08-28-2017 05:32 PM
Hi
Now that my fully distributed ISE 2.2 deployment is working quite nicely, my customer has decided that the DNS domain has to be changed
I am slightly dreading this because, as I understand, it will involve the de-registration of all joined nodes, and a few application restarts. Has anyone in this forum done this before?
The Admin certs will be re-issued from the same PKI - so I won't need to install a different chain of trust.
The only service being offered thus far is Sponsored Guest and some TACACS+. I can afford to be somewhat disruptive (i.e. down time).
Here are the steps as I currently see them
Open questions:
thanks for any pearls of wisdom
Arne
Solved! Go to Solution.
08-28-2017 07:15 PM
The AD domain name of the existing joint point can not be changed. If DNS change also impact the AD domain, then you will need to create a new join point.
Unfortunately, there is no short-cut. The CLI should prevent you from updating the domain name, if not standalone.
In case the new domains are mainly for guest services, then it's possible to keep the existing domain and add static hostname for guest redirects.
08-28-2017 07:15 PM
The AD domain name of the existing joint point can not be changed. If DNS change also impact the AD domain, then you will need to create a new join point.
Unfortunately, there is no short-cut. The CLI should prevent you from updating the domain name, if not standalone.
In case the new domains are mainly for guest services, then it's possible to keep the existing domain and add static hostname for guest redirects.
08-28-2017 08:43 PM
Thanks for the feedback.
I have two DC's and I am thinking of doing a smooth migration. See diagram below.
After I have created my new deployment in DC2 as shown below , will I lose all the Endpoints in the Endpoint Identity Groups?
Essentially, this is where are all my authenticated Guest users' MAC addresses are kept. I would like to save and restore this. Can I import/export Endpoint Identities?
08-28-2017 10:36 PM
If all nodes in DC2 are currently in the same deployment as those in DC1, then the configuration are there after de-registration.
If using export/import endpoints, not all attributes are preserved and neither are the guest accounts. Please ensure good backups and insert testings along the way.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide