08-10-2023 11:42 PM
I have a couple other posts on this topic for ISE and FMC, but have decided to split them up so not to mix up answers for the different technologies.
The server team will be replacing the existing AD servers with new ones shortly. The new servers have been added to the network using new hostnames and IPs and will live side by side the old servers until everything else is confirmed OK at which point the old servers will be turned off. The new servers will then have their IPs updated to that of the old servers. These servers are also the DNS servers for the network.
Since the ADs are also the DNS servers in the network, and will be eventually inheriting the IP addresses of the old AD servers I would assume that DNS lookups via the Umbrella VA's would not be affected. let me know if my understanding is correct on this matter.
These Umbrella VA's are also integrated with AD to get user context in the logs, and this is where I get a little uncertain. Can the server team just change the IP of the new AD servers to that of the old servers and then run the Umbrella AD script on the server and everything will be OK? Or would we need to remove the old AD servers from Cisco Umbrella Deployments > Configuration > Sites and Active Directory and then add them back?
Any other Gotcha's?
08-22-2023 02:09 AM
08-22-2023 06:06 AM
The bot got it mostly right.
I would add that you might want to add the temporary server addresses in your VA configuration so that they see them as valid DNS servers for internal lookups.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide