cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

3034
Views
6
Helpful
3
Replies
Highlighted
Cisco Employee

15 Character limit for hostname

I've seen some references to a 15 character hostname limit in ISE when connecting to  AD. Is this still the case? Something to do with Centrify? Also there is this bug id CSCtx57316

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Cisco Employee

According to the ISE 2.4 install guide:

Hostname

Must not exceed 15 characters. Valid characters include alphanumerical (A–Z, a–z, 0–9), and the hyphen (-). The first character must be a letter.

Note  

We recommend that you use lowercase letters to ensure that certificate authentication in Cisco ISE is not impacted by minor differences in certificate-driven verifications. You cannot use "localhost" as hostname for a node.

Cisco Identity Services Engine Installation Guide, Release 2.4 - Install Cisco ISE [Cisco Identity Services Engine] - C…

View solution in original post

3 REPLIES 3
Highlighted
Cisco Employee

According to the ISE 2.4 install guide:

Hostname

Must not exceed 15 characters. Valid characters include alphanumerical (A–Z, a–z, 0–9), and the hyphen (-). The first character must be a letter.

Note  

We recommend that you use lowercase letters to ensure that certificate authentication in Cisco ISE is not impacted by minor differences in certificate-driven verifications. You cannot use "localhost" as hostname for a node.

Cisco Identity Services Engine Installation Guide, Release 2.4 - Install Cisco ISE [Cisco Identity Services Engine] - C…

View solution in original post

Highlighted

For a more detailed response this boils down to active directory, there is a confusion with computer objects when the exceed 15 characters.

Issues with computer objects and netbios so if the first 15 characters are the same then you have all sorts of issues with multiple nodes with AD communication. During my days with TAC this was a common issue when ACS 5 first came out.

https://support.microsoft.com/en-us/help/909264/naming-conventions-in-active-directory-for-computers-domains-sites-and

Highlighted
Cisco Employee

Since ISE 1.3, it's possible to exceed 15 characters but it's still better to limit to 15 characters.

Per DE, ISE 1.3+ search for accounts using both DNS and short name when joining. The limitation in ISE 1.2 or prior was due to the 3rd-party AD runtime so it might be OK with longer ones although not exhaustively checked.

Content for Community-Ad