<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Did you install the server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673445#M55285</link>
    <description>&lt;P&gt;Did you install the server certificate of the seconday in the trust certificate list of the primary&lt;/P&gt;&lt;P&gt;I think this is required to enable the communications&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jun 2015 21:16:49 GMT</pubDate>
    <dc:creator>jrabinow</dc:creator>
    <dc:date>2015-06-07T21:16:49Z</dc:date>
    <item>
      <title>ISE- unable to register a node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673444#M55284</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We are trying to integrate a new ISE node as a PSN to our current setup. When we try to register we are getting below error messages. Does anyone has faced same issue. Also need clarity on these&amp;nbsp;error messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When trying to register with IP address we are getting error message as below:&lt;/P&gt;&lt;P&gt;Unable to authenticate &lt;EM&gt;ISE secondary_ise_name&lt;/EM&gt;. Please check server and CA certificate configuration and try again .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When trying to register with FQDN we are getting error message as below&amp;nbsp;:&lt;/P&gt;&lt;P&gt;FQDN 'XYZ.local.com' which cannot be resolved. Please check your DNS configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So need clarity whether this is a DNS or Certificate issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Avinash&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673444#M55284</guid>
      <dc:creator>avinash2092</dc:creator>
      <dc:date>2019-03-11T05:47:11Z</dc:date>
    </item>
    <item>
      <title>Did you install the server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673445#M55285</link>
      <description>&lt;P&gt;Did you install the server certificate of the seconday in the trust certificate list of the primary&lt;/P&gt;&lt;P&gt;I think this is required to enable the communications&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2015 21:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673445#M55285</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2015-06-07T21:16:49Z</dc:date>
    </item>
    <item>
      <title>We are adding this as a pure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673446#M55286</link>
      <description>&lt;P&gt;We are adding this as a pure PSN node. Its certificate has been added in certificate store in primary admin node&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 06:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673446#M55286</guid>
      <dc:creator>avinash2092</dc:creator>
      <dc:date>2015-06-08T06:20:09Z</dc:date>
    </item>
    <item>
      <title>Hi,Please make sure that your</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673447#M55287</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please make sure that your FQDN is resolvable by your ISE.&lt;/P&gt;&lt;P&gt;For that you need to add entry for DNS in your Server.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 07:38:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673447#M55287</guid>
      <dc:creator>krishnangangster</dc:creator>
      <dc:date>2015-06-08T07:38:36Z</dc:date>
    </item>
    <item>
      <title>make sure you have secondary</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673448#M55289</link>
      <description>&lt;P&gt;make sure you have secondary PSN certificate in primary PSN and secondary PSN&amp;nbsp; dns should be resolvable . if still issue check&amp;nbsp; "ise-psc.log"&amp;nbsp; can give you insight&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 09:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673448#M55289</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2015-06-11T09:01:28Z</dc:date>
    </item>
    <item>
      <title>Depending on what version of</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673449#M55290</link>
      <description>&lt;P&gt;Depending on what version of ISE you are running the new PSN MUST have a certificate signed by the same CA Server like the Primary PAN Node.&lt;/P&gt;&lt;P&gt;On Version 1.2 and above, the Primary PAN validates the certificate presented by the new PSN so it can join to the current&amp;nbsp;deployment. In addition to that you MUST have in the DNS an entry for the FQDN of the new PSN. In the previous 1.1.3 version you could include a new PSN only with the IP but this option is NO more available. The Primary PAN Node requests the IP of the new PSN Node from DNS based on the FQDN provided during the join process.&lt;/P&gt;&lt;P&gt;Hoping this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 21:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673449#M55290</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2015-06-11T21:24:09Z</dc:date>
    </item>
    <item>
      <title>When you add the PSN server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673450#M55291</link>
      <description>&lt;P&gt;When you add the PSN server certificate to the trust store in primary, did you tick the "trust for ISE registration"?&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 07:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673450#M55291</guid>
      <dc:creator>alberx</dc:creator>
      <dc:date>2015-08-18T07:28:34Z</dc:date>
    </item>
    <item>
      <title>Hi Alberx, Based on my</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673451#M55292</link>
      <description>&lt;P&gt;Hi Alberx,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on my understanding, you do not need to add the PSN's certificates into the PAN Primary ISE trust store at least on version 1.2.1.198. You only have to install the certificate in the corresponding&amp;nbsp;PSN, that certificate could be a SAN Certificate that includes all the FQDN Names of the ISE&amp;nbsp;nodes in your deployment (actually I am using only 1 common certificate for all&amp;nbsp;my deployment - 12 ISE's)&amp;nbsp;but that certificate must be signed for the same CA Server like Primary PAN Cert.&lt;/P&gt;&lt;P&gt;Regarding the "trust for ISE Registration", I would say YES to tick it because when you are building the deployment, the certificate presented by each PSN or MNT Node to be integrated with&amp;nbsp;the Prim PAN Node is used so PAN Node can check if the CA Server who signed the MNT/PSN cert is a valid one during the registration process.&lt;/P&gt;&lt;P&gt;Hoping this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 19:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/m-p/2673451#M55292</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2015-08-18T19:45:02Z</dc:date>
    </item>
  </channel>
</rss>

