<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.6 error message in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004863#M543744</link>
    <description>&lt;P&gt;Which logging category need to be set on DEBUG level for these logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Dec 2019 18:31:30 GMT</pubDate>
    <dc:creator>jm.virtual01</dc:creator>
    <dc:date>2019-12-30T18:31:30Z</dc:date>
    <item>
      <title>Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4003727#M543676</link>
      <description>&lt;P&gt;I have upgraded the Cisco ISE 2.2 to 2.6 recently, it is distributed deployment. After teh upgradation, i am seeing this alarm from my primary MnT node;&lt;/P&gt;&lt;P&gt;Error Message:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alarm Name :&lt;/P&gt;&lt;P&gt;Log Collection Error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details :&lt;/P&gt;&lt;P&gt;Syslog parsing error : String index out of range: -1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am not sure about the reason for this alarm but wanted to make this alarm shuts off.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please reply here of anyone has some suggestion for this issue&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2019 18:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4003727#M543676</guid>
      <dc:creator>jm.virtual01</dc:creator>
      <dc:date>2019-12-26T18:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4003899#M543689</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Here i would suggest to open a tac case. I had an issue on the last when ise saw a username with a sign / but it should be solved now.&lt;BR /&gt;</description>
      <pubDate>Fri, 27 Dec 2019 05:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4003899#M543689</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-12-27T05:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004104#M543709</link>
      <description>&lt;P&gt;Thank you Sir,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DO you know from where i can find the string configuration in ISE?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 13:38:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004104#M543709</guid>
      <dc:creator>jm.virtual01</dc:creator>
      <dc:date>2019-12-27T13:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004569#M543728</link>
      <description>You can start looking at the file ise-psc.log.&lt;BR /&gt;But be aware that some of your logging categories must be in debug mode to have a more verbose log.</description>
      <pubDate>Mon, 30 Dec 2019 01:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004569#M543728</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-12-30T01:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004863#M543744</link>
      <description>&lt;P&gt;Which logging category need to be set on DEBUG level for these logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 18:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004863#M543744</guid>
      <dc:creator>jm.virtual01</dc:creator>
      <dc:date>2019-12-30T18:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004865#M543753</link>
      <description>&lt;P&gt;This is the error message i found form the logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2019-12-15 00:02:07,231 WARN [pool-81918-thread-1][] cisco.epm.cert.validator.CRLCache -::::- Unable to download CRL javax.naming.NamingException: [LDAP: error code 1 - 000004DC: LdapErr: DSID-0C090A4C, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v3839 ]; remaining name ''&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any suggestion on this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 18:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4004865#M543753</guid>
      <dc:creator>jm.virtual01</dc:creator>
      <dc:date>2019-12-30T18:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4005704#M543756</link>
      <description>please work through the TAC if not getting resolution for break fix troubleshooting</description>
      <pubDate>Thu, 02 Jan 2020 18:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4005704#M543756</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2020-01-02T18:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.6 error message</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4008579#M543761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/344775"&gt;@jm.virtual01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have seen this since ISE 2.2 - it's due to ISE's attempt at trying to download a CRL by inspecting the CDP (CRL Distribution Point). If the certificate was created using Microsoft CA (which is very common in the Enterprise), then the default template includes the CA's URL as an LDAP address. But ISE has no credentials to bind to that URL using LDAP - hence, it fails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I remember correctly, you can fix that error by specifying a manual CRL URL for every trusted CA cert that you have added in ISE. This then causes ISE to ignore the CDP, and use your manual URL instead.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 06:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-6-error-message/m-p/4008579#M543761</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-01-09T06:10:08Z</dc:date>
    </item>
  </channel>
</rss>

