08-22-2025 01:45 PM
Hello
I have a question. We need to use EAP authentication. To start, ISE is on the ise.example.com domain, but I need my users to use other.net. Is this feasible?
When generating the CSR, should I choose to use EAP and use ise.other.net?
08-23-2025 01:48 AM
gDay to u @Leo TI and yes, that’s feasible. For EAP, the certificate’s CN/SAN must match the domain clients expect. If ur users belong to other.net, then the CSR should use ise.other.net (or include it in the SAN). U can also add multiple SANs if u need the ISE node reachable under both domains. Just make sure the certificate chain is trusted by the clients; otherwise EAP authentication will fail.....
hope it helps and enjoy ur weekend!!
-Enes
08-23-2025 02:20 PM
And remember your clients will need DNS resolution for that domain, so just make sure you're allowed to configure DNS records on the other.net domain. Otherwise you need to use your own registered domain.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide