<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035944#M558350</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Basically &lt;U&gt;&lt;FONT color="#FF0000"&gt;not&lt;/FONT&gt;&lt;/U&gt; as the below thread will confirm : MS-AD is indeed not a good solution for DHCP, better is to look into appliances such as infoblox or others. These can offer extended and flexible configuration for lots of vlan's and subnets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-with-dhcp-server/td-p/3540467" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-with-dhcp-server/td-p/3540467&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2020 08:35:22 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2020-02-26T08:35:22Z</dc:date>
    <item>
      <title>Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035871#M558346</link>
      <description>&lt;P&gt;I have a client who wants to deploy only single ISE node in their environment for wireless guest access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Their current DHCP server is configured in AD which is hosted in their datacentre.&lt;/LI&gt;&lt;LI&gt;They are using Meraki MX devices for wireless&lt;/LI&gt;&lt;LI&gt;ISE will be part of Corp network.&lt;/LI&gt;&lt;LI&gt;Their concern is they dont want guest devices accessing the AD server for DHCP/DNS.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, I was wondering if I could use ISE as DHCP and DNS server. But I read in docs that these features exist in ISE for third party NAD devices that dont support dynamic or static url redirection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, my question is, even though the client's NAD device would be Meraki, in that case, can I use ISE as DHCP and DNS server ?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 04:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035871#M558346</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-02-26T04:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035944#M558350</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Basically &lt;U&gt;&lt;FONT color="#FF0000"&gt;not&lt;/FONT&gt;&lt;/U&gt; as the below thread will confirm : MS-AD is indeed not a good solution for DHCP, better is to look into appliances such as infoblox or others. These can offer extended and flexible configuration for lots of vlan's and subnets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-with-dhcp-server/td-p/3540467" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-with-dhcp-server/td-p/3540467&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 08:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035944#M558350</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-02-26T08:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035947#M558351</link>
      <description>They are already using MS-AD now for DHCP.&lt;BR /&gt;&lt;BR /&gt;The question is whether we can use ISE as DHCP and DNS server for handling wireless guest connections.</description>
      <pubDate>Wed, 26 Feb 2020 08:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035947#M558351</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-02-26T08:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035950#M558352</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- &lt;FONT color="#FF0000"&gt;Negative&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 08:48:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035950#M558352</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-02-26T08:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035998#M558353</link>
      <description>can you please explain why ?&lt;BR /&gt;Also, please recommend an alternative way we can achieve this ?</description>
      <pubDate>Wed, 26 Feb 2020 10:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4035998#M558353</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-02-26T10:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4036007#M558355</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/457168"&gt;@damode&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it’s a great question and it’s probably not the use case that Cisco intended. But there is no reason why it should not work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;i have always wanted to test this in my lab but never got around to it. I don’t know if the ISE PSN would Hand out the DNS server to the client. That would be a show stopper if it didn’t. Do you have the opportunity to try this in a lab environment?The function of a single DHCP service should not pose a problem to even a simple Linux daemon. You’re probably not concerned with lease database survivability or complex options?&lt;/P&gt;
&lt;P&gt;I would however think this is not in your best interest because there is no way to monitor the scope usage etc or to manage the leases. I’d say look elsewhere.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 10:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4036007#M558355</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-02-26T10:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use ISE as DHCP/DNS server to prevent guest traffic using internal DHCP/DNS servers ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4036321#M558382</link>
      <description>&lt;P&gt;ISE will always return itself as DNS and it is not a configurable parameter.&lt;/P&gt;
&lt;P&gt;This is not intended as production DHCP, rather it was just meant to provide DHCP during AUTH state to address the lack of URL-Redirect feature on certain NADs. I understand the OP's desire to utilize ISE for DHCP server for other purpose, but recommend using the router/switch or a purpose built DHCP server.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 17:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-we-use-ise-as-dhcp-dns-server-to-prevent-guest-traffic-using/m-p/4036321#M558382</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2020-02-26T17:01:19Z</dc:date>
    </item>
  </channel>
</rss>

