cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6635
Views
6
Helpful
3
Replies

15 Character limit for hostname

greg2.0
Cisco Employee
Cisco Employee

I've seen some references to a 15 character hostname limit in ISE when connecting to  AD. Is this still the case? Something to do with Centrify? Also there is this bug id CSCtx57316

Thanks

1 Accepted Solution

Accepted Solutions

howon
Cisco Employee
Cisco Employee

According to the ISE 2.4 install guide:

Hostname

Must not exceed 15 characters. Valid characters include alphanumerical (A–Z, a–z, 0–9), and the hyphen (-). The first character must be a letter.

Note  

We recommend that you use lowercase letters to ensure that certificate authentication in Cisco ISE is not impacted by minor differences in certificate-driven verifications. You cannot use "localhost" as hostname for a node.

Cisco Identity Services Engine Installation Guide, Release 2.4 - Install Cisco ISE [Cisco Identity Services Engine] - C…

View solution in original post

3 Replies 3

howon
Cisco Employee
Cisco Employee

According to the ISE 2.4 install guide:

Hostname

Must not exceed 15 characters. Valid characters include alphanumerical (A–Z, a–z, 0–9), and the hyphen (-). The first character must be a letter.

Note  

We recommend that you use lowercase letters to ensure that certificate authentication in Cisco ISE is not impacted by minor differences in certificate-driven verifications. You cannot use "localhost" as hostname for a node.

Cisco Identity Services Engine Installation Guide, Release 2.4 - Install Cisco ISE [Cisco Identity Services Engine] - C…

For a more detailed response this boils down to active directory, there is a confusion with computer objects when the exceed 15 characters.

Issues with computer objects and netbios so if the first 15 characters are the same then you have all sorts of issues with multiple nodes with AD communication. During my days with TAC this was a common issue when ACS 5 first came out.

https://support.microsoft.com/en-us/help/909264/naming-conventions-in-active-directory-for-computers-domains-sites-and

hslai
Cisco Employee
Cisco Employee

Since ISE 1.3, it's possible to exceed 15 characters but it's still better to limit to 15 characters.

Per DE, ISE 1.3+ search for accounts using both DNS and short name when joining. The limitation in ISE 1.2 or prior was due to the 3rd-party AD runtime so it might be OK with longer ones although not exhaustively checked.