<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTP issue Cisco ISE 2.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ntp-issue-cisco-ise-2-1/m-p/3862035#M472838</link>
    <description>It did work after we change NTP server, instead point to core switch we change to AD&lt;BR /&gt;&lt;BR /&gt;thanks</description>
    <pubDate>Fri, 24 May 2019 01:40:47 GMT</pubDate>
    <dc:creator>Ruelb2214</dc:creator>
    <dc:date>2019-05-24T01:40:47Z</dc:date>
    <item>
      <title>NTP issue Cisco ISE 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ntp-issue-cisco-ise-2-1/m-p/3859833#M472836</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We run the URT tools for preparation upgrade of our production ISE 2.1 to v2.4.&lt;/P&gt;&lt;P&gt;Base on the logs, NTP failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nstalling URT bundle&lt;BR /&gt;- Successful&lt;/P&gt;&lt;P&gt;########################################&lt;BR /&gt;# Running Upgrade Readiness Tool (URT) #&lt;BR /&gt;########################################&lt;BR /&gt;This tool will perform following tasks:&lt;BR /&gt;1. Pre-requisite checks&lt;BR /&gt;2. Clone config database&lt;BR /&gt;3. Copy upgrade files&lt;BR /&gt;4. Data upgrade on cloned database&lt;BR /&gt;5. Time estimate for upgrade&lt;/P&gt;&lt;P&gt;Pre-requisite checks&lt;BR /&gt;====================&lt;BR /&gt;Disk Space sanity check&lt;BR /&gt;- Successful&lt;BR /&gt;&lt;STRONG&gt;NTP sanity&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;- Failed&lt;/STRONG&gt;&lt;BR /&gt;Appliance/VM compatibility&lt;BR /&gt;- Successful&lt;BR /&gt;Trust Cert Validation&lt;BR /&gt;- Successful&lt;BR /&gt;System Cert Validation&lt;BR /&gt;- Successful&lt;BR /&gt;Invalid MDMServerNames in Authorization Policies check&lt;BR /&gt;- Successful&lt;BR /&gt;5 out of 6 pre-requisite checks passed&lt;BR /&gt;Some pre-requisite checks have failed. Hence exiting...&lt;/P&gt;&lt;P&gt;Final cleanup before exiting...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have point the NTP to our Core Switch:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;# sho ntp&lt;/STRONG&gt;&lt;BR /&gt;Configured NTP Servers:&lt;BR /&gt;10.67.2.1&lt;BR /&gt;10.67.2.2&lt;/P&gt;&lt;P&gt;synchronised to local net at stratum 11&lt;BR /&gt;time correct to within 12 ms&lt;BR /&gt;poremoteserver everrefids st t when poll reach delay offset jitter&lt;BR /&gt;==============================================================================&lt;BR /&gt;*127.127.1.0 .LOCL. 10 l 58 64 377 0.000 0.000 0.000&lt;BR /&gt;10.67.2.1 10.67.2.17 6 u 91d 1024 0 1.001 9.296 0.000&lt;BR /&gt;10.67.2.2 10.67.2.17 6 u 91d 1024 0 0.931 -0.024 0.000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But Cisco ISE pointed to local? Could it be the issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it necessary NTP must not be local? how should we force the NTP to point 10.67.2.1 or 2.2? Any downtime?&lt;/P&gt;&lt;P&gt;We check the Firewall between ISE and Switch no problem, can ping also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 03:57:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ntp-issue-cisco-ise-2-1/m-p/3859833#M472836</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2019-05-21T03:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: NTP issue Cisco ISE 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ntp-issue-cisco-ise-2-1/m-p/3859846#M472837</link>
      <description>&lt;P&gt;Hi mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that your configured NTPs are not even showing as candidate (backup).&lt;/P&gt;&lt;P&gt;Can you confirm that you see udp 123 is shown on live logs of your firewall.&lt;/P&gt;&lt;P&gt;Are you using keys on ntp? Can you post the configuration.&lt;/P&gt;&lt;P&gt;Also what server are you running this NTP ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Raffy&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 04:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ntp-issue-cisco-ise-2-1/m-p/3859846#M472837</guid>
      <dc:creator>RaffyLindogan</dc:creator>
      <dc:date>2019-05-21T04:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: NTP issue Cisco ISE 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ntp-issue-cisco-ise-2-1/m-p/3862035#M472838</link>
      <description>It did work after we change NTP server, instead point to core switch we change to AD&lt;BR /&gt;&lt;BR /&gt;thanks</description>
      <pubDate>Fri, 24 May 2019 01:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ntp-issue-cisco-ise-2-1/m-p/3862035#M472838</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2019-05-24T01:40:47Z</dc:date>
    </item>
  </channel>
</rss>

