<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.1 define a list of preferred DC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497429#M527659</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply. I suspected this.&amp;nbsp; &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;It remains only to understand why preferred DC list need and why cisco doc &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt; indicate the following:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;. You can create a list of preferred DCs in the following cases:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The SRV records are bad, missing or not configured. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * The DNS configuration is wrong or cannot be edited. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;This only confuses us.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Aug 2017 08:19:43 GMT</pubDate>
    <dc:creator>Alexander Kravtsov</dc:creator>
    <dc:date>2017-08-15T08:19:43Z</dc:date>
    <item>
      <title>ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497422#M527641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day, Colleagues&lt;/P&gt;&lt;P&gt;We would like&amp;nbsp; to add new AD in External Identity Source, but this AD didn't resolved by DNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Documentation says:&lt;/P&gt;&lt;P&gt;&amp;lt;snip&amp;gt;&lt;/P&gt;&lt;P&gt;Cisco ISE also provides the ability to define a list of preferred DCs per domain. This list of DCs will be prioritized for selection before DNS SRV queries. But this list of preferred DCs is not an exclusive list. If the preferred DCs are unavailable, other DCs are selected. You can create a list of preferred DCs in the following cases: &lt;/P&gt;&lt;UL&gt;&lt;LI&gt; The SRV records are bad, missing or not configured.&amp;nbsp; &lt;/LI&gt;&lt;LI&gt; The site association is wrong or missing or the site cannot be used.&amp;nbsp; &lt;/LI&gt;&lt;LI&gt; The DNS configuration is wrong or cannot be edited.&amp;nbsp; &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;H3 class="sectiontitle"&gt;Advanced Tuning&lt;/H3&gt;&lt;P&gt;&amp;nbsp; The advanced tuning feature provides node-specific changes and settings to adjust the parameters deeper in the system. This page allows&amp;nbsp; configuration of preferred DCs, GCs, DC failover parameters, and timeouts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/snip&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But no any information how to do this list.&amp;nbsp; Is it possible ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497422#M527641</guid>
      <dc:creator>Alexander Kravtsov</dc:creator>
      <dc:date>2017-08-14T14:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497423#M527646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Admin Guide is clear that this should only be used during a support case:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Advanced Tuning.PNG" class="image-1 jive-image" src="/legacyfs/online/fusion/110475_Advanced Tuning.PNG" style="height: 85px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://https//www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#reference_D81D04FDE46C4FF1A396641074E8836C"&gt;Cisco ISE 2.1 Admin Guide on AD Advanced Tuning&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you poke around long enough, you'll find it at:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Advanced Tuning2.PNG" class="jive-image image-2" src="/legacyfs/online/fusion/110476_Advanced Tuning2.PNG" style="height: 288px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With these configurable parameters:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Advanced Tuning3.PNG" class="jive-image image-3" src="/legacyfs/online/fusion/110477_Advanced Tuning3.PNG" style="height: 242px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that, I highly encourage you to work through TAC to set the parameters correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497423#M527646</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-08-14T14:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497424#M527649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said in topic we knows where this may be done but didn't know how to do this.&lt;/P&gt;&lt;P&gt;What parameters and values can be used for this list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC is &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt; puzzled &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;already but without susccess yet &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497424#M527649</guid>
      <dc:creator>Alexander Kravtsov</dc:creator>
      <dc:date>2017-08-14T14:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497425#M527652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding to Charles.&lt;/P&gt;&lt;P&gt;The proper way to define the preferred DCs is use Microsoft AD Sites and Services.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497425#M527652</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-14T14:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497426#M527654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please provide the TAC case number, if possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497426#M527654</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-14T14:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497427#M527656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is SR &lt;SPAN class="ng-binding"&gt;682828830&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="ng-binding"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="ng-binding"&gt;It seems, our customer has two different DCs without trust relationships. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497427#M527656</guid>
      <dc:creator>Alexander Kravtsov</dc:creator>
      <dc:date>2017-08-14T14:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497428#M527658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Defining the preferred DC list using the registry keys is not going to help with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If ISE deployment using multiple domains without trust, the DNS servers configured in ISE need to able to resolve all the AD domain records and use multiple join.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In our training labs, I used stub zones&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="110492" alt="Screen Shot 2017-08-14 at 9.02.28 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/110492_Screen Shot 2017-08-14 at 9.02.28 AM.png" style="height: auto; width: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's also possible to use conditional forwarding, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 16:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497428#M527658</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-14T16:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 define a list of preferred DC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497429#M527659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply. I suspected this.&amp;nbsp; &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;It remains only to understand why preferred DC list need and why cisco doc &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt; indicate the following:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;. You can create a list of preferred DCs in the following cases:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The SRV records are bad, missing or not configured. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * The DNS configuration is wrong or cannot be edited. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;This only confuses us.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2017 08:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-define-a-list-of-preferred-dc/m-p/3497429#M527659</guid>
      <dc:creator>Alexander Kravtsov</dc:creator>
      <dc:date>2017-08-15T08:19:43Z</dc:date>
    </item>
  </channel>
</rss>

