<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse DNS with Context Visibility in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/4628839#M575354</link>
    <description>&lt;P&gt;Hi !!&lt;BR /&gt;I came across you post to find out to configure reverse DNS pointer ... my question is probably irrelevant to your post, but seriously how to configure a reverse DNS ? is it the same for " ip name-server x.x.x.x" ?? Im trying to do it from CLI and I can see its already working&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin# nslookup MYPC1.MYDOMAIN.LOCAL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Trying "MYPC1.MYDOMAIN.LOCAL"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 15412&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; QUESTION SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;MYPC1.MYDOMAIN.LOCAL. IN ANY&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; ANSWER SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;MYPC1.MYDOMAIN.LOCAL. 1200 IN A 10.155.20.56&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Received 55 bytes from 10.150.0.11#53 in 5 ms&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin#&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin# nslookup 10.155.20.56&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Trying "56.20.155.10.in-addr.arpa"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 35360&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; QUESTION SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;56.20.155.10.in-addr.arpa. IN PTR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; ANSWER SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;56.20.155.10.in-addr.arpa. 900 IN PTR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin# nslookup 10.155.20.56&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Trying "56.20.155.10.in-addr.arpa"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 35360&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; QUESTION SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;56.20.155.10.in-addr.arpa. IN PTR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; ANSWER SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;56.20.155.10.in-addr.arpa. 900 IN PTR MYPC1.MYDOMAIN.LOCAL.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Received 78 bytes from 10.150.0.11#53 in 6 ms&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin#&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Received 78 bytes from 10.150.0.11#53 in 6 ms&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin#&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Thu, 09 Jun 2022 12:07:37 GMT</pubDate>
    <dc:creator>Radwan3000</dc:creator>
    <dc:date>2022-06-09T12:07:37Z</dc:date>
    <item>
      <title>Reverse DNS with Context Visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533503#M518317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer that has installed multiple distributed ISE deployments across the nation. Each deployment contains nodes from several different states and my customer has strong concerns with configuring reverse DNS pointer records across their nationwide infrastructure which includes many separate subnets. All total, there are 270 nodes. Configuring Reverse DNS is recommended in the in ISE admin guides but without configuring it, there does not seem to be an impact to normal RADIUS authentications, replication between nodes or joining nodes to the deployment. However, if we try to examine endpoints or devices under the context visibility menu of 2.2 patch 5, we receive the following error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unable to load Context Visibility page. Ensure that reverse DNS lookup is configured for all Cisco ISE nodes in your distributed deployment in the DNS server. Exception: blocked by: [SERVICE_UNAVAILABLE/1/state not recovered / initialized]; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We further document the need for reverse DNS in the release notes: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/release_notes/ise22_rn.html#pgfId-700468" rel="nofollow" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/release_notes/ise22_rn.html#pgfId-700468&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additionally, I understand that elastic search needs reverse DNS configured for each host in the deployment in order to work properly but &lt;STRONG&gt;do we have any enhancements on the roadmap whereby we won't rely on reverse DNS? Are there any other solutions apart from configuring reverse DNS?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2018 20:03:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533503#M518317</guid>
      <dc:creator>Thomas Wall</dc:creator>
      <dc:date>2018-01-25T20:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse DNS with Context Visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533504#M518318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may go ahead and file one, if you like. Please discuss any roadmap items directly with our PM team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jan 2018 01:26:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533504#M518318</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-26T01:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse DNS with Context Visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533505#M518319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, are you aware of any solutions outside of configuring reverse DNS pointer records? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jan 2018 16:34:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533505#M518319</guid>
      <dc:creator>Thomas Wall</dc:creator>
      <dc:date>2018-01-26T16:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse DNS with Context Visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533506#M518320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The current implementation mandates DNS PTR records for the ISE admin nodes for the underlying data store of context visibility. There is no other way around for ISE deployments with two PANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps, you may limit the resolution for the DNS servers used by the two PANs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jan 2018 16:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533506#M518320</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-26T16:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse DNS with Context Visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533507#M518321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your inputs and speedy replies. I will reach out to the ISE PM team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jan 2018 17:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/3533507#M518321</guid>
      <dc:creator>Thomas Wall</dc:creator>
      <dc:date>2018-01-26T17:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse DNS with Context Visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/4628839#M575354</link>
      <description>&lt;P&gt;Hi !!&lt;BR /&gt;I came across you post to find out to configure reverse DNS pointer ... my question is probably irrelevant to your post, but seriously how to configure a reverse DNS ? is it the same for " ip name-server x.x.x.x" ?? Im trying to do it from CLI and I can see its already working&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin# nslookup MYPC1.MYDOMAIN.LOCAL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Trying "MYPC1.MYDOMAIN.LOCAL"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 15412&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; QUESTION SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;MYPC1.MYDOMAIN.LOCAL. IN ANY&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; ANSWER SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;MYPC1.MYDOMAIN.LOCAL. 1200 IN A 10.155.20.56&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Received 55 bytes from 10.150.0.11#53 in 5 ms&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin#&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin# nslookup 10.155.20.56&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Trying "56.20.155.10.in-addr.arpa"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 35360&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; QUESTION SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;56.20.155.10.in-addr.arpa. IN PTR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; ANSWER SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;56.20.155.10.in-addr.arpa. 900 IN PTR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin# nslookup 10.155.20.56&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Trying "56.20.155.10.in-addr.arpa"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 35360&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; QUESTION SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;56.20.155.10.in-addr.arpa. IN PTR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;;; ANSWER SECTION:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;56.20.155.10.in-addr.arpa. 900 IN PTR MYPC1.MYDOMAIN.LOCAL.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Received 78 bytes from 10.150.0.11#53 in 6 ms&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin#&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Received 78 bytes from 10.150.0.11#53 in 6 ms&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;ISE01/admin#&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 09 Jun 2022 12:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reverse-dns-with-context-visibility/m-p/4628839#M575354</guid>
      <dc:creator>Radwan3000</dc:creator>
      <dc:date>2022-06-09T12:07:37Z</dc:date>
    </item>
  </channel>
</rss>

