10-01-2024 08:00 AM
due to Solved: mess in ISE ERS integration - Cisco Community we need to rename PANs from reg1pan1.reg1.company.com/reg2pan1.reg2.company.com to reg1pan1.company.com/reg2pan1.company.com. we configure A-records in zone company.com & reconfigure PTRs to point to new FQDNs. On the PANs (one by one with deregistering from both deployment & DNAC, & then registering back to deployment & DNAC) we configure new domain-names & DNS-servers on nodes. What is opinion of ISE-gurus on workability of the approach?
Solved! Go to Solution.
10-02-2024 12:42 AM
The method of procedure sounds alright to me. Especially the de-registration - only then can you mess with the node's name/IP etc. I would also think about the certs of the new nodes - they will need new Admin certs, and any other certs that relate to the new hostname.
10-01-2024 08:48 AM
Are the pans bound to AD? You may have to re-join them afterwards - check if binding account has admin rights to create the new pan objects.
hth
Andy
10-01-2024 09:04 AM
tnx, Andy. have forgotten to mention it. is the remaining part Ok from your pov?
10-02-2024 12:42 AM
The method of procedure sounds alright to me. Especially the de-registration - only then can you mess with the node's name/IP etc. I would also think about the certs of the new nodes - they will need new Admin certs, and any other certs that relate to the new hostname.
10-02-2024 12:50 AM
tnx Arne. your input is always appreciated. of course new certificates enrolment will be included.
BTW interesting thing is TAC also recommends to rename PxGrid nodes which integration with DNAC is a bit different from xPAN. i'm still thinking.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide