<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Neno Spasov:You are in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498524#M89922</link>
    <description>&lt;P&gt;Hi Neno Spasov:&lt;/P&gt;&lt;P&gt;You are correct! So the CA enviroment is not must needed.However DNS record is a must be.&lt;/P&gt;&lt;P&gt;I want to rate your answer as the correct answer,but when I click the correct answer,the system indicate it's an invlaid answer,I'll try to find how to rate your answer as the correct answer.&lt;/P&gt;&lt;P&gt;Anyway Thansk!&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jun 2014 23:51:52 GMT</pubDate>
    <dc:creator>xuekai zhang</dc:creator>
    <dc:date>2014-06-16T23:51:52Z</dc:date>
    <item>
      <title>ISE HA Deployment prerequisite issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498521#M89919</link>
      <description>&lt;P&gt;I encountered this HA node deployment issue.Actually , I finished this feature with the enviroment of CA and DNS.However,Can I finish ISE‘s HA deployment without CA and DNS.&lt;/P&gt;&lt;P&gt;When I adding the second ISE node to the first one,I fill the blank with the second ISE's server IP address,the system notification indicates that Unalbe to authenticate xxx.Please check server and CA certificate configuration and try agian.&lt;/P&gt;&lt;P&gt;After that notification, I deploy the CA and DNS server.Also I signed the certificate and install the root CA for both ISE nodes,DNS records also be done.After that,I fill the blank with second ISE's FQDN and administration account .It can be done successfully.&lt;/P&gt;&lt;P&gt;So if my enviroment doesn't have CA and DNS.Does that mean I can't finish ISE'S HA function?&lt;/P&gt;&lt;P&gt;Any help or suggestion will be appreciated!&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498521#M89919</guid>
      <dc:creator>xuekai zhang</dc:creator>
      <dc:date>2019-03-11T04:48:00Z</dc:date>
    </item>
    <item>
      <title>Hello-DNS: Your ISE nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498522#M89920</link>
      <description>&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DNS:&amp;nbsp;&lt;/STRONG&gt;Your ISE nodes must be resolvable via DNS before they can be registered in a "cluster." In fact, I think the DNS is also required before the install script would complete.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CA:&amp;nbsp;&lt;/STRONG&gt;On the other hand, a CA is not required. If you don't have a CA you can use the self-signed ISE certificates. You will need to import the self-signed certs to "Certificate Store" in ISE&lt;/P&gt;&lt;P&gt;Hope this answers your question(s)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 01:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498522#M89920</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-06-16T01:23:42Z</dc:date>
    </item>
    <item>
      <title>Hi,You can not do ISE HA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498523#M89921</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:16px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;Hi,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:16px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;You can not do ISE HA deployment without CA and DNS.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:16px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;STRONG&gt;DNS :&amp;nbsp;&lt;/STRONG&gt;&lt;B style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.222222328186035px; line-height: normal; text-indent: -28.80000114440918px;"&gt;&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.222222328186035px; line-height: normal; text-indent: -28.80000114440918px;" width="1" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; text-indent: -28.80000114440918px;"&gt;When you upgrade a complete Cisco ISE deployment, Domain Name System (DNS) server resolution is mandatory; otherwise the upgrade will fail.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:16px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;STRONG&gt;CA : &lt;/STRONG&gt;&amp;nbsp;During&amp;nbsp;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; text-indent: -0.56in;"&gt;the split deployment upgrade, before you register the nodes to the new primary Administration node, you must do the following:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:16px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; text-indent: -0.25in;"&gt;-If you use self-signed certificate, you must import the self-signed certificate of all nodes to your new primary Administration node.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:16px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; text-indent: -0.25in;"&gt;-If you use different CA certificates for the nodes, you must import all the CA certificates into the new primary Administration node.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:16px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; text-indent: -0.25in;"&gt;-If you use the same CA certificate for the nodes, you must import that CA certificate into the new primary Administration node.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 12:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498523#M89921</guid>
      <dc:creator>abwahid</dc:creator>
      <dc:date>2014-06-16T12:54:16Z</dc:date>
    </item>
    <item>
      <title>Hi Neno Spasov:You are</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498524#M89922</link>
      <description>&lt;P&gt;Hi Neno Spasov:&lt;/P&gt;&lt;P&gt;You are correct! So the CA enviroment is not must needed.However DNS record is a must be.&lt;/P&gt;&lt;P&gt;I want to rate your answer as the correct answer,but when I click the correct answer,the system indicate it's an invlaid answer,I'll try to find how to rate your answer as the correct answer.&lt;/P&gt;&lt;P&gt;Anyway Thansk!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 23:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498524#M89922</guid>
      <dc:creator>xuekai zhang</dc:creator>
      <dc:date>2014-06-16T23:51:52Z</dc:date>
    </item>
    <item>
      <title>Hi abwhaid:Thanks!Your replay</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498525#M89923</link>
      <description>&lt;P&gt;Hi abwhaid:&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Your replay is helpful to me!&lt;/P&gt;&lt;P&gt;I can do ISE's HA with DNS enviroment,without CA server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 23:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498525#M89923</guid>
      <dc:creator>xuekai zhang</dc:creator>
      <dc:date>2014-06-16T23:54:30Z</dc:date>
    </item>
    <item>
      <title>Glad I was able to help!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498526#M89924</link>
      <description>&lt;P&gt;Glad I was able to help! Thanks for the rating! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 00:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498526#M89924</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-06-17T00:00:44Z</dc:date>
    </item>
    <item>
      <title>Hi abwahid:After the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498527#M89925</link>
      <description>&lt;P&gt;Hi abwahid:&lt;/P&gt;&lt;P&gt;After the deployment can these two nodes work normaly withou DNS.&lt;/P&gt;&lt;P&gt;Can I finish this feature just through IP address,not in the method of FQDN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 08:07:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498527#M89925</guid>
      <dc:creator>xuekai zhang</dc:creator>
      <dc:date>2014-06-18T08:07:05Z</dc:date>
    </item>
    <item>
      <title>Hi Neno Spasov:After the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498528#M89926</link>
      <description>&lt;P&gt;Hi Neno Spasov:&lt;/P&gt;&lt;P&gt;After the deployment can these two nodes work normaly withou DNS.&lt;/P&gt;&lt;P&gt;Can I finish this feature just through IP address,not in the method of FQDN.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 08:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-deployment-prerequisite-issue/m-p/2498528#M89926</guid>
      <dc:creator>xuekai zhang</dc:creator>
      <dc:date>2014-06-18T08:08:23Z</dc:date>
    </item>
  </channel>
</rss>

