<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Affects of Changing the Domain Name in ISE CLI in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227009#M593295</link>
    <description>&lt;A href="https://community.cisco.com/t5/security-blogs/reset-ise-host-os-config-with-a-single-cli/ba-p/3660180" target="_blank"&gt;https://community.cisco.com/t5/security-blogs/reset-ise-host-os-config-with-a-single-cli/ba-p/3660180&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Wed, 20 Nov 2024 22:58:53 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2024-11-20T22:58:53Z</dc:date>
    <item>
      <title>Affects of Changing the Domain Name in ISE CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5226964#M593290</link>
      <description>&lt;P&gt;I have a customer that has 2 ISE nodes 3.3 in a deployment.&amp;nbsp; The nodes are VMs.&amp;nbsp; When the nodes were originally configured they used a domain name that they don't really use anymore.&amp;nbsp; Now they want to change the domain name in the CLI of the ISE nodes to their current domain name.&amp;nbsp; (i.e. from abc.com to xyz.com).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They use an CA that is internal to their organization.&amp;nbsp; The current admin/eap/radius dtls certificate has isenode1.abc.com, isenode2.abc.com in the SANs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They've generated a new CSR with SANs containing isenode1.abc.com, isenode2.abc.com, isenode1.xyz.com and isenode2.xyz.com.&lt;/P&gt;
&lt;P&gt;After they bind the new cert to the CSR and get it installed on both nodes, do they need to deregister the secondary node from the deployment prior to changing the domain name in the CLI?&lt;/P&gt;
&lt;P&gt;Will changing the domain name affect the current AD Join?&lt;/P&gt;
&lt;P&gt;Is there anything else that might be affected?&lt;/P&gt;
&lt;P&gt;Does anyone have links to documentation for this process?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 19:58:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5226964#M593290</guid>
      <dc:creator>cherie13653</dc:creator>
      <dc:date>2024-11-20T19:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Affects of Changing the Domain Name in ISE CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5226997#M593293</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Yes, since the DNS name will change.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Yes, hostname changes require AD re-join&lt;/LI&gt;
&lt;LI&gt;Services will restart&lt;/LI&gt;
&lt;LI&gt;Use reset-config&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 20 Nov 2024 22:01:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5226997#M593293</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-11-20T22:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Affects of Changing the Domain Name in ISE CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227004#M593294</link>
      <description>&lt;P&gt;I'm not sure I understand #4 use reset-config.&amp;nbsp;&amp;nbsp; This is in the cli when you type 'configure application ise'??&amp;nbsp; Do we do that prior to changing the domain-name of after?&amp;nbsp; What is that command doing?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 22:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227004#M593294</guid>
      <dc:creator>cherie13653</dc:creator>
      <dc:date>2024-11-20T22:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Affects of Changing the Domain Name in ISE CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227009#M593295</link>
      <description>&lt;A href="https://community.cisco.com/t5/security-blogs/reset-ise-host-os-config-with-a-single-cli/ba-p/3660180" target="_blank"&gt;https://community.cisco.com/t5/security-blogs/reset-ise-host-os-config-with-a-single-cli/ba-p/3660180&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Nov 2024 22:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227009#M593295</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-11-20T22:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Affects of Changing the Domain Name in ISE CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227015#M593296</link>
      <description>&lt;P&gt;historically, changing IP addressing or hostname in ISE was dark magic with the potential of causing issues, and with the introduction of the "reset-config" command in ISE 2.1, it became the recommended approach when changing IP address or hostname.&lt;/P&gt;
&lt;P&gt;But now, if you look at the ISE 3.3 admin guide, at the bottom of the "Deployment of ISE" section, you'll see a notice/guideline on changing the hostname using the "hostname" command.&lt;BR /&gt;(&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3/b_ISE_admin_33_deployment.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3/b_ISE_admin_33_deployment.html&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;You will also see in the same guide that the node must be standalone.&lt;/P&gt;
&lt;SECTION id="ID686__prereq_7BA93D4D02DF4F698BCCFF6A6B5B84BA" class="section prereq p"&gt;
&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;EM&gt;"If a Cisco&amp;nbsp;ISE&amp;nbsp;node is a part of a&amp;nbsp;distributed&amp;nbsp;deployment, you must first remove it from the deployment and ensure that it is a standalone node."&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p B1_Body1-F9CE5028"&gt;You can find additional information on the "reset-config" command:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/cli_guide/b_ise_CLI_Reference_Guide_33/b_ise_CLIReferenceGuide_33_chapter_01.html#wp1520224057" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/cli_guide/b_ise_CLI_Reference_Guide_33/b_ise_CLIReferenceGuide_33_chapter_01.html#wp1520224057&lt;/A&gt;&lt;/P&gt;
&lt;/SECTION&gt;
&lt;P class="p B1_Body1-F9CE5028"&gt;And you should also remove it from AD, and then re-join after changing the hostname.&lt;/P&gt;
&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;EM&gt;"Updating the hostname will cause any certificate using the old hostname to become invalid. A new self-signed certificate using the new hostname will be generated now for use with HTTPS/EAP. If CA-signed certificates are used on this node, import the new ones with the correct hostname. In addition, if this node is part of an AD domain, delete any AD memberships before proceeding."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 23:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227015#M593296</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2024-11-20T23:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Affects of Changing the Domain Name in ISE CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227023#M593297</link>
      <description>&lt;P&gt;Thank you so much.&amp;nbsp; I will check that out.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 00:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227023#M593297</guid>
      <dc:creator>cherie13653</dc:creator>
      <dc:date>2024-11-21T00:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Affects of Changing the Domain Name in ISE CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227250#M593300</link>
      <description>&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 14:03:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/affects-of-changing-the-domain-name-in-ise-cli/m-p/5227250#M593300</guid>
      <dc:creator>cherie13653</dc:creator>
      <dc:date>2024-11-21T14:03:03Z</dc:date>
    </item>
  </channel>
</rss>

