<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic That is good to hear Joe! Did in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585472#M75388</link>
    <description>&lt;P&gt;That is good to hear Joe! Did you complete the hostname changes without having to perform any additional tasks or or..?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sat, 10 Jan 2015 23:56:01 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2015-01-10T23:56:01Z</dc:date>
    <item>
      <title>Cisco ISE change Domain Name</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585465#M75368</link>
      <description>&lt;P&gt;Our ISE deployment was setup with our internal domain name of csi.corp, when presenting the guest CWA this is the domain name the is presented to&lt;/P&gt;&lt;P&gt;the guest. &amp;nbsp;We would like for this to be out public domain and a valid certificate. &amp;nbsp;From what I have gathered the web portal https certificate must contain the FQDN of the ISE node, therefore I would need to change the domain name on the server(s). &amp;nbsp;I have found posts that some have changed the domain name after deployment without any adverse results, is this possible? &amp;nbsp;We are currently integrated with our corp AD and able to utilize this the EAP authentications. &amp;nbsp;We have 2 nodes in our deployment, is it possible to change the domain name to our public domain without a rebuild?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585465#M75368</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2019-03-11T05:18:30Z</dc:date>
    </item>
    <item>
      <title>Hi Joe-Yes, what you are</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585466#M75371</link>
      <description>&lt;P&gt;Hi Joe-&lt;/P&gt;&lt;P&gt;Yes, what you are describing here is possible and I have done it in the past. You can have ISE joined (in the GUI)&amp;nbsp;to an internal domain (company.local) while the hostname and domain configuration in CLI be set to the public domain (company.com). ISE will require a restart so plan on doing this during a maintenance window. You will also have to do some tweaking with your DNS in order to allow hosts on the "inside" of your network to be able to resolve "ise.company.com" to a private IP.&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2014 20:07:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585466#M75371</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-29T20:07:31Z</dc:date>
    </item>
    <item>
      <title>Thanks for the reply, Since</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585467#M75375</link>
      <description>&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since there are 2 servers in the deloyment, should I simply start with the first node, no out the domain name as it is now and replace it with the public, then restart the appliance, do the same secondary?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2014 20:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585467#M75375</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2014-12-29T20:10:46Z</dc:date>
    </item>
    <item>
      <title>Yes, anything that can</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585468#M75378</link>
      <description>&lt;P&gt;Yes, anything that can minimize downtime. Btw, I have not done this during production time so be aware that changing the domain and hostname will probably invalidate the currently installed certificate, thus it will break the inter-cluster communication between the two nodes. Again, that should not be a big deal but just something to keep in mind.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2014 20:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585468#M75378</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-29T20:21:42Z</dc:date>
    </item>
    <item>
      <title>TAC has come back stating</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585469#M75382</link>
      <description>&lt;P&gt;TAC has come back stating that a domain name change isn't needed if we request the certificate the following way:&lt;/P&gt;&lt;P&gt;Here is a example, in the wild card certificate please ensure you have SAN field set to:&lt;BR /&gt;DNS name: isenode1.local.corp&lt;BR /&gt;DNS name: isenode2.local.corp&lt;BR /&gt;DNS name: *.public.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wouldn't expect that a Registrar would provide this certificate, am I incorrect?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2015 14:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585469#M75382</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2015-01-02T14:00:25Z</dc:date>
    </item>
    <item>
      <title>Hmm, unless something has</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585470#M75385</link>
      <description>&lt;P&gt;Hmm, unless something has changed I don't believe this would work because:&lt;/P&gt;&lt;P&gt;- Even though the CN doesn't have to be an exact match of the FQDN, I believe that the domain suffix in the CN still must match the domain suffix in the FQDN. So you can have many different values and domains in the SAN fields but the domain in the CN field must match the domain specified in the FQDN.&amp;nbsp;I don't have any certs to test this with now but I am pretty sure that even though the CSR generation would work, the process will fail when trying to import the cert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Is ".local.corp" a public domain? It doesn't sound like it but perhaps it is &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; However, if it is not, then many public CAs won't issue you a public certificate for a private domain. You can definitely give it a try and see what they say &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Let me know what you find out!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 08:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585470#M75385</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-01-05T08:18:21Z</dc:date>
    </item>
    <item>
      <title>To update, I was able to</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585471#M75386</link>
      <description>&lt;P&gt;To update, I was able to change the domain name on both servers without issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2015 22:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585471#M75386</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2015-01-09T22:14:03Z</dc:date>
    </item>
    <item>
      <title>That is good to hear Joe! Did</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585472#M75388</link>
      <description>&lt;P&gt;That is good to hear Joe! Did you complete the hostname changes without having to perform any additional tasks or or..?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jan 2015 23:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585472#M75388</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-01-10T23:56:01Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585473#M75390</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can you tell &amp;nbsp;how did you do that&amp;nbsp;&amp;nbsp;?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 04:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585473#M75390</guid>
      <dc:creator>wyfy-2015</dc:creator>
      <dc:date>2016-04-07T04:02:52Z</dc:date>
    </item>
    <item>
      <title>I logged into the cli via ssh</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585474#M75391</link>
      <description>&lt;P&gt;I logged into the cli via ssh and did a no ip domain-name olddomain.com&lt;/P&gt;
&lt;P&gt;then&lt;/P&gt;
&lt;P&gt;ip domain-name newdomain.com&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;restarted appliance completely.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 13:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585474#M75391</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2016-04-07T13:30:37Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585475#M75392</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;And what about the eap and admin certificate , you are using the certificate from your internal CA . &amp;nbsp;I believe that &amp;nbsp; for that you are using &amp;nbsp;internal CA and for portal you are using &amp;nbsp;external CA . It would be a great help if you brief about that&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 16:07:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585475#M75392</guid>
      <dc:creator>wyfy-2015</dc:creator>
      <dc:date>2016-04-07T16:07:11Z</dc:date>
    </item>
    <item>
      <title>You are correct, we are using</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585476#M75393</link>
      <description>&lt;P&gt;You are correct, we are using a certificate signed by our internal CA for EAP connections and one from an external CA for admin and portal access.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 16:10:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585476#M75393</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2016-04-07T16:10:09Z</dc:date>
    </item>
    <item>
      <title>Thank you Joe and Special</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585477#M75394</link>
      <description>&lt;P&gt;Thank you Joe and Special thanks to Neno .Without Neno ISE discussion is not&lt;/P&gt;
&lt;P&gt;complete &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 19:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585477#M75394</guid>
      <dc:creator>wyfy-2015</dc:creator>
      <dc:date>2016-04-07T19:22:58Z</dc:date>
    </item>
    <item>
      <title>Wow, this is an old thread</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585478#M75395</link>
      <description>&lt;P&gt;Wow, this is an old thread but I am glad that it is still providing help to others &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;wyfy-2015 - Thank you for the compliment!&lt;/P&gt;
&lt;P&gt;joeharb - Thank you for taking the time to come back and post info about this (+5 from me as well).&lt;/P&gt;
&lt;P&gt;Now, if this issue was resolved, we should mark the thread as "answered" &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 06:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/2585478#M75395</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-08T06:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: You are correct, we are using</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/4403184#M567301</link>
      <description>&lt;P&gt;I have a similar issue. Just to clarify, what did you need to change to migrate from using an internal cert for admin and portal? Just change the domain name on each ISE node, reboot and apply the public certificate? Are you using a wild card certificate?&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 15:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-change-domain-name/m-p/4403184#M567301</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2021-05-14T15:51:43Z</dc:date>
    </item>
  </channel>
</rss>

