10-13-2019 10:37 PM
Hi All,
I have come across a distributed ISE design where the ISE deployment is provided as a hosted NAC solution for a client.
Question is, the ISE servers will have a FQDN from the host company but the certificates issued by the customer's CA will have their DNS/Domain appended to it. How would ISE will match this certificate and accepts it.
As far as I know ISE will look into the SAN extension of the Cert and if the SAN contains one or more DNS names, then one of the DNS names must match the FQDN of the Cisco ISE node.
In this case the SAN extension within the certificate will only have the customer DNS details and not the host company.
How would we get around this.
Thanks.
Solved! Go to Solution.
10-25-2019 04:12 AM
10-14-2019 02:54 AM
10-14-2019 03:59 PM
Thanks Mohammed,
The cert will be used for EAP-TLS and Portals (Guest, BYOD, Sponsor, Self-Registered Guest).
How do we go around this for the portals then?
The way I have done the CSR in the past with on-premise deployment (customer owned and managed ISE solution) is like:
CN=CompanyA-ISE
Now the CSR with the managed solution will have the DNS entry of the host-company and not customer's, I do not know how this would work?
Is there anything the customer can do on their infrastructure like within the CA to include the host company's DNS details etc.?
Appreciate any input.
Thanks.
10-25-2019 04:12 AM
10-30-2019 07:35 PM
Hi Jason,
Thanks for your reply.
ISE is being hosted for only a single client, I should have worded it correctly my apologies. It is managed by a third party in their network for this client.
So that is why the DNS and FQDN questions arised, whose to use.
We are trying to add the DNS entries of the the managed services team into clients domain (which is again managed by a third party) so ISE can resolve it. This is work in progress and I will keep you posted.
Thanks again for your time and the links attached.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide