<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE NODE NOT REACHABLE when building distributed deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277556#M135974</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Originally I had added them all at the same time. I thought that maybe I just wasn't waiting long enough for the sync. I waited an entire day and all the nodes were still unreachable. At this point, I've de-registered all the nodes, rebooted all the nodes, converted the primary back to standalone (the remaining nodes never converted from standalone to distributed even when I rebooted them after registering despite a message that they were successfully registered), converted one node back to primary and tried to register just the secondary admin node giving it plenty of time to sync; this node is still not reachable from the primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've quadruple checked the certificates on all the nodes, these certs were all added on the same day (just last week) and the default self-signed certs were removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had restored from a backup on the primary so I might just rest the config on that node and try joining the other nodes before I restore again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Jun 2013 12:39:00 GMT</pubDate>
    <dc:creator>vancamt76</dc:creator>
    <dc:date>2013-06-14T12:39:00Z</dc:date>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277552#M135970</link>
      <description>&lt;P&gt;I am trying to build a distributed deployment with the following personas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 policy admin nodes&lt;/P&gt;&lt;P&gt;2 monitoring nodes&lt;/P&gt;&lt;P&gt;4 policy service nodes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was a project that was partially implemented but never in production. It was in a distributed deployment, but half the nodes were no longer working (http errors or devices weren't reachable or could not sync). I decided to start from scratch. All nodes were:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-de-registered &lt;/P&gt;&lt;P&gt;-application was reset to factory defaults on all nodes&lt;/P&gt;&lt;P&gt;-upgraded all 8 nodes to 1.1.4.218 patch 1 &lt;/P&gt;&lt;P&gt;-installed all new certs and joined all nodes to the domain&lt;/P&gt;&lt;P&gt;-added to DNS forward and reverse lookup zones&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I make 1 admin node primary and register the other nodes (secondary admin, monitoring, policy services) the nodes successfully register and show up in the deployment window of the primary; however, all the nodes show as NODE NOT REACHABLE. After registration, I've noticed that the registered nodes are still showing as STANDALONE if I access the GUI. I've tried rebooting them manually after registration and they are still unreachable. I have also tried resetting the database user password from the CLI on both admin nodes and the results are always the same. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277552#M135970</guid>
      <dc:creator>vancamt76</dc:creator>
      <dc:date>2019-03-11T03:32:22Z</dc:date>
    </item>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277553#M135971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you already gone through this thread.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2220572"&gt;https://supportforums.cisco.com/thread/2220572&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 14:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277553#M135971</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-13T14:56:28Z</dc:date>
    </item>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277554#M135972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes I have - in fact, it's still open on my screen &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;. 6 of the nodes are on the same vlan and the remaining 2 nodes are on a separate subnet, but there is no firewall in between. I've also already reset the database user passwords. When I do a port scan on the nodes, I do not see any of them listening on tcp port 1521.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 15:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277554#M135972</guid>
      <dc:creator>vancamt76</dc:creator>
      <dc:date>2013-06-13T15:01:51Z</dc:date>
    </item>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277555#M135973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On my last distributed deployment setup I had a few nodes that didnt join successfully.&amp;nbsp; My gut feeling was I added to many nodes at one time and the sync of all them upset the ISE.&amp;nbsp; I de-registered the non-sync nodes for the admin node and then made sure the formerly failed nodes appeared ok in standalone mode with all services running.&amp;nbsp; I then added them back in one at a time waiting for the sync to complete, before moving on to the rest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you are saying all of yours have failed to sync?&amp;nbsp; Did you add them all at the same time?&amp;nbsp; Are you sure the certificates are valid on all nodes?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 09:47:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277555#M135973</guid>
      <dc:creator>Nicholas Poole</dc:creator>
      <dc:date>2013-06-14T09:47:14Z</dc:date>
    </item>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277556#M135974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Originally I had added them all at the same time. I thought that maybe I just wasn't waiting long enough for the sync. I waited an entire day and all the nodes were still unreachable. At this point, I've de-registered all the nodes, rebooted all the nodes, converted the primary back to standalone (the remaining nodes never converted from standalone to distributed even when I rebooted them after registering despite a message that they were successfully registered), converted one node back to primary and tried to register just the secondary admin node giving it plenty of time to sync; this node is still not reachable from the primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've quadruple checked the certificates on all the nodes, these certs were all added on the same day (just last week) and the default self-signed certs were removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had restored from a backup on the primary so I might just rest the config on that node and try joining the other nodes before I restore again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 12:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277556#M135974</guid>
      <dc:creator>vancamt76</dc:creator>
      <dc:date>2013-06-14T12:39:00Z</dc:date>
    </item>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277557#M135975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can do the following:&lt;BR /&gt;• For out of&amp;nbsp; sync issues, which most likely are due to time changes or NTP sync&lt;BR /&gt;issues,&amp;nbsp; you must correct the system time and perform a manual sync up through&lt;BR /&gt;the&amp;nbsp; UI.&lt;BR /&gt;• For certificate expiry issues, you must install a valid certificate and&amp;nbsp; perform a&lt;BR /&gt;manual sync up through the UI.&lt;BR /&gt;• For a node that has been down&amp;nbsp; for more than six hours, you must restart the node,&lt;BR /&gt;check for connectivity&amp;nbsp; issues, and perform a manual sync up through the UI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 09:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277557#M135975</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2013-06-18T09:19:56Z</dc:date>
    </item>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277558#M135976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have seen the same behavior some times, and it often works if I put in the new nodes IP address instead of FQDN.&lt;/P&gt;&lt;P&gt;That has solved it for me a few times at least &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Kelvin Dam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 08:02:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277558#M135976</guid>
      <dc:creator>kelvindam</dc:creator>
      <dc:date>2013-06-19T08:02:59Z</dc:date>
    </item>
    <item>
      <title>ISE NODE NOT REACHABLE when building distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277559#M135977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you everyone for the replies. Just an update after working with TAC:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tried de-registering and re-registering the nodes to the primary and received the same problem, restarted all nodes and still wouldn't sync. TAC advised that I should remove the application from the primary, download the .iso from cisco.com and reinstall the application. After doing these steps on the primary, I was able to successfully join all nodes in a distributed deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 13:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-node-not-reachable-when-building-distributed-deployment/m-p/2277559#M135977</guid>
      <dc:creator>vancamt76</dc:creator>
      <dc:date>2013-06-27T13:19:07Z</dc:date>
    </item>
  </channel>
</rss>

