cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
0
Helpful
3
Replies

New DMZ ISE node not able to reach DNS on inside zone

blocksupport
Level 1
Level 1

I am deploying a new ISE node which resides within a DMZ zone on FTD. During the initial bootstrapping it is failing to reach the name server .

ISE node 192.168.235.12 - DMZ zone

DNS 192.168.245.246

I have created a policy on the FTD and ran a packet capture the traffic is allowed.. What else could be stopping this?

3 Replies 3

@blocksupport 

 Where the DNS server is connected? Does it have gateway or use route table?

What action did you apply to that rule? I would try to change it to "trust" if that is not already applied. Another thing come to mind,  in terms of routing, does the DNS server know how to reach ISE?

Share packet tracer ypu run'

Send it to me as PM

MHM