Cisco ISE 3.4 Two Node Deployment with External CA Certificate
Anurag Mishra
Cisco ISE | Cisco FTD & FMC | Cisco, Aruba, HPE Routing & Switching | Aruba WLC | Windows Server | AWS Cloud Solution Architect Associate | Network Infrastructure |
Introduction
This article describes the best practices and proactive procedures to register the two-node ISE cluster with the Root CA.
Component used
Cisco ISE 3.4 and Windows Server 2016
Prerequisite of ISE node deployment:
Background Information
Before proceeding with the registration and two-node deployment, we must install the Root CA on the Windows Server and set up the forward and reverse lookup zones for the FQDNs ise-01.hydent.com and ise-02.hydent.com (optional). You can use any version—2012, 2016, or 2019—as the steps will be the same. In my case, I have Windows Server 2016, and my domain name is 'hydent.com.' Below, you can find some snapshots of the DNS
DNS Forward Zones and Reverse Lookup Zones Entry
2. Reverse Lookup Zones Entry
3. Verifying NSLookup
To download the Root CA, import, and register the ISE nodes with the external certificate, follow the steps below:
Download the Root CA certificate
2. Click on Base 64 and then click Download CA Certificate
Primary ISE Node " ise-01.hydent.com"
1 .Go to ISE-01 (10.10.10.11 or ise-01.hydent.com), which is my first ISE Node, and click on 'Administration,' then click on 'Deployment
2. Under Deployment, click on ISE-01 and edit the general settings of the node.
3. Click "Make Primary" and save it
4. Go to the certificate and click Trusted Certificate and then click import
5. Import the certificate file that we downloaded from the Root CA server and check the boxes below and click submit
6. In the screenshot below, we can see that the Root CA has been successfully imported with the expiration date 2034.
7. Go to the Certificate Signing Request to generate the CSR
8. Fill in the parameters below and allow the wildcard certificate for multi-use so that you can use a single certificate for multiple services, then click 'Generate
领英推荐
9. After clicking 'Generate,' the window below will appear. Just click 'Export,' and a CSR will be downloaded.
10. Now navigate to the Server CA on the browser and click on request a certificate for signing the CSR
11. Click on advance certificate request
12. Open the CSR you exported, copy the content inside, paste it into the 'Save Request' field, and click 'Submit.' This will download the signed certificate.
13. Click on the CSR and then Click Bind Certificate
14. Browse for the signed certificate, provide a friendly name, and check the boxes according to the required services, then click 'Submit.' After that, your services will restart and will be updated with the new signed certificate.
15. Here, you can see that the ISE-01 node has come up with the new certificate.
Secondary ISE Node " ise-02.hydent.com"
Navigate to ISE-01, click on 'Administration,' then click on 'Deployment,' and click on 'Register
2. Enter the FQDN of ISE-02, along with the user ID and password for ISE-02 and then click next .
3. After clicking Next we will get this Pop-up and then just click Import certificate and Proceed.
3. Here, we can see that the role of ise-02.hydent.com is secondary.
4. Select the parameters below, and then click 'Submit
5. Here, we can see that the secondary node is in the process of syncing. This may take a few minutes to complete the synchronization.
6. Registration and Synchronization has been completed
7. ISE-02
2xCCIE #55298 EI | Security
2 个月Good read !!!
CCNA | CCNP | ITILv4 | PaloAlto PCNSA | Cisco Ethical hacker | Youtube IT content creator
2 个月Hi, how did you get the license for ISE ?
IT Manager | Enterprise Infrastructure & Security Architect | Technical & Strategy Consultant || Fortinet FCP | CCNP SD-WAN | Aruba ACSP SD-WAN | CCNP Enterprise | CCS ENCOR | CCS ENARSI | CNSP ||
2 个月Anurag a nice document, Regarding the deployment do you think the two ise nodes deployment with CA only enough without policy monitoring node (3rd node) in the production? Because I experienced a failover problem in production with only two nodes setup and when one of the nodes goes down you needs to Promote the secondary node for primary role (manually) as there is no possibility for PAN auto failover in less than a minutes (since there is no 3rd node) so what’s your thought on this point ?
Senior Consultant -Presales at Presto | CCNP |Solution Design| Cisco SDWAN | ISE| Versa SDWAN | Data center | Campus Network Design | Project Management|CRD/HLD/LLD |
2 个月Nice document Anurag
Associate Consultant Network SDx | Team managemnt | CCNP Certified | Wireless | Routing, Switching | Design & Implementing Scalable Network Solutions | 10 Years of Experience |
2 个月Good