<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Distributed environment question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136128#M215420</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a similar issue to the above and I am curious if the license/certificate will have issues once the NTP server or clock is changed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kanes.R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Nov 2013 01:34:16 GMT</pubDate>
    <dc:creator>Kanes Ramasamy</dc:creator>
    <dc:date>2013-11-04T01:34:16Z</dc:date>
    <item>
      <title>Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136121#M215298</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to deploy the ISE's nodes in primary- secondary to high availability.&lt;/P&gt;&lt;P&gt;One Node is in Europe and the another node is in America.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there exist some restriction about the distance or times, to syncronize between each one?. &lt;/P&gt;&lt;P&gt;Of course, the timezone for each node will be different (GMT - 8 and GMT +1 for example).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was reading the way for implement it, but it didn't show any information about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136121#M215298</guid>
      <dc:creator>soporte-pan</dc:creator>
      <dc:date>2019-03-11T02:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136122#M215299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make your timezones &lt;STRONG&gt;BOTH&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;UTC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of connection do you have between the 2 sites?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt; &lt;BR /&gt;I hope you find this information useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" /&gt;&lt;PARAM name="counter" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 03:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136122#M215299</guid>
      <dc:creator>jw.sl9</dc:creator>
      <dc:date>2012-12-06T03:18:43Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136123#M215306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My suggestion is to lab this between two boxes in a virtual environment. I dont think there is an issue with this since the clock has to be NTP and from a reliable clock source (please do not use windows). From my understanding the timezone is just an offset to the raw time data that is learned from NTP so if you have two nodes in different timezones should be covered. I understand that using UTC is a pain but James brings up a good solution. I feel that if you configure this in a lab you should be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 06:11:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136123#M215306</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-12-06T06:11:33Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136124#M215319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for answer a little late. I&amp;nbsp; had not the information before by the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The connection between the two sites is a International MPLS (no internet from our perspective). This is the information:&lt;/P&gt;&lt;P&gt;BW: 2 Mbps&lt;/P&gt;&lt;P&gt;Delay: 200 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put the 2 Nodes ISE in that way:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Node in Europe (We will call NodeA):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Administration (PAN) Primary&lt;/P&gt;&lt;P&gt;- Monitoring (MNT)&lt;/P&gt;&lt;P&gt;- Policy (PSN)&lt;/P&gt;&lt;P&gt;- NTP Server: Public NTP Server. 130.206.3.166&lt;/P&gt;&lt;P&gt;Timezone: UTC&lt;/P&gt;&lt;P&gt;CA Certificate: Self-Certificate_from_ise_node_America&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Node in America (We will call NodeB):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Administration (PAN) Secondary&lt;/P&gt;&lt;P&gt;NTP Server: Public NTP Server. 130.206.3.166 (the same NTP Server)&lt;/P&gt;&lt;P&gt; Timezone: EST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;NodeB &lt;/STRONG&gt;is registered from &lt;STRONG&gt;NodeA &lt;/STRONG&gt;using its dns name, &lt;SPAN style="font-size: 10pt;"&gt;with no problem &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;(so I assumed that the certificate, credential and DNS resolve correctly).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Waiting for a couple of hour, the &lt;STRONG&gt;NodeB &lt;/STRONG&gt;viewed from the &lt;STRONG&gt;NodeA &lt;/STRONG&gt; in the section &lt;EM&gt; Administration - System - Deployment &lt;/EM&gt;state &lt;SPAN style="text-decoration: underline;"&gt;OUT OF SYNC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When I tried to sync manually, the &lt;STRONG&gt;NodeA&lt;/STRONG&gt; showed the following message:&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Internal Error: Server returned HTTP Response Code: 500 for URL: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;STRONG&gt;NodeB&lt;/STRONG&gt;/deployment-rpc/cert&lt;/P&gt;&lt;P&gt;Expiry status&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;And happened everytime I tried to sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;NodeB &lt;/STRONG&gt;is no possible to access through http server web page correctly after its register. It shows the portal page, but it doesn't matter if you use a correct user or bad user, after you click &lt;EM&gt;Logging, &lt;/EM&gt;return a white page without information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution to use the same timezone &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/9/7/135793-HA_3rdTry_3.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/0/8/135809-HA_3rdTry_4.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will put in practice, making the nodes using for both &lt;STRONG&gt;UTC&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you guys have another ideas, it's appreciate it.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 22:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136124#M215319</guid>
      <dc:creator>khernandezruiz</dc:creator>
      <dc:date>2013-04-15T22:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136125#M215323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No... Configuring both Nodes using the timezone &lt;STRONG&gt;UTC&lt;/STRONG&gt; did not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136125#M215323</guid>
      <dc:creator>soporte-pan</dc:creator>
      <dc:date>2013-04-17T14:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136126#M215372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check the guide of Setting Up Cisco ISE in a Distributed Environment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 12:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136126#M215372</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2013-08-27T12:07:01Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136127#M215393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: sans-serif; left: 426.333px; top: 432.067px; transform: scale(0.95371, 1); transform-origin: 0% 0% 0px;"&gt;Sync issues, which are usually&amp;nbsp; due to time changes or Network Time Protocol (NTP) sync issues, you must correct the system time and perform a manual sync-up through the UI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Sep 2013 23:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136127#M215393</guid>
      <dc:creator>harvisin</dc:creator>
      <dc:date>2013-09-21T23:32:50Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136128#M215420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a similar issue to the above and I am curious if the license/certificate will have issues once the NTP server or clock is changed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kanes.R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 01:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136128#M215420</guid>
      <dc:creator>Kanes Ramasamy</dc:creator>
      <dc:date>2013-11-04T01:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136129#M215477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are these nodes virtual?&amp;nbsp; If so, please make sure that the Virtual Host Machine is syncing with the NTP server properly before deploying the VM image.&amp;nbsp; Once that is done, ensure that you are using the same NTP server on both the Virtual Host Machine and the VM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The licenses will be fine, but you may have to generate new certs once the time syncs up.&amp;nbsp; It can take 15-20 minutes for the NTP polling to sync the times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.&amp;nbsp; Otherwise, feel free to post follow-up questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 13:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136129#M215477</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2013-11-04T13:49:26Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136130#M215508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to make your own calculations as in&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://communities.cisco.com/servlet/JiveServlet/download/30977-55-46302/TT+ISE+Overview.pdf"&gt;https://communities.cisco.com/servlet/JiveServlet/download/30977-55-46302/TT+ISE+Overview.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/4/3/165346-ISEbw.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 20:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136130#M215508</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2013-11-06T20:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Distributed environment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136131#M215580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just one of them is virtual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently is not a sync problems, but a possible bug &lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCuh70984" target="_blank"&gt;CSCuh70984&lt;/A&gt; is hitting. Although is not discarded the delay issue between the nodes (200 ms), maybe is not the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will do the workaround if the problem is resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll let you know guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 20:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-environment-question/m-p/2136131#M215580</guid>
      <dc:creator>khernandezruiz</dc:creator>
      <dc:date>2013-11-06T20:33:44Z</dc:date>
    </item>
  </channel>
</rss>

