<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE HA and CA deployment without a DNS server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574865#M540901</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can get around the DNS/FQDN requirement in ISE HA by using the ip host configuration command in the ISE CLI. It will require a restart of the ISE services anytime you add host. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In config mode the command is "ip host A.B.C.D ISE-PAN01.example.com"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Feb 2016 15:13:17 GMT</pubDate>
    <dc:creator>Cory Peterson</dc:creator>
    <dc:date>2016-02-10T15:13:17Z</dc:date>
    <item>
      <title>ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574860#M540896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;&lt;SPAN style="font-size: 9pt; font-family: Calibri, sans-serif;"&gt;Could someone let me know any notice to take prior to ISE deployment in HA, where no DNS server is deployed?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;&lt;SPAN style="font-size: 9pt; font-family: Calibri, sans-serif;"&gt;ISE is also expected to publish client certificates for EAP-TLS auth.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;&lt;SPAN style="font-size: 9pt; font-family: Calibri, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 21:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574860#M540896</guid>
      <dc:creator>yfukudom</dc:creator>
      <dc:date>2016-02-09T21:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574861#M540897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm very confused by your query..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does EAP-TLS auth have to do with DNS? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see my blog post on how certificate authentications work here: &lt;A class="loading" href="http://www.networkworld.com/article/2226498/infrastructure-management/simply-put-how-does-certificate-based-authentication-work.html" title="http://www.networkworld.com/article/2226498/infrastructure-management/simply-put-how-does-certificate-based-authentication-work.html"&gt;http://www.networkworld.com/article/2226498/infrastructure-management/simply-put-how-does-certificate-based-authentication-work.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your concern about querying the OCSP service? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Always keep in mind that DNS is a mission-critical application for networking, in general.&amp;nbsp; It will be needed for Active Directory - even simple web browsing.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Aaron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 23:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574861#M540897</guid>
      <dc:creator>Aaron Woland</dc:creator>
      <dc:date>2016-02-09T23:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574862#M540898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The partner who is asking deploys closed/separated LAN for hospitals as design, where there has been no DNS/AD server, from cost-reduction perspective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Dome&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 23:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574862#M540898</guid>
      <dc:creator>yfukudom</dc:creator>
      <dc:date>2016-02-09T23:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574863#M540899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the endpoint has NO DNS resolution.&amp;nbsp; That still won't effect the EAP-TLS authentication.&amp;nbsp; It WILL however, impact all advanced services that use URL redirection - (WebAuth, GUEST, MDM, etc.).&amp;nbsp; Are those type services being deployed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Aaron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 23:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574863#M540899</guid>
      <dc:creator>Aaron Woland</dc:creator>
      <dc:date>2016-02-09T23:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574864#M540900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;There are only web/application/DB servers and file servers inside the LAN. All hostnames needed to be resolved by client hosts are written in local hosts file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Updates)&lt;/P&gt;&lt;P&gt;A partner is building up this environment for a testing required prior to proposal, but has been facing to an issue when shutting down the primary ISE, expecting the secondary one takes over all roles of primary one. While shutting down the primary, no EAP-TLS authentication is succeeded as the partner claims. Some consideration in ISE configuration seems to be needed and any comments would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ISE_HA-status.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/92960_ISE_HA-status.png" style="height: 368px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 23:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574864#M540900</guid>
      <dc:creator>yfukudom</dc:creator>
      <dc:date>2016-02-09T23:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574865#M540901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can get around the DNS/FQDN requirement in ISE HA by using the ip host configuration command in the ISE CLI. It will require a restart of the ISE services anytime you add host. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In config mode the command is "ip host A.B.C.D ISE-PAN01.example.com"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Feb 2016 15:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574865#M540901</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2016-02-10T15:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574866#M540902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks for your comment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have received a screenshot of the ISE HA status adding to my question, and would like to know another steps to troubleshoot as HA itself seems good.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Feb 2016 00:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574866#M540902</guid>
      <dc:creator>yfukudom</dc:creator>
      <dc:date>2016-02-12T00:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574867#M540907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you able to recreate this issue in your own lab?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No DNS in a deployment is not well supported. DNS can run on a royalty-free Linux or BSD so it would not cause the customer or partner much extra. ISE PoV kit includes a VM to run common network services.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2016 20:33:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574867#M540907</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-02-17T20:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA and CA deployment without a DNS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574868#M540908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot for comments, folks.&lt;/P&gt;&lt;P&gt;Finally, after installing the certification of secondary ISE server on client hosts, it has worked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Feb 2016 08:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-and-ca-deployment-without-a-dns-server/m-p/3574868#M540908</guid>
      <dc:creator>yfukudom</dc:creator>
      <dc:date>2016-02-18T08:06:44Z</dc:date>
    </item>
  </channel>
</rss>

