<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE DNS &amp; Syslog in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/4624360#M575191</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/133457"&gt;@stefan.tabell&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, but if I'm not mistake, this command (&lt;EM&gt;ise/admin(config)#&amp;nbsp;service cache enable ...&lt;/EM&gt;) is an option on &lt;STRONG&gt;ISE&amp;nbsp;2.7P3+&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jun 2022 21:27:14 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2022-06-03T21:27:14Z</dc:date>
    <item>
      <title>ISE DNS &amp; Syslog</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460871#M517027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #000000; font-size: 12pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;My customer has reported ISE making a DNS query every time it sends a syslog.&amp;nbsp; Doesn't seem desirable behavior, is this normal behavior or should I request they open a TAC case?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 12pt; font-family: Calibri, sans-serif;"&gt;&lt;EM style="font-size: 11pt;"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 12pt; font-family: Calibri, sans-serif;"&gt;&lt;EM style="font-size: 11pt;"&gt;It looks like ISE makes a DNS query for the syslog server prior to every syslog message.&amp;nbsp; In our environment, it looks like that means a new DNS request every 0.1 seconds from each server.&amp;nbsp; This is despite the DNS TTL for our syslog server being 900 seconds&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 12pt; font-family: Calibri, sans-serif;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 12pt; font-family: Calibri, sans-serif;"&gt;&lt;EM style="font-size: 11pt;"&gt;We'd probably prefer ISE to respect the DNS TTL (or at least something resembling it). &lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2018 18:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460871#M517027</guid>
      <dc:creator>jlaw2@cisco.com</dc:creator>
      <dc:date>2018-05-17T18:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS &amp; Syslog</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460872#M517028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me do some research internally &amp;amp; respond to you. If the customer can't wait, please request them to open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Krish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2018 22:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460872#M517028</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-05-17T22:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS &amp; Syslog</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460873#M517029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I consulted the DNS RFC &amp;amp; it says resource record 'may be cached' (read it as optionally cached) for the TTL time interval. So even if ISE is not honoring TTL, it is not a standard violation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible for your customer to try a couple of options - try a different DNS and/or add a static host entry to see if there is any change. If your customer wants to pursue this further, please request them to open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Krish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2018 15:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460873#M517029</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-05-18T15:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS &amp; Syslog</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460874#M517030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you confirm that ISE performs a DNS query prior to sending each syslog message?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 19:45:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/3460874#M517030</guid>
      <dc:creator>jlaw2@cisco.com</dc:creator>
      <dc:date>2018-05-24T19:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS &amp; Syslog</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/4624050#M575185</link>
      <description>&lt;P&gt;I understand that you can configure ISE to keep a DNS cache using the command "&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;service cache enable hosts ttl [ttl in seconds]". Trying this myself. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 12:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/4624050#M575185</guid>
      <dc:creator>stefan.tabell</dc:creator>
      <dc:date>2022-06-03T12:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE DNS &amp; Syslog</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/4624360#M575191</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/133457"&gt;@stefan.tabell&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, but if I'm not mistake, this command (&lt;EM&gt;ise/admin(config)#&amp;nbsp;service cache enable ...&lt;/EM&gt;) is an option on &lt;STRONG&gt;ISE&amp;nbsp;2.7P3+&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 21:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dns-syslog/m-p/4624360#M575191</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-03T21:27:14Z</dc:date>
    </item>
  </channel>
</rss>

