cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6132
Views
8
Helpful
8
Replies

ISE HA and CA deployment without a DNS server

yfukudom
Cisco Employee
Cisco Employee

Could someone let me know any notice to take prior to ISE deployment in HA, where no DNS server is deployed?

ISE is also expected to publish client certificates for EAP-TLS auth.


1 Accepted Solution

Accepted Solutions

yfukudom
Cisco Employee
Cisco Employee

Thanks a lot for comments, folks.

Finally, after installing the certification of secondary ISE server on client hosts, it has worked.

View solution in original post

8 Replies 8

Aaron Woland
Cisco Employee
Cisco Employee

I'm very confused by your query..

What does EAP-TLS auth have to do with DNS?

Please see my blog post on how certificate authentications work here: http://www.networkworld.com/article/2226498/infrastructure-management/simply-put-how-does-certificate-based-authentication-work.html

Is your concern about querying the OCSP service?

Always keep in mind that DNS is a mission-critical application for networking, in general.  It will be needed for Active Directory - even simple web browsing. 

-Aaron

The partner who is asking deploys closed/separated LAN for hospitals as design, where there has been no DNS/AD server, from cost-reduction perspective.

-Dome

So the endpoint has NO DNS resolution.  That still won't effect the EAP-TLS authentication.  It WILL however, impact all advanced services that use URL redirection - (WebAuth, GUEST, MDM, etc.).  Are those type services being deployed?

-Aaron

There are only web/application/DB servers and file servers inside the LAN. All hostnames needed to be resolved by client hosts are written in local hosts file.

(Updates)

A partner is building up this environment for a testing required prior to proposal, but has been facing to an issue when shutting down the primary ISE, expecting the secondary one takes over all roles of primary one. While shutting down the primary, no EAP-TLS authentication is succeeded as the partner claims. Some consideration in ISE configuration seems to be needed and any comments would be greatly appreciated.

ISE_HA-status.png

Cory Peterson
Level 5
Level 5

You can get around the DNS/FQDN requirement in ISE HA by using the ip host configuration command in the ISE CLI. It will require a restart of the ISE services anytime you add host.

In config mode the command is "ip host A.B.C.D ISE-PAN01.example.com"

Thanks for your comment.

I have received a screenshot of the ISE HA status adding to my question, and would like to know another steps to troubleshoot as HA itself seems good.

Are you able to recreate this issue in your own lab?

No DNS in a deployment is not well supported. DNS can run on a royalty-free Linux or BSD so it would not cause the customer or partner much extra. ISE PoV kit includes a VM to run common network services.

yfukudom
Cisco Employee
Cisco Employee

Thanks a lot for comments, folks.

Finally, after installing the certification of secondary ISE server on client hosts, it has worked.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: