<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic on port TCP/9399 between primary and secondary administrative nodes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441784#M526254</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will see if I can get that information, but it seems to have coincided with the moment we were re-building the Elastic Search DB (as per the notes for CSCvh48558, in a distributed deployment with PAN and SAN).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 May 2018 17:20:22 GMT</pubDate>
    <dc:creator>giosif</dc:creator>
    <dc:date>2018-05-21T17:20:22Z</dc:date>
    <item>
      <title>Traffic on port TCP/9399 between primary and secondary administrative nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441782#M526248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Working with a customer ISE deployment (version 2.2 patch 7) and we are seeing traffic between the PAN and the SAN on port TCP/9399.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Q1: Can someone please tell me what that port is used for?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The closest thing I could find the documentation was TCP/9300 for Elastic Search, but that's a bit far off from what we are seeing.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Q2: Is the use of this port intentional?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If so, we need to include it in our documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If not, then I guess this is a bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, in case anyone asks, I can confirm the source port for this traffic was an ephemeral one (i.e. different from one connection to another, with a random value and above 1024).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 15:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441782#M526248</guid>
      <dc:creator>giosif</dc:creator>
      <dc:date>2018-05-21T15:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic on port TCP/9399 between primary and secondary administrative nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441783#M526251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not aware any ISE services using it.&lt;/P&gt;&lt;P&gt;Please use ISE admin CLI "show tech" and look for "netstat -tunap...", which will give us an idea which program name is using it. Below is a sample output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;*****************************************&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;Running netstat -tunap...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;*****************************************&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;Active Internet connections (servers and established)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;Proto Recv-Q Send-Q Local Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Foreign Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PID/Program name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 127.0.0.1:6379&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0:*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LISTEN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 28529/redis-server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 127.0.0.1:31755&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0:*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LISTEN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 28319/timestensubd&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 127.0.0.1:25550&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0:*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LISTEN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 28324/ttcserver&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 17:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441783#M526251</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-21T17:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic on port TCP/9399 between primary and secondary administrative nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441784#M526254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will see if I can get that information, but it seems to have coincided with the moment we were re-building the Elastic Search DB (as per the notes for CSCvh48558, in a distributed deployment with PAN and SAN).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 17:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441784#M526254</guid>
      <dc:creator>giosif</dc:creator>
      <dc:date>2018-05-21T17:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic on port TCP/9399 between primary and secondary administrative nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441785#M526257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I was able to replicate this in the lab, by doing an Context Visibility reset between a PAN and a SAN (i.e. "application configure ise" -&amp;gt; option 19):&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117174_1.png" style="height: 133px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The below logs are from the SAN:&lt;/P&gt;&lt;P&gt;logs/ise-elasticsearch.log:[2018-05-22 07:32:44,987][INFO ][transport&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] [testice02] publish_address {testice02.&amp;lt;&amp;lt;EDITED&amp;gt;&amp;gt;/172.20.10.21:&lt;STRONG&gt;9399&lt;/STRONG&gt;}, bound_addresses {172.20.10.21:&lt;STRONG&gt;9399&lt;/STRONG&gt;} logs/ise-elasticsearch.log:[2018-05-22 07:32:49,567][INFO ][cluster.service&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] [testice02] new_master {testice02}{eWJ8Xpa1TQClTWZmqTfxIg}{172.20.10.21}{testice02.&amp;lt;&amp;lt;EDITED&amp;gt;&amp;gt;/172.20.10.21:&lt;STRONG&gt;9399&lt;/STRONG&gt;}, reason: zen-disco-join(elected_as_master, [0] joins received) logs/ise-elasticsearch.log:[2018-05-22 07:33:46,552][WARN ][discovery.zen.ping.unicast] [testice02] [1] failed send ping to {#zen_unicast_1#}{172.20.10.20}{testice01.&amp;lt;&amp;lt;EDITED&amp;gt;&amp;gt;/172.20.10.20:9399}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime, I was also able to confirm with someone from the BU that this is a new port being used.&lt;/P&gt;&lt;P&gt;It just needs to be added to the documentation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 09:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/traffic-on-port-tcp-9399-between-primary-and-secondary/m-p/3441785#M526257</guid>
      <dc:creator>giosif</dc:creator>
      <dc:date>2018-05-22T09:38:23Z</dc:date>
    </item>
  </channel>
</rss>

