<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Replacing AD and DNS servers in Umbrella VA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replacing-ad-and-dns-servers-in-umbrella-va/m-p/4903577#M1103366</link>
    <description>&lt;P&gt;I have a couple other posts on this topic for ISE and FMC, but have decided to split them up so not to mix up answers for the different technologies.&lt;/P&gt;&lt;P&gt;The server team will be replacing the existing AD servers with new ones shortly.&amp;nbsp; The new servers have been added to the network using new hostnames and IPs and will live side by side the old servers until everything else is confirmed OK at which point the old servers will be turned off.&amp;nbsp; The new servers will then have their IPs updated to that of the old servers.&amp;nbsp; These servers are also the DNS servers for the network.&lt;/P&gt;&lt;P&gt;Since the ADs are also the DNS servers in the network, and will be eventually inheriting the IP addresses of the old AD servers I would assume that DNS lookups via the Umbrella VA's would not be affected.&amp;nbsp; let me know if my understanding is correct on this matter.&lt;/P&gt;&lt;P&gt;These Umbrella VA's are also integrated with AD to get user context in the logs, and this is where I get a little uncertain.&amp;nbsp; Can the server team just change the IP of the new AD servers to that of the old servers and then run the Umbrella AD script on the server and everything will be OK?&amp;nbsp; Or would we need to remove the old AD servers from Cisco Umbrella Deployments &amp;gt; Configuration &amp;gt; Sites and Active Directory and then add them back?&lt;/P&gt;&lt;P&gt;Any other Gotcha's?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2023 06:42:32 GMT</pubDate>
    <dc:creator>BoomShakaLak</dc:creator>
    <dc:date>2023-08-11T06:42:32Z</dc:date>
    <item>
      <title>Replacing AD and DNS servers in Umbrella VA</title>
      <link>https://community.cisco.com/t5/network-security/replacing-ad-and-dns-servers-in-umbrella-va/m-p/4903577#M1103366</link>
      <description>&lt;P&gt;I have a couple other posts on this topic for ISE and FMC, but have decided to split them up so not to mix up answers for the different technologies.&lt;/P&gt;&lt;P&gt;The server team will be replacing the existing AD servers with new ones shortly.&amp;nbsp; The new servers have been added to the network using new hostnames and IPs and will live side by side the old servers until everything else is confirmed OK at which point the old servers will be turned off.&amp;nbsp; The new servers will then have their IPs updated to that of the old servers.&amp;nbsp; These servers are also the DNS servers for the network.&lt;/P&gt;&lt;P&gt;Since the ADs are also the DNS servers in the network, and will be eventually inheriting the IP addresses of the old AD servers I would assume that DNS lookups via the Umbrella VA's would not be affected.&amp;nbsp; let me know if my understanding is correct on this matter.&lt;/P&gt;&lt;P&gt;These Umbrella VA's are also integrated with AD to get user context in the logs, and this is where I get a little uncertain.&amp;nbsp; Can the server team just change the IP of the new AD servers to that of the old servers and then run the Umbrella AD script on the server and everything will be OK?&amp;nbsp; Or would we need to remove the old AD servers from Cisco Umbrella Deployments &amp;gt; Configuration &amp;gt; Sites and Active Directory and then add them back?&lt;/P&gt;&lt;P&gt;Any other Gotcha's?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 06:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-ad-and-dns-servers-in-umbrella-va/m-p/4903577#M1103366</guid>
      <dc:creator>BoomShakaLak</dc:creator>
      <dc:date>2023-08-11T06:42:32Z</dc:date>
    </item>
    <item>
      <title>Based on the information I found, to handle the transitio...</title>
      <link>https://community.cisco.com/t5/network-security/replacing-ad-and-dns-servers-in-umbrella-va/m-p/4909647#M1103686</link>
      <description>Based on the information I found, to handle the transition of servers in your given situation, the process might involve these steps:&lt;BR /&gt;&lt;BR /&gt;1. Remove old AD servers from Cisco Umbrella Deployments ) Configuration ) Sites and Active Directory. This makes sure that the old servers are no longer associated with the Umbrella deployment.&lt;BR /&gt;&lt;BR /&gt;2. Change the IP of the new AD servers to match the IP of the old servers (if necessary). This step can be performed by the server team to ensure consistency in the network configuration.&lt;BR /&gt;&lt;BR /&gt;3. Install the AD connector on the domain controller of the specific domain. The AD connector is responsible for syncing the Active Directory information with Cisco Umbrella.&lt;BR /&gt;&lt;BR /&gt;By following these steps, the new AD servers should be correctly integrated into the Cisco Umbrella deployment, and any changes made to the IP addresses will be reflected in the configuration. This should not affect your DNS lookups via the Umbrella VA's.&lt;BR /&gt;&lt;BR /&gt;However, since this process is complex and involves critical network elements, I strongly recommend reaching out to Cisco support or referring to the official Cisco documentation to ensure that every step is done correctly and your network security is not compromised.</description>
      <pubDate>Tue, 22 Aug 2023 09:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-ad-and-dns-servers-in-umbrella-va/m-p/4909647#M1103686</guid>
      <dc:creator>Cisco_Virtual_Engineer</dc:creator>
      <dc:date>2023-08-22T09:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing AD and DNS servers in Umbrella VA</title>
      <link>https://community.cisco.com/t5/network-security/replacing-ad-and-dns-servers-in-umbrella-va/m-p/4909938#M1103690</link>
      <description>&lt;P&gt;The bot got it mostly right.&lt;/P&gt;
&lt;P&gt;I would add that you might want to add the temporary server addresses in your VA configuration so that they see them as valid DNS servers for internal lookups.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 13:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-ad-and-dns-servers-in-umbrella-va/m-p/4909938#M1103690</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-08-22T13:06:12Z</dc:date>
    </item>
  </channel>
</rss>

