<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Guest with OpenDNS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429676#M539004</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;or possibly the Internet Firewall can inspect client DNS requests and intercept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks George.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Apr 2016 19:41:56 GMT</pubDate>
    <dc:creator>joshhunter</dc:creator>
    <dc:date>2016-04-28T19:41:56Z</dc:date>
    <item>
      <title>ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429670#M538998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: left;"&gt;Hello, is anyone using OpenDNS for their DNS as Guest content filtering with ISE?&lt;/P&gt;&lt;P style="text-align: left;"&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;The only problem I envisage is that we want to use a wildcard certificate to prevent certificate warning in browsers.&lt;/P&gt;&lt;P style="text-align: left;"&gt;So this means users need to resolve the DNS name of ISE guest portal to the internal IP as part of the re-direct process.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2016 12:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429670#M538998</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-04-28T12:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429671#M538999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a reason you don't want to publish the ISE guest portal A record to external DNS?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2016 15:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429671#M538999</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2016-04-28T15:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429672#M539000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi George, I have had a look at OpenDNS free package and there does not appear to be a way to add an A record.&lt;/P&gt;&lt;P&gt;Have you any information on this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want the benefits of content filtering the guest using OpenDNS but for the ability to resolve the ISE Guest Portal IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2016 15:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429672#M539000</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-04-28T15:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429673#M539001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You still have to publish DNS records using whatever method your organization or your customer's organization does for other records.&amp;nbsp; For example, if my domain is bekmezian.com I go to my DNS configuration (for me it's WebKor) and I add a record for guest.bekmezian.com.&amp;nbsp; Nothing to do in OpenDNS except for ensure you don't Block internal IP addresses (screenshot attached):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/94937_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2016 16:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429673#M539001</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2016-04-28T16:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429674#M539002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi George, Are you suggesting you add an 'A record' that maps to a private ip on a public DNS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, lets say for example I own the domain of &lt;STRONG&gt;isecold.com&lt;/STRONG&gt; and I have a wildcard certificate that is allows for &lt;STRONG&gt;*.isecold.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I would then add a public DNS entry for example for &lt;STRONG&gt;guest.isecold.com&lt;/STRONG&gt; to my private IP address (ISE Guest Portal IP).&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;That way my guests can still use opendns and resolve &lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt; line-height: 1.5em;"&gt;guest.isecold.com&lt;/STRONG&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; and SSL certicate would work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing that may prevent this is if my Domain/DNS provider would not allow a private IP. &lt;/P&gt;&lt;P&gt;I've read a few different forums with many suggesting this is bad practice even if you provider does allow it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2016 19:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429674#M539002</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-04-28T19:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429675#M539003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's exactly what I am suggesting Josh.&amp;nbsp; If you know what you are doing and why you are doing it, then you are free to bend rules.&amp;nbsp; If the requirement is "point my guests to opendns" then that is your only option.&amp;nbsp; The other option you could consider is having your guests point to a DNS forwarder in your own network.&amp;nbsp; Then your DNS server could resolve your own domain locally while forwarding all other requests to opendns' name servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2016 19:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429675#M539003</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2016-04-28T19:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429676#M539004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;or possibly the Internet Firewall can inspect client DNS requests and intercept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks George.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2016 19:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429676#M539004</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-04-28T19:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest with OpenDNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429677#M539005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Worked perfectly George as you suggested.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 May 2016 23:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-with-opendns/m-p/3429677#M539005</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-05-03T23:15:37Z</dc:date>
    </item>
  </channel>
</rss>

