<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE DNS CNAME Requirement in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547561#M538010</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ISE 2.0 Admin guide, there is a statement about a DNS CNAME record requirement for each ISE node:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Extract:&lt;/P&gt;&lt;P&gt;You need to add Canonical Name (CNAME) record of the ISE hostname to the DNS. Ensure that you create CNAME RR along with the A record for each Cisco ISE node. If CNAME record is not created, it might result in the alarm ‘DNS Resolution failed for CNAME &amp;lt;hostname of the node&amp;gt;’.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than an alarm being raised, what other functionality is impacted by the absence of a CNAME record (assume A &amp;amp; PTR records do exist)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come across an example where a DNS server doesn't support the same value in the A and CNAME fields...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Denis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Aug 2016 06:24:25 GMT</pubDate>
    <dc:creator>dvan</dc:creator>
    <dc:date>2016-08-10T06:24:25Z</dc:date>
    <item>
      <title>ISE DNS CNAME Requirement</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547561#M538010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ISE 2.0 Admin guide, there is a statement about a DNS CNAME record requirement for each ISE node:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Extract:&lt;/P&gt;&lt;P&gt;You need to add Canonical Name (CNAME) record of the ISE hostname to the DNS. Ensure that you create CNAME RR along with the A record for each Cisco ISE node. If CNAME record is not created, it might result in the alarm ‘DNS Resolution failed for CNAME &amp;lt;hostname of the node&amp;gt;’.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than an alarm being raised, what other functionality is impacted by the absence of a CNAME record (assume A &amp;amp; PTR records do exist)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come across an example where a DNS server doesn't support the same value in the A and CNAME fields...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Denis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2016 06:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547561#M538010</guid>
      <dc:creator>dvan</dc:creator>
      <dc:date>2016-08-10T06:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS CNAME Requirement</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547562#M538011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the usage of CNAME that is explained nicely here.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.networking4all.com/en/support/domain+names/dns/cname-records/" title="https://www.networking4all.com/en/support/domain+names/dns/cname-records/"&gt;https://www.networking4all.com/en/support/domain+names/dns/cname-records/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CNAME is an alias name used in certain situations, for eg: you use wild cards in your certificates that ISE supports (or) you have to renew certificates and change the names constantly. It is for easier DNS management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The key is that DNS resolution between ISE nodes and between endpoints and ISE nodes need to work consistently. This is a tool to make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2016 20:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547562#M538011</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2016-08-10T20:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS CNAME Requirement</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547563#M538013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That paragraph is a bit misleading. If an A record exists for an ISE node, there is no need for a CNAME record created for it, unless setting up an FQDN for ISE sponsor portal, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a matter of facts, I would consider it a misconfiguration if both A and CNAME point to the same FQDN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I logged a doc bug -- CSCva87189&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2016 20:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547563#M538013</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-08-10T20:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS CNAME Requirement</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547564#M538015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the clarification Hsing-Tsu &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2016 05:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-cname-requirement/m-p/3547564#M538015</guid>
      <dc:creator>dvan</dc:creator>
      <dc:date>2016-08-11T05:34:38Z</dc:date>
    </item>
  </channel>
</rss>

