<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE NTP Misbehaviour in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590631#M538607</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;okay, will do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Jun 2016 20:24:58 GMT</pubDate>
    <dc:creator>Christopher Hobbs</dc:creator>
    <dc:date>2016-06-14T20:24:58Z</dc:date>
    <item>
      <title>ISE NTP Misbehaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590627#M538603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;Over the weekend, we upgraded an ISE 1.3 system from patch 3 to patch 7. After the upgrade we observed client connectivity issues (for static IP devices and&amp;nbsp; decided to roll back.&amp;nbsp; We then noticed that NTP synchronization was not functioning. We tried to restart services and found they would restart and then shutdown after a few minutes.&amp;nbsp; The only way to fix this was to correct the local time on the ESXI host (which was about 70 minutes behind true time).&amp;nbsp; We also noticed high NTP jitter and fluctuating low and high ping RTTs.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;Can you help answer the following questions...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;1) What is the expected application behavior for a large 16 node cluster when NTP becomes unreliable - I.e. NTP clock sync experiences high jitter?&amp;nbsp; How does it impact patch upgrades and how does it impact client authentications?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;2) What is the expected behavior when there is time discrepancy between the local clock defined on the ESXI host and the local clock configured on the ISE (if NTP is unreliable)? Is there a reliance between the&amp;nbsp; local ESXI host clock and the local ISE-VM clock, and which is master?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;3) What issues would you expect if a customer enables NTP client on ESXI host that the ISE-VM is installed on?&amp;nbsp; I believe we recommend against enabling this, but what bad things would happen?&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;4) Can you supply a link to explain the different fields in the "show ntp" CLI output?&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;Thanks&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman';"&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2016 00:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590627#M538603</guid>
      <dc:creator>Christopher Hobbs</dc:creator>
      <dc:date>2016-06-14T00:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE NTP Misbehaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590628#M538604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE would get the base time from the host VM, this should be stable and accurate to start. Think of having an appliance and relying on the underlying hardware to get your base time. This needs to be stable first before looking external.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you will need to point to a stable trusted time source in your organization for best support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the recommended resources.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_0100.html#ID96" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_0100.html#ID96"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.0 - Administer Cisco ISE [Cisco Identity Services Engine]…&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp6428581100" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp6428581100"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp6428581100&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp2638879531" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp2638879531"&gt;Cisco Identity Services Engine CLI Reference Guide, Release 2.0 - Cisco ISE CLI Commands in Configuration Mode [Cisco I…&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2016 14:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590628#M538604</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-06-14T14:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE NTP Misbehaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590629#M538605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason - but I'd like to understand how ISE behaves when NTP is unreliable to see if it matches some of the issues we experienced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During testing, we observed NTP would switch between sync and unsync and would like to know what values trigger that.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;below are cli outputs of "show ntp" when it is in using local and sync'd time.&amp;nbsp; The big concern are the offset and jitter values, and we need to understand what is causing that, especially when the delay values are relatively low (4.3-4.5ms).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;#sh ntp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;synchronised to local net at stratum 11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; time correct to within 73 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; polling server every 64 s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; remote&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; refid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; st t when poll reach&amp;nbsp; delay&amp;nbsp; offset&amp;nbsp; jitter&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;==============================================================================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;*127.127.1.0&amp;nbsp;&amp;nbsp;&amp;nbsp; .LOCL.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 l&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; 64&amp;nbsp; 177&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000&amp;nbsp; 0.000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;lt;NTP1&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;NTP1&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 u&amp;nbsp; 53&amp;nbsp; 64&amp;nbsp; 177&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.589&amp;nbsp; 30622.7 17270.7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;lt;NTP2&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;NTP2&amp;gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 u&amp;nbsp; 42&amp;nbsp; 64&amp;nbsp; 177&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.303&amp;nbsp; 46425.1 27940.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;#sh ntp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;synchronised to NTP server (&amp;lt;NTP 2&amp;gt;) at stratum 11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; time correct to within 209 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; polling server every 64 s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; remote&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; refid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; st t when&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; poll&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; reach&amp;nbsp; delay&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; offset&amp;nbsp;&amp;nbsp;&amp;nbsp; jitter&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;==============================================================================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;127.127.1.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .LOCL.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 l&amp;nbsp; 43&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 64&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 377&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;lt;NTP1&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;NTP1&amp;gt; &lt;/SPAN&gt;&amp;nbsp; 6 u&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 64&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 377&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.382&amp;nbsp;&amp;nbsp;&amp;nbsp; 240.283&amp;nbsp; 36.614&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;*&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;lt;NTP2&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;NTP2&amp;gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 u&amp;nbsp;&amp;nbsp;&amp;nbsp; 9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 64&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 377&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.534&amp;nbsp;&amp;nbsp;&amp;nbsp; 270.101&amp;nbsp; 30.531&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV align="center" style="font-size: 11pt; font-family: Calibri; color: #000000; text-align: center;"&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2016 20:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590629#M538605</guid>
      <dc:creator>Christopher Hobbs</dc:creator>
      <dc:date>2016-06-14T20:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE NTP Misbehaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590630#M538606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would be best to gather the logs and work with the TAC to better understand what is happening and if it is still happening to gather some network traces and debugs as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2016 20:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590630#M538606</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-06-14T20:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE NTP Misbehaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590631#M538607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;okay, will do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2016 20:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ntp-misbehaviour/m-p/3590631#M538607</guid>
      <dc:creator>Christopher Hobbs</dc:creator>
      <dc:date>2016-06-14T20:24:58Z</dc:date>
    </item>
  </channel>
</rss>

