gt;@Colby LeMaire&lt;/a&gt;&amp;nbsp;.&amp;nbsp; &amp;nbsp;Just out of curosity, taking into account that ISE is on .local, would it be possible to use a .com public wildcard certificate as an option for the EAP authentication?&amp;nbsp; Or will it definitely need the .local?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 18:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990885#M455354</guid>
      <dc:creator>BrianPersaud</dc:creator>
      <dc:date>2019-11-28T18:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication question for global uses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990934#M455356</link>
      <description>&lt;P&gt;Think about it from the perspective of the client side.&amp;nbsp; ISE is presenting a certificate and the client must verify that the certificate is valid and trusted.&amp;nbsp; To do this, the client side checks the following things:&lt;/P&gt;&lt;P&gt;- Is the certificate valid or expired?&amp;nbsp; Each certificate has a validity period.&amp;nbsp; The current date/time must be within the valid dates of the certificate.&lt;/P&gt;&lt;P&gt;- Was the certificate issued by a CA that the client already trusts, such as Verisign?&amp;nbsp; This is based on the client's Certificate Trust List which can be viewed through browser settings.&lt;/P&gt;&lt;P&gt;- Does the certificate belong to the website or server being visited?&amp;nbsp; The client looks at the FQDN or IP address being visited and verifies that the Subject (CN) matches or that one of the Subject Alternative Name (SAN) fields match.&lt;/P&gt;&lt;P&gt;With that said, if your certificate is issued to "ise.corp.com" but the ISE server's real FQDN in DNS is "ise.corp.local", then the client will see them as different and won't trust it.&amp;nbsp; You could manipulate DNS to resolve "ise.corp.com" to the server's IP address.&amp;nbsp; But ISE may not allow you to install the certificate unless its FQDN is in the certificate somewhere.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 22:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-question-for-global-uses/m-p/3990934#M455356</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-11-28T22:21:42Z</dc:date>
    </item>
  </channel>
</rss>

