<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add 2 Separate Cisco ISE Deployment Configurations into a New Deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/add-2-separate-cisco-ise-deployment-configurations-into-a-new/m-p/4117096#M561643</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;1. Are there options to merge/add 2 different deployment configurations into the new deployment?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;No. You need manually add the configurations from the 2nd to the 1st.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;2. Is it possible to make a 2 node deployment with different domain, but both nodes are reachable from the 2 DNS. (Will try this on lab for the meantime)&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This seems about two DNS domains. Yes, we may have multiple DNS domains. However, the DNS servers configured in ISE needs able to resolve both/all these DNS domains.&lt;/P&gt;
&lt;P&gt;In case multiple MS AD domains, ISE may use one single AD join point if the AD domains have 2-way trusts. Else, ISE may use two AD join points and one for each AD domain. Still, the DNS servers configured in ISE need able to resolve both AD domains.&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jul 2020 21:41:20 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2020-07-11T21:41:20Z</dc:date>
    <item>
      <title>Add 2 Separate Cisco ISE Deployment Configurations into a New Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/add-2-separate-cisco-ise-deployment-configurations-into-a-new/m-p/4116880#M561636</link>
      <description>&lt;P&gt;Objective:&lt;BR /&gt;- To combine configurations of two separate (2.3) ISE deployment into a (2.7) new deployment.&lt;BR /&gt;- To refresh the old deployments (2 existing deployment)&lt;/P&gt;&lt;P&gt;Overview:&lt;BR /&gt;There are two separate deployments, and the new deployment must have both of the configurations of the two separate deployments. Each deployment has a different domain services and internal certificates.&lt;/P&gt;&lt;P&gt;Configurations: Policies, Profiles, Network devices, User accounts and etc..&lt;/P&gt;&lt;P&gt;New Deployment: Located on 2 different sites, and will use new IP addresses and Hostnames, and latest versions.&lt;/P&gt;&lt;P&gt;Question(s):&lt;/P&gt;&lt;P&gt;1. Are there options to merge/add 2 different deployment configurations into the new deployment?&lt;BR /&gt;(Update*)A: No&lt;/P&gt;&lt;P&gt;2. Is it possible to make a 2 node deployment with different domain, but both nodes are reachable from the 2 DNS. (Will try this on lab for the meantime)&lt;BR /&gt;(Update*)A: Yes&lt;/P&gt;&lt;P&gt;Follow up Question(s):&lt;/P&gt;&lt;P&gt;3. Should I import the 2nd Site's Certificate chain as well on the Primary Node.&lt;/P&gt;&lt;P&gt;- I've noticed that after deploying it as Primary and secondary, the trusted certificates did not contain the ISEPAN-CORP02's trusted certificate chain I imported before it became as secondary.&lt;/P&gt;&lt;P&gt;4. Will this setup pose any problems in the future? (Two separate domained ISEPAN on each site deployed as Primary and Secondary)&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 04:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-2-separate-cisco-ise-deployment-configurations-into-a-new/m-p/4116880#M561636</guid>
      <dc:creator>jj2048</dc:creator>
      <dc:date>2020-07-12T04:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Add 2 Separate Cisco ISE Deployment Configurations into a New Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/add-2-separate-cisco-ise-deployment-configurations-into-a-new/m-p/4117096#M561643</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;1. Are there options to merge/add 2 different deployment configurations into the new deployment?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;No. You need manually add the configurations from the 2nd to the 1st.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;2. Is it possible to make a 2 node deployment with different domain, but both nodes are reachable from the 2 DNS. (Will try this on lab for the meantime)&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This seems about two DNS domains. Yes, we may have multiple DNS domains. However, the DNS servers configured in ISE needs able to resolve both/all these DNS domains.&lt;/P&gt;
&lt;P&gt;In case multiple MS AD domains, ISE may use one single AD join point if the AD domains have 2-way trusts. Else, ISE may use two AD join points and one for each AD domain. Still, the DNS servers configured in ISE need able to resolve both AD domains.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 21:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-2-separate-cisco-ise-deployment-configurations-into-a-new/m-p/4117096#M561643</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-07-11T21:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Add 2 Separate Cisco ISE Deployment Configurations into a New Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/add-2-separate-cisco-ise-deployment-configurations-into-a-new/m-p/4117128#M561649</link>
      <description>&lt;P&gt;Hi, hslai.&lt;/P&gt;&lt;P&gt;Appreciate the response.&lt;/P&gt;&lt;P&gt;Question 1 is answered and I accept it.&lt;BR /&gt;Question 2 below is the environment I've set up on our lab.&lt;BR /&gt;A: Yes, we can deploy ISE as primary and secondary under two domains, as long as it is resolvable.&lt;/P&gt;&lt;P&gt;Environment:&lt;/P&gt;&lt;P&gt;2 Sites with 2 Different domains&lt;BR /&gt;Corporate 1 and Corporate 2&lt;BR /&gt;Both have two tier PKI and each of their ISE in the beginning as standalone has a certificate signed by each of corporate's SubCA respectively.&lt;BR /&gt;ISEPAN-CORP01 and ISEPAN-CORP02 both has dns of each site, and are resolvable either way.&lt;/P&gt;&lt;P&gt;Deployment:&lt;/P&gt;&lt;P&gt;I've imported each PAN their respective certificate chain on the trusted certificate.&lt;BR /&gt;I've successfully deployed the PANs as primary and secondary node under two different domains.&lt;/P&gt;&lt;P&gt;Follow up Question:&lt;/P&gt;&lt;P&gt;3. Should I import the 2nd Site's Certificate chain as well on the Primary Node.&lt;/P&gt;&lt;P&gt;- I've noticed that after deploying it as Primary and secondary, the trusted certificates did not contain the ISEPAN-CORP02's trusted certificate chain I imported before it became as secondary.&lt;/P&gt;&lt;P&gt;4. Will this setup pose any problems in the future? (Two separate domained ISEPAN on each site deployed as Primary and Secondary)&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 04:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-2-separate-cisco-ise-deployment-configurations-into-a-new/m-p/4117128#M561649</guid>
      <dc:creator>jj2048</dc:creator>
      <dc:date>2020-07-12T04:20:37Z</dc:date>
    </item>
  </channel>
</rss>

