<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP name Servers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586392#M537316</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a difference between the DNS server was misconfigured and the DNS server was down.  If the server was up but misconfigured, it is very likely the secondary server would not be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Oct 2016 22:40:59 GMT</pubDate>
    <dc:creator>gbekmezi-DD</dc:creator>
    <dc:date>2016-10-18T22:40:59Z</dc:date>
    <item>
      <title>IP name Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586389#M537312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We recently had an issue where our primary ip name server's dns stopped responding. However the ISE node did not fail over to the secondary name servers and broke all users in the child domain that was no long resolving. Is there a way to help ISE fail over to secondary name servers for DNS? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We waited for our server team to address the issue and then everything started working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2016 00:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586389#M537312</guid>
      <dc:creator>ziggyzwy</dc:creator>
      <dc:date>2016-10-18T00:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: IP name Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586390#M537314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE should have failed over if there were no DNS response. What version of ISE did you see the behavior? Also, was the primary DNS server truly down as in not responding to DNS request, or is it possible the DNS server was still responding, but without proper response?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2016 05:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586390#M537314</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-10-18T05:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: IP name Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586391#M537315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to our Systems guys the dns zone file was not set up correctly on the primary dns name server for the node.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to traceroute from the node to the domain controller and ping the domain controller but the dns was failing for the child.domain.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was the message that I received from the primary name server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS request timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout was 2 seconds.&lt;/P&gt;&lt;P&gt;DNS request timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout was 2 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The secondary and tertiary dns name servers were set up correctly and provided the correct ip address for the child.domain.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the &lt;SPAN style="color: #0088c2; font-family: Tahoma; font-size: 11px; font-weight: bold;"&gt;Active Directory Diagnostic Tool&lt;/SPAN&gt; it was unable to locate the domain controller for the child domain in question and all tests failed. Once our system team updated the primary dns server for the node everything started working again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very weird behavior indeed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 2.0.306 patch 3&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2016 16:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586391#M537315</guid>
      <dc:creator>ziggyzwy</dc:creator>
      <dc:date>2016-10-18T16:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: IP name Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586392#M537316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a difference between the DNS server was misconfigured and the DNS server was down.  If the server was up but misconfigured, it is very likely the secondary server would not be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2016 22:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586392#M537316</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2016-10-18T22:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: IP name Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586393#M537317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The OS DNS resolver needs to see 'no response' before it will decide to fail over to your secondary.&amp;nbsp; So if you get a response from the primary, but some records are incorrect/missing, it's not smart enough to know it should fail over to the secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2016 16:47:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586393#M537317</guid>
      <dc:creator>ChrisMurray</dc:creator>
      <dc:date>2016-10-24T16:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: IP name Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586394#M537318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, that does make sense of how the fail-over works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2016 17:51:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-name-servers/m-p/3586394#M537318</guid>
      <dc:creator>ziggyzwy</dc:creator>
      <dc:date>2016-10-24T17:51:26Z</dc:date>
    </item>
  </channel>
</rss>

