ISE redirect to the wrong domain name

Hello guys,
We changed a domain name of the ISE appliance and it started giving us grief. It was configured to redirect wireless users to the web registration and authentication portal. We properly added all required A records in DNS server and looked everywhere but didn't find anything that could give any clue.
Perhaps the old FQDN get stuck somewhere in the database.
Any idea? Please help !!!

Case Solution:
Connecting to the Active Directory Domain
To reconnect with Active Directory domain, complete the following steps:
Step 1                                                   Choose Administration > Identity Management > External Identity Sources.
Step 2    From the External Identity Sources navigation pane on the left, click Active Directory.
Step 3    Enter the domain name in the Domain Name text box.
Step 4    Enter a friendly name in the Identity Store Name text box for your Active Directory identity source (by default, this value will be AD1).
Step 5    Clicks Save Configuration.
Step 6    To verify if your Cisco ISE node can be connected to the Active Directory domain, click Test Connection. A dialog box appears and prompts you to enter the Active Directory username and password.
Step 7    Enter the Active Directory username and password and click OK.
A dialog box appears with the status of the test connection operation.
Step 8    Click OK.
Step 9    Click Join to join the Cisco ISE node to the Active Directory domain.
The Join Domain dialog box appears.
Step 10    Enter your Active Directory username and password, and click OK.
Step 11    Check the Enable Password Change check box to allow the user to change their password.
Step 12    Check the Enable Machine Authentication check box to allow machine authentication.
Step 13    Check the Enable Machine Access Restrictions (MARs) check box to ensure that the machine authentication results are tied to the user authentication and authorization results. If you check this check box, you must enter the Aging Time in hours.
Step 14    Enter the Aging Time in hours if you have enabled MARs.
This value specifies the expiration time for machine authentication. If the time expires, the user authentication fails. For example, if you have enabled MARs and enter a value of 2 hours, the user authentication fails if the user tries to authenticate after 2 hours.
Step 15    Click Save Configuration.
Step 16. Create Certificate Authentication Profile
Step 17: Import CA Certificates into ISE Certificate Trust Store
Step 18: Configure CA Certificates for Revocation Status Check
Step 19: Enable Client Certificate-Based Authentication
Please check below link for certificates configurations
http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_admin.html#wp1122804

Similar Messages

  • Url redirects using the BC domain

    My url redirects are using the BC domain name instead of my "added domain".
    eg : 
    Inside the url directs section it shows
    http://mydomain.businesscatalyst.com       
    instead of
    http://www.mydomain.com
    as the source destination.
    Should that be happening?  Ind oing so its causing a few of my redirects not to work correctly.

    Hello Sydney,
    Thanks for the help.  We never used the .businesscatalyst.com domain as a link reference when building the site and looking over it again, as far as we can see, we've used all relative urls.
    The only way the .businesscatalyst.com may have been inserted is if BC itself inserted it somewhere (maybe a stray link somewhere). 
    I can add a screenshot of the reference but BC and CC seem to be down as its not logging me in (constantly loading).
    The reference itself is appearing in the "Url redirect section" of BC, in the "add redirect" window.
    For the source destination it asks for folder/filename and below that it is the auto generated url which is using the system url instead of the "added domain".
    I'll try and add a screenshot once Adobe let me log in.

  • I tried to share a photo using e-mail and when I set up my gmail account I typed in the wrong user name and password.  Now i can't share photos using e-mail.

    I tried to share a photo using e-mail and when i set up my gmail account I typed in the wrong user name and password.
    Now I can't send a photo because i get an error message saying the user name and password do not match.
    How do i save a new gmail user name and password??

    iPhoto Menu ->
    Preferences ->
    Accounts ->
    Delete and recreate your email settings.
    Alternatively, use Apple's Mail for the job. It has Templates too - and more of them.

  • Problem with the wrong host name, when accessing IR or ID

    Hey all,
    I am trying to accessing the IR and ID at my client however the wrong host name is being called. For instance the
    URL should start nero.bcm.tmc.edu, but it is calling just nero. The basis guy here fixed a similar problem in the exchange profile for calling the Builder start page, where do we need to fix the problems for accessiing the IR and ID for the start page?
    Kind regards,
    Chris

    Problem reso;ved, just had to restart XI for the changes to take effect

  • C170 Ironport error "The query domain.name.accept failed

    Dear Community,
    I have two Cisco C170 Ironport devices.  Each is throwing the following error:
    "The query <domain.name.accept> failed with result inquiry timed out."
    I have been unable to decipher it and was hoping anyone might possibly have a clue to look for the resolution.
    I would be very grateful Community.
    Thanks.
    Rocky

    Hey Rocky,
    This seems to be an error on an LDAP accept query that is configured on the appliance.
    If you have indeed created an LDAP accept query, please check connectivity from the appliance to your AD servers currently set.
    Please go to GUI > System Admin > LDAP
    Here you can check connectivity to the AD servers and also run a test accept query.
    Please attempt these tests and let us know the results.
    Judging from the error, I am assuming that the LDAP accept query test will fail resulting in a time out, if it does this usually indicates either the AD server was not properly setup on the appliance, if so, you will need to ensure that your firewalls if any are in place is allowing the query traffic from the appliance to the AD server
    Please let us know.
    Regards,
    Matthew

  • Convert database IP link with the sub-domain name

    Can someone help me to covert the database ip with the SUB-domain name ?
    Kind regards,
    Shar Kurtishi
    Freelance Consultant
    10000 Prishtina, KOSOVO
    +377.44.210.456

    Hi Shar,
    You can use unix "nslookup" to get the domain from up or viceversa.
    The aim to get the info frm the dns server.
    Regards,
    Chandan

  • Find the full domain names?

    Hi,
    Where can i found the full domain names in application server?
    for example,
    suppose, i am installed in portal, discoverer, etc.,
    http://...:7778/pls/portal
    http://...7781/discoverer/plus
    Thanks!

    Hi,
    You can find your full computer name at My Computer > Properties > Computer name.
    If your machine is not under any domain, as in case of Home PC, then you will have workgroup name instead of domain name.
    You can install portal,discoverer, etc in both cases.
    Cheers!
    Yogini

  • Iam Anvesh  i have recently bought an iphone 5S   i gave it for factory unlock but i have given the wrong operator name (instead of TELCEL i gave At

    Iam Anvesh
    i have recently bought an iphone 5S
    i gave it for factory unlock but i have given the wrong operator name (instead of TELCEL i gave At&t)
    will i get my refund back please let me know please
    Thank you

    Who did you give it to for the unlock?
    The only one that can legally unlock it is the carrier holding the lock.
    Anything else will lead to someone illegally jailbreaking yopur iPhone so that Apple will no longer support it inany fashsion.
    Allan

  • The wrong user name pops up when I try to update apps on Iphone. Unable to update or change incorrect user name.

    The wrong user name pops up when I try to update apps on Iphone. Unable to update or change incorrect user name.

    It is popping up because you have apps installed that you bought with the old AppleID, you can either delete those apps or buy the apps again using your new Apple ID, if they were free apps then not a big deal, paid apps obviously means you would have to buy them twice.

  • How do I redirect to the default domain without showing home.html in the url

    Is there a way to redirect the following domains to the default domain.
    www.membersalliance.com.au//
    www.membersalliance.com.au/index.aspx 
    The default domain is www.membersalliance.com.au
    We have been told that these pages are seen by google as separate content and we want to consolidate them to all go to the default domain.
    I have spoken to adobe support and they said that:
    Redirecting to another page can be done, there's no issue with that. But what we're looking for here is to not have any other postfix with the domain name. When a page is set to be the starting page, there is an automatic functionality that the postfix/name of the page is removed, but that is not the case with other pages.So, they would still show the name of the page, even if you redirect it to the home page (starting page set for your domain).
    So, I can redirect to www.membersalliance.com.au/home.html but is this seen by google as a separate page to www.membersalliance.com.au?

    To be able to redirect a website with a submit button, you must have a custom submit button and insert the following line:
    app.launchURL("www.url.com");

  • ISE node registering after change domain-name

    At Customer Site I changed the domain name of our 4 ISE server before they were registered to any deployment. I regenerated a self signed certificate and started to register the other nodes to the deployment. This went well for the 2 PSN nodes which have a ip address in a different subnet. I tried to register the presumed secondarry PAN/MnT node and got the following error message "
    Node beiing registerd has FQDN 'ISE-PAN-AP02.office.intern' which cannot be resolved. Please check your DNS configuration."
    My DNS config is in order.
    Can anyone please tell me want possible can be the cause of this?

    Please check these Prerequisites:
    The fully qualified domain name (FQDN) of the standalone node that you are going to register, for example, ise1.cisco.com must be DNS-resolvable from the primary Administration ISE node.  Otherwise, node registration will fail. You must enter the IP addresses  and FQDNs of the ISE nodes that are part of your distributed deployment  in the DNS server.
    •The  primary Administration ISE node and the standalone node that you are  about to register as a secondary node should be running the same version  of Cisco ISE.
    •Node  registration fails if you provide the default credentials (username:  admin, password: cisco) while registering a secondary node. Before you  register a standalone node, you must log into its administrative user  interface and change the default password (cisco).
    •You  can alternatively create an administrator account on the node that is  to be registered and use those credentials for registering that node.  Every ISE administrator account is assigned one or more administrative  roles. To register and configure a secondary node, you must have one of  the following roles assigned: Super Admin, System Admin, or RBAC Admin.  See Cisco ISE Admin Group Roles and Responsibilities for more information on the various administrative roles and the privileges associated with each of them.
    •If  you plan to register a secondary Administration ISE node for high  availability, we recommend that you register the secondary  Administration ISE node with the primary first before you register other  Cisco ISE nodes. If Cisco ISE nodes are registered in this sequence,  you do not have to restart the secondary ISE nodes after you promote the  secondary Administration ISE node as your primary.
    •If  you plan to register multiple Policy Service ISE nodes running Session  services and you require mutual failover among those nodes, you must  place the Policy Service ISE nodes in a node group. You must create the  node group first before you register the nodes because you need to  select the node group to be used on the registration page. See "Creating, Editing, and Deleting Node Groups" section for more information.
    •Ensure  that the Certificate Trust List (CTL) of the primary node is populated  with the appropriate Certificate Authority (CA) certificates that can be  used to validate the HTTPS certificate of the standalone node (that you  are going to register as the secondary node). See the "Creating Certificate Trust Lists in the Primary Cisco ISE Node" section on page 12-24 for more information.
    •After  registering your secondary node to the primary node, if you change the  HTTPS certificate on the registered secondary node, you must obtain  appropriate CA certificates that can be used to validate the secondary  node's HTTPS certificate and import it to the CTL of the primary node.  See "Creating Certificate Trust Lists in the Primary Cisco ISE Node" section on page 12-24 for more information.

  • Report Print.VI redirects to the wrong printer if error on intended printer

    I have an application that involves a Zebra barcode printer and an HP letter-sized printer, both connected via USB to an XP box running LV2011.  I need to send binary files directly to the label printer so I have it shared as LPT1 using NETUSE and I use COPY to get the file to the printer.  Works great, except for the flash as the DOS screen momentarily appears during the COPY command.  I can live with that.  Here's the problem: when I use Print Report.VI to send an HTML report to the letter-sized printer it comes out on the label printer if there is any issue with the intended printer (e.g. out of toner).  35 labels later....
    1] is there any way to force the print to sit in the HP's queue instead of redirecting to the label printer? I believe the Print Report VI uses IE's default printer regardless of what you specify, so maybe it's also IE that's doing the substitution?
    2] is there any way to query the HP printer's "health" before sending a job so I can avoid creating the issue in the first place? I read somewhere that Windows only knows the state of the printer at certain discrete (an not-so-informative) times.

    Hi Zwired1,
    Just to make sure I fully understand the situation - I am assuming since you say you are printing to two different printers that when you are using the Print Report.vi you are using the printer name string to specify which printer you would like to print on. And if the printer that you specify is not functioning it automatically prints on the other printer, is that correct?
    From looking at the code in the Print Report.vi, it looks like if you specify a printer name in the input string, if there is a problem with that printer or if that printer is unavailable, the VI should not print anything, so please let me know if that is not the behavior you are seeing.
    For your question about checking the health of printers, there is a VI in the report gen toolkit called Query Available Printers. You can find it if you open up the Print Report.vi and choose the Standard Report instance, the Query Available Printers.vi is on the block diagram of that VI. It will return the list of available printers and the default printer.
    I hope that helps,

  • How to change the root domain name in window 2012 server

    Got a window 2012 server build up. My root domain name looks something like corp.marketing   Well I seems to have missed to add the last .com or .local.  How do I add the .com to my existing root domain name please. The server is new, will
    go online in few days time. Thanks for all the help.

    I have a similar question and not sure if this is the right place. I had set a server with corp.brighterworld.com but the install wizard anywhere access had me believe that microsoft's strongly preferred domain name prefix was remote.brighterworld.com so
    I contacted GoDaddy and had it reissued as remote. but when I went to reconfigure for the new name. I had already set the server for being a CA, and in that process it issued like 4 or 5 certificates. So I had tried to rebuild the machine from scratch, but
    the it didn't wipe everything, but rather saved previous state which left the old certificate stuff to be dealt with. Any hints or help out here for us having to learn this stuff the hard way?
    Thanks,
    Mark Saxton

  • Changing the default domain name of the server.

    I know this is not the correct title for the topic. but its the best word i could found on my voculabary.
    here's my problem.
    Im using Sun App Server 9. the server is installed in the local machine. for testing purposes client access from the local server is sufficient. I deployed a web service using net beans 5.5. My problem is that the WSDL file is generated (by server) uses a fully qualified domain name rather than localhost. for example it uses http://mlb.stdmlb.sliit.lk:8080. When i try to create a client using netbeans it tries to access the server using this address (the one in the WSDL) but the firewall denies access to port 8080. Therefore i want to use the server to use localhost rather than the long domai name. (at least http://mlb) Can anyone tell me how to configure this?
    Lahiru

    These are the steps for changing domain name & IP address without reinstall
    a) Stop the Gateway and Server .
    b) Export the profile server database to a flat ldif file:
    # /opt/netscape/directory4/slapd-host_name/db2ldif /temp/profile.ldif
    c) Use awk, perl, or vi, to change every instance of the system domainname in the ldif file to that of the new system.
    d) Import the edited ldif file into the profile server on the new machine:
    # /opt/netscape/directory4/slapd-/ldif2db -i /temp/profile.ldif
    e) edit etc/opt/SUNWips/platform.conf and change all the domain name & Ip address
    f) edit /etc/opt/SUNWips/properties.file change the domain name
    g) Start the platform server and gateway on the new machine.

  • How to determine the Current Domain name from inside an Mbean / Java Prog

    We have registered an Application Defined MBean. The mbean has several APIs. Now we want to determine the currrent domain using some java api inside this Mbean. Similarly we have deployed a Webapp/Service in the Weblogic domain. And inside this app we need to know the current Domain. Is there any java api that will give this runtime information.
    Note: We are the MBean providers not clients who can connect to the WLS (using user/passwd) and get the domain MBean and determine the domain.
    Fusion Applcore

    Not sure if this will address exactly what you are looking to do, but I use this technique all the time to access runtime JMX information from within a Weblogic deployed application without having to pass authentication credentials. You are limited, however, to what you can access via the RuntimeServiceMBean. The example class below shows how to retrieve the domain name and managed server name from within a Weblogic deployed application (System.out calls only included for simplicity in this example):
    package com.yourcompany.jmx;
    import javax.management.MBeanServer;
    import javax.management.ObjectName;
    import javax.naming.InitialContext;
    public class JMXWrapper {
        private static JMXWrapper instance = new JMXWrapper();
        private String domainName;
        private String managedServerName;
        private JMXWrapper() {
        public static JMXWrapper getInstance() {
            return instance;
        public String getDomainName() {
            if (domainName == null) {
                try {
                    MBeanServer server = getMBeanServer();
                    ObjectName domainMBean = (ObjectName) server.getAttribute(getRuntimeService(), "DomainConfiguration");
                    domainName = (String) server.getAttribute(domainMBean, "Name");
                } catch (Exception ex) {
                    System.out.println("Caught Exception: " + ex);
                    ex.printStackTrace();
            return domainName;
        public String getManagedServerName() {
            if (managedServerName == null) {
                try {
                    managedServerName = (String) getMBeanServer().getAttribute(getRuntimeService(), "ServerName");
                } catch (Exception ex) {
                    System.out.println("Caught Exception: " + ex);
                    ex.printStackTrace();
            return managedServerName;
        private MBeanServer getMBeanServer() {
            MBeanServer retval = null;
            InitialContext ctx = null;
            try {
                //fetch the RuntimeServerMBean using the
                //MBeanServer interface
                ctx = new InitialContext();
                retval = (MBeanServer) ctx.lookup("java:comp/env/jmx/runtime");
            } catch (Exception ex) {
                System.out.println("Caught Exception: " + ex);
                ex.printStackTrace();
            } finally {
                if (ctx != null) {
                    try {
                        ctx.close();
                    } catch (Exception dontCare) {
            return retval;
        private ObjectName getRuntimeService() {
            ObjectName retval = null;
            try {
                retval = new ObjectName("com.bea:Name=RuntimeService,Type=weblogic.management.mbeanservers.runtime.RuntimeServiceMBean");
            } catch (Exception ex) {
                System.out.println("Caught Exception: " + ex);
                ex.printStackTrace();
            return retval;
    }I then created a simply test JSP to call the JMXWrapper singleton and display retrieved values:
    <%@page contentType="text/html" pageEncoding="UTF-8"%>
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
       "http://www.w3.org/TR/html4/loose.dtd">
    <%@ page import="com.yourcompany.jmx.JMXWrapper"%>
    <%
       JMXWrapper jmx = JMXWrapper.getInstance();
       String domainName = jmx.getDomainName();
       String managedServerName = jmx.getManagedServerName();
    %>
    <html>
        <head>
            <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
            <title>JMX Wrapper Test</title>
        </head>
        <body>
            <h2>Domain Name: <%= domainName %></h2>
            <h2>Managed Server Name: <%= managedServerName %></h2>
        </body>
    </html>

Maybe you are looking for

  • IBook app slow to start

    Over the past few weeks (I think subsequent to updating my iPad1 IOS to 5.0.1), iBook has been very slow to start.  Upon opening the app, there is a 10-second delay between the "bookshelf" appearing and the books appearing on the bookshelf.  Once pas

  • Do image files adjusted in Lightroom transfer to another computer if you need to reload the files?

    I'm used to making adjustments in Camera RAW and copying the image files for use on multiple workstations.  In this case, my adjustments go with the image file.  If I make my adjustments using Lightroom and move the image files to another computer wi

  • LOGO in SAP Script

    I have a bitmap image i want to add to a standard SAPScript..I have created a Z copy of the script. I would like to add it to the header window. I used the INSERT ->GRAPHIC command, but with that the graphic is printed on the next line. The graphic n

  • Using "operations" in the new Mac OS Keynote version

    Hi, I used to put "operations" on my object groups in the previous version of Keynote, but can't find a way to use the same effects in the latest version. This made gorgeous effects like carousel or grid in a simple click. Do you have a clue about it

  • Numbers for iPad .Column width

    I can adjust column width.Can I adjust column with of individual rows?