03-15-2023 11:44 PM
Hi ALL
We ae planning to change the domain name on ISE with setup running on two ISE nodes. We have ISE nodes names as ise1.xyzindia.xyz.org and ise2.xyzindia.xyz.org . We are changing it to ise1.xyz.org and ise2.xyz.org. Trying to generate new CSR with new domain name to get it signed by CA prior changes but getting error. May I know what steps needed to be done as I came through some where that these two nodes should be in standalone for generating new CSR , domain-name change and changing the AD server IP as well . is my understanding right and any steps if some body can brief it will be helpful...ISE running on version 3.0
Solved! Go to Solution.
03-16-2023 02:01 PM
As stated in the Admin Guide, these changes require the node to be in Standalone mode. The CLI Guide also provides info on the impact of this change.
The following steps would be required:
03-16-2023 03:01 AM
You can change the domain of ISE by using the CLI command "ip domain-name" but I don't recall if it requires a reboot.
Regarding the certificate, a new self-signed certificate will be issued for each server, once that is done you can generate new CSRs for your ISE nodes to get a CA signed certificate.
Make sure to do the above in a maintenance window, and you can start by one node to avoid impacting both nodes at the same time.
03-16-2023 01:54 PM
I don't know if changing the domain name whilst the nodes are in an ISE Cube (Deployment) will work cleanly. Perhaps it will - I have never done this.
If this were my deployment, I would deregister the nodes as a first step. Even after de-registration, the services will still work e.g. RADIUS TACACS+) - but each node will be a standalone node. Once the node is standalone and applications are running, you can start the CLI changes. Make the changes on all of the nodes. And then create CSRs for the Admin role on each node. Install the new Admin Cert on each node. Then promote the Primary PAN to Primary. And then register all the standalone nodes back in. In my opinion that is the cleanest way to do it - but it involves more work.
03-16-2023 02:01 PM
As stated in the Admin Guide, these changes require the node to be in Standalone mode. The CLI Guide also provides info on the impact of this change.
The following steps would be required:
05-10-2023 11:20 AM
Hi All,
Thanks for your suggestions. We followed the below steps :
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide