<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: my devices portal FQDN DNS resolution in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717291#M492212</link>
    <description>Ok what’s their concern?&lt;BR /&gt;</description>
    <pubDate>Tue, 02 Oct 2018 11:42:51 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-10-02T11:42:51Z</dc:date>
    <item>
      <title>my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3716939#M492207</link>
      <description>&lt;P&gt;I have two ISEs. Primary PAN, Secondary Mnt, Active PSN on ISE01 (192.168.1.10). Secondary PAN, Primary Mnt, Active PSN on ISE02 (192.168.1.20).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup BYOD but for the my devices portal I can only set the FQDN under the Portal Settings. For this example its mydevices.test.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All this works OK as I have DNS resolving mydevices.test.com to 192.168.1.10. But how do I make this work for the second ISE node? The FQDN has to be mydevices.test.com. I don't have any loadbalancers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can get the CWA for BYOD to work on both ISEs by using two seperate authz profiles and identifying the request based on the source ISE.&amp;nbsp;The authz profile for BYOD redirect&amp;nbsp;has the option to set static FQDN which can be used in a rule and modified to suit the ISE. So ISE1 has byod1,test.com and ISE2 has byod2.test.com. The authz rules match the source ISE and apply the corresponding BYOD CWA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I can't see how to do this for the mydevices portal. I thought of just using two DNS records pointing to the same FQDN but don't think that is the correct way to do it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help on this one?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 22:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3716939#M492207</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2018-10-01T22:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3716949#M492208</link>
      <description>My devices portal has nothing to do with the byod nsp redirect. Why are you statically assigning this? ISE takes care of that for you by resolving the psn your authenticated to automatically&lt;BR /&gt;&lt;BR /&gt;For the my devices easy url FQDN yes you set a dns record with both IP addresses in it&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_webportals.html#pgfId-1000833" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_webportals.html#pgfId-1000833&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 01 Oct 2018 22:30:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3716949#M492208</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-01T22:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717187#M492209</link>
      <description>&lt;P&gt;Hi, sorry but I don't understand part of your answer. You say:&lt;BR /&gt;&lt;BR /&gt; &lt;FONT size="3"&gt;&lt;EM&gt;"Why are you statically assigning this? ISE takes care of that for you by resolving the psn your authenticated to automatically"&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;I'm assuming you mean the URL that gets applied during the BYOD redirect? If I leave it default without specifying a manual FQDN then it will return the hostname of the authenticating ISE but I don't want that, I want byod1.test.com or byod2.test.com not the hostname, hence why I set the manual URL on the redirect authz profile. If I have this setup completely wrong then i'm open to suggestions.&lt;BR /&gt;&lt;BR /&gt;As for mydevices portal if DNS round robin is the way then i'll give that a go but the link you posted is for ISE 1.2 and i'm using ISE 2.4. I don't see the same recommendations for mydevices portal in the 2.4 user guides. Is this still valid?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 08:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717187#M492209</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2018-10-02T08:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717253#M492210</link>
      <description>For the byod flow it’s not necessary to do what you did. I don’t understand why you have a problem automatically returning the psn hostname of the server the device authenticated to? It should then redirect to same. What you’re doing is not necessary please read the byod guide&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867" target="_blank"&gt;https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also the dns recommendations are still the same&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Oct 2018 10:26:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717253#M492210</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-02T10:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717269#M492211</link>
      <description>&lt;P&gt;Yes I know the PSN hostname is the norm but it's a customer requirement that the hostname is not shown in the URL. That is why it has to be a unique BYOD FQDN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 10:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717269#M492211</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2018-10-02T10:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717291#M492212</link>
      <description>Ok what’s their concern?&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Oct 2018 11:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717291#M492212</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-02T11:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717352#M492213</link>
      <description>&lt;P&gt;No concern. They have stipulated that the URL shouldn't show the hostname. I've suggested the standard way but they insist doing without the hostname.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 13:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717352#M492213</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2018-10-02T13:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: my devices portal FQDN DNS resolution</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717630#M492214</link>
      <description>&lt;P&gt;Just do the URL override in the portal redirection.&amp;nbsp; Setup two DNS names, byodportal1.mycompany.com and byodportal2.mycompany.com, and assign map them to each PSN.&amp;nbsp; Then build two redirect authorization profiles, one that uses byodportal1 and one that uses byodportal2.&amp;nbsp; Finally build your policy set rules:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if network access ISE hostname equals psn1 then use authorization profile byodportal1&lt;/P&gt;
&lt;P&gt;if network access ISE hostname equals psn2 then use authorization profile byodportal2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are talking about the MyDevices portal outside of the BYOD flow then you can just map the FQDN to both PSN IPs and let DNS figure it out.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 17:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-fqdn-dns-resolution/m-p/3717630#M492214</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-02T17:37:16Z</dc:date>
    </item>
  </channel>
</rss>

