<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.1 Joining to the Cluster Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3725310#M495181</link>
    <description>Did you backup your certificates before the update. If yes, go ahead and&lt;BR /&gt;reimport them.&lt;BR /&gt;&lt;BR /&gt;Another option is trying to promote the secondary node as primary then go&lt;BR /&gt;ahead and de-register PSNs then register them again. That might fix&lt;BR /&gt;the problem&lt;BR /&gt;</description>
    <pubDate>Mon, 15 Oct 2018 06:56:00 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2018-10-15T06:56:00Z</dc:date>
    <item>
      <title>ISE 2.1 Joining to the Cluster Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3725289#M495163</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have Two node deployment and currently running with 2.1 with Patch 7 (Physical Appliance)&lt;/P&gt;
&lt;P&gt;Primary&amp;nbsp; - Policy Service (Primary) ,&amp;nbsp;PRI(A), PRI(M)&lt;/P&gt;
&lt;P&gt;Secondary - Policy Service (Primary),&amp;nbsp;SEC(A), SEC(M)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me brief you about our issue, last week on our Primary node the Application Service got stopped running(Don't know exactly what happened) we open a support case the after troubleshooting, TAC suggested to go for latest patch 7.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After applying the patch we got one more issue, the secondary node is not joining to the cluster, we tried many time its getting failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;From GUI :&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE class="mytable" border="0"&gt;
&lt;TBODY class="mybody"&gt;
&lt;TR class="myrow"&gt;
&lt;TD class="cLabel"&gt;
&lt;DIV&gt;&lt;LABEL&gt;Sync Status:&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="cValue"&gt;
&lt;DIV class="qvCellLabel"&gt;&lt;LABEL&gt;Node Registration or Sync failed. Please deregister and register the node again&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Below is the error message from the CLI......&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2018-10-07 21:25:10,441 INFO&amp;nbsp;&amp;nbsp; [admin-http-pool2930][] cpm.admin.infra.action.DeploymentEditAction -:admin:Secondary.node:registerNode:- HostConfig hostId of registering node Secondary.node at time of local cert save: aff7bf20-ca00-11e8-b228-843dc6e&lt;BR /&gt;c40ec. All local certs and CSRs reference the HostConfig using this hostId.&lt;BR /&gt;2018-10-07 21:15:11,028 ERROR&amp;nbsp; [admin-http-pool2930][] cpm.infrastructure.deployment.client.DeploymentRegistrationClient -:admin:Secondary.node.com:registerNode:- An error occurred while importing deployment shared system certificates to the regis&lt;BR /&gt;tering node&lt;BR /&gt;2018-10-07 21:25:11,029 ERROR&amp;nbsp; [admin-http-pool2930][] cpm.admin.infra.action.DeploymentEditAction -:admin:Secondary.node.com:- Error occurred while replicating deployment shared certificates&lt;BR /&gt;com.cisco.cpm.infrastructure.certmgmt.api.CertMgmtException: An error occurred while importing deployment shared system certificates to the registering node&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.infrastructure.deployment.client.DeploymentRegistrationClient.importDeploymentSharedCertificates(DeploymentRegistrationClient.java:1608)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.admin.infra.action.DeploymentEditAction.replicateDeploymentSharedCertificates(DeploymentEditAction.java:1512)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.admin.infra.action.DeploymentEditAction.createSubmit(DeploymentEditAction.java:1205)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.admin.infra.action.DeploymentEditAction.createSubmit(DeploymentEditAction.java:1035)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Caused by: java.io.EOFException&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.io.ObjectInputStream$PeekInputStream.readFully(ObjectInputStream.java:2328)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.io.ObjectInputStream$BlockDataInputStream.readShort(ObjectInputStream.java:2797)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.io.ObjectInputStream.readStreamHeader(ObjectInputStream.java:802)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.io.ObjectInputStream.&amp;lt;init&amp;gt;(ObjectInputStream.java:299)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.infrastructure.deployment.client.DeploymentRegistrationClient.importDeploymentSharedCertificates(DeploymentRegistrationClient.java:1598)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ... 89 more&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2018-10-07 21:25:11,029 ERROR&amp;nbsp; [admin-http-pool2930][] cpm.admin.infra.action.DeploymentEditAction -:admin:Secondary.node.com:registerNode:- Replicating the deployment shareable certificates to the registering node failed:&lt;BR /&gt;com.cisco.cpm.infrastructure.certmgmt.api.CertMgmtException: Error occurred while replicating deployment shared certificates&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.admin.infra.action.DeploymentEditAction.replicateDeploymentSharedCertificates(DeploymentEditAction.java:1527)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.admin.infra.action.DeploymentEditAction.createSubmit(DeploymentEditAction.java:1205)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.cisco.cpm.admin.infra.action.DeploymentEditAction.createSubmit(DeploymentEditAction.java:1035)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2018-10-07 21:27:06,220 WARN&amp;nbsp;&amp;nbsp; [Thread-114][] com.cisco.epm.util.NodeCheckHelper -::::- Unable to retrieve the host config from standby pap java.io.IOException: Server returned HTTP response code: 401 for URL:&amp;nbsp; WARNING : This URL stripped from the email as per Company policy&lt;BR /&gt;f.com/deployment-rpc/getNodeConfig?hostname=Secondary.Node&lt;BR /&gt;3dd70-ca00-11e8-b228-843ertchcec::- Setting credentials on http client&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does any one has faced the above issue while joining to the cluster or any suggestion for the above Problem would be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 06:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3725289#M495163</guid>
      <dc:creator>Ali</dc:creator>
      <dc:date>2018-10-15T06:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Joining to the Cluster Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3725310#M495181</link>
      <description>Did you backup your certificates before the update. If yes, go ahead and&lt;BR /&gt;reimport them.&lt;BR /&gt;&lt;BR /&gt;Another option is trying to promote the secondary node as primary then go&lt;BR /&gt;ahead and de-register PSNs then register them again. That might fix&lt;BR /&gt;the problem&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Oct 2018 06:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3725310#M495181</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-10-15T06:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Joining to the Cluster Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3726768#M495187</link>
      <description>&lt;P&gt;Hello Mohammed,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the reply, i re-imported the certificates still Secondary is getting failed to join.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below&amp;nbsp;are the logs .......&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2018-10-05 16:51:19,443 ERROR&amp;nbsp; [pool-46-thread-1][] cisco.cpm.deployment.replication.ReplayerImpl -::::- Could not get all the missing change data records from 4172912 to 4172921&lt;/P&gt;
&lt;P&gt;2018-10-05 16:51:19,443 ERROR&amp;nbsp; [pool-46-thread-1][] cisco.cpm.deployment.replication.ReplayerImpl -::::- Could not apply all missing change records. Expected to apply upto 4227056 but applied only upto 4172911&lt;/P&gt;
&lt;P&gt;2018-10-05 16:51:34,238 INFO&amp;nbsp;&amp;nbsp; [localhost-startStop-2][] cisco.cpm.cluster.impl.ClusterManagerImpl -::::- LocalCluster - Deregistering servicecom.cisco.profiler.api.ProfilerEpRemoteInterface&lt;/P&gt;
&lt;P&gt;2018-10-05 16:51:34,238 INFO&amp;nbsp;&amp;nbsp; [localhost-startStop-2][] cisco.cpm.cluster.impl.ClusterManagerImpl -::::- GlobalCluster - Deregistering servicecom.cisco.profiler.api.ProfilerEpRemoteInterface&lt;/P&gt;
&lt;P&gt;2018-10-05 16:52:09,044 INFO&amp;nbsp;&amp;nbsp; [main][] cisco.epm.fullsync.secondary.SecondarySyncManager -::c7e55690-c868-11e8-b228-843dc6ec40ec:FullSync:- Sending Transient Sync status:DBIMPORT_INITIATED, Node Sync Status: SYNC_INPROGRESS to PAP. Sync req id : c7e55690-c868-11e8-b228-843dc6ec40ec&lt;/P&gt;
&lt;P&gt;2018-10-05 16:52:09,054 INFO&amp;nbsp;&amp;nbsp; [main][] class com.cisco.epm.fullsync.FileUtil -::c7e55690-c868-11e8-b228-843dc6ec40ec:FullSync:- Reading primary node info from : /opt/oracle/base/admin/cpm10/dpdump/config_c7e55690-c868-11e8-b228-843dc6ec40ec.properties&lt;/P&gt;
&lt;P&gt;2018-10-05 16:52:09,054 INFO&amp;nbsp;&amp;nbsp; [main][] class com.cisco.epm.fullsync.HttpClientHelper -::c7e55690-c868-11e8-b228-843dc6ec40ec:FullSync:- syncRequestIdentifier..local value : c7e55690-c868-11e8-b228-843dc6ec40ec &amp;amp; syncRequestIdentifier in config file : c7e55690-c868-11e8-b228-843dc6ec40ec&lt;/P&gt;
&lt;P&gt;2018-10-05 16:52:09,054 INFO&amp;nbsp;&amp;nbsp; [main][] class com.cisco.epm.fullsync.HttpClientHelper -::c7e55690-c868-11e8-b228-843dc6ec40ec:FullSync:- Sending sync status to [https[:]//PrimaryNode.com/deployment-rpc/updateSyncStatus] for syncRequestIdentifier c7e55690-c868-11e8-b228-843dc6ec40ec&lt;/P&gt;
&lt;P&gt;2018-10-05 16:52:09,054 INFO&amp;nbsp;&amp;nbsp; [main][] class com.cisco.epm.fullsync.HttpClientHelper -::c7e55690-c868-11e8-b228-843dc6ec40ec:FullSync:- Creating http connection manager&lt;/P&gt;
&lt;P&gt;2018-10-05 16:53:35,161 INFO&amp;nbsp;&amp;nbsp; [main][] class com.cisco.epm.fullsync.HttpClientHelper -::c7e55690-c868-11e8-b228-843dc6ec40ec::- Setting credentials on http client&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;after this i am not getting any logs.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the 2nd option our customer is not agreeing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 05:05:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3726768#M495187</guid>
      <dc:creator>Ali</dc:creator>
      <dc:date>2018-10-17T05:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Joining to the Cluster Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3726774#M495191</link>
      <description>&lt;P&gt;I would recommend continuing to work with&amp;nbsp;TAC and sharing their findings when it is resolved.&amp;nbsp; If it is impacting production you should ask to escalate the case above a severity 3.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 05:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-joining-to-the-cluster-issue/m-p/3726774#M495191</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-10-17T05:25:41Z</dc:date>
    </item>
  </channel>
</rss>

