<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Secondary Server authentication issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3203365#M553421</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've experienced the same issue. These two new bugs might be related.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CSCvg19243:&amp;nbsp;ISE is sensitive to high values of "Root Dispersion" for NTP server&lt;/P&gt;
&lt;P&gt;CSCvg19246: ISE unable to make persistent changes to ntp.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;workaround is to change&amp;nbsp;ntp.conf file : tos maxdist 16. But if the appliance is reloaded the issue will re-occur. Only TAC can do the workaround&amp;nbsp; by installing root patch.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Oct 2017 08:30:56 GMT</pubDate>
    <dc:creator>Mady</dc:creator>
    <dc:date>2017-10-23T08:30:56Z</dc:date>
    <item>
      <title>ISE Secondary Server authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3202020#M553407</link>
      <description>&lt;P&gt;I have two ISE servers both running version 2.2.0.470.&amp;nbsp; One is a primary located in our data center while the other is a secondary located at a remote site.&amp;nbsp; Secondary acts as the primary auth server for the remote site.&amp;nbsp; Both have been working fine, had one issue where I would got alerts about contacting the DC but a reboot fixed the issue.&amp;nbsp; Today I had an issue that started with the following alerts in order:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NTP Sync Failure\Joined domain is unavailable\AD forest unavailable\AD not &amp;nbsp;joined\AD: Machine TGT refresh failed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried restarting the services which didn't work so I rebooted the server.&amp;nbsp; Everything seemed to be working fine as all the alerts stopped and the status was "operational" as an identity source.&amp;nbsp; Well the alerts stopped but the server is no longer authenticating devices. All devices from the remote site are failing over to the primary.&amp;nbsp; Checked the time on the server, removed the server from the domain and add it back but it still will not authenticate any users.&amp;nbsp; Our primary is authenticating the failed devices but I would like to get the secondary working it’s located at a remote site and the authentication is now being done across a WAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of the dropped authentications show&amp;nbsp; "Failure Reason 11007 could not locate Network Device or AAA Client."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas as to where to look next?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quentin&lt;BR /&gt; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3202020#M553407</guid>
      <dc:creator>quentincorbett</dc:creator>
      <dc:date>2020-02-21T18:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Secondary Server authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3202927#M553411</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/246568"&gt;@quentincorbett&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Wondering if you gave the logs some check. Logs looks pretty much auto explained ""&lt;SPAN&gt;NTP Sync Failure\Joined domain is unavailable\AD forest unavailable\AD not &amp;nbsp;joined\AD: Machine TGT refresh failed""&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ISE is pretty sensitive to NTP. And if this is not properly communicating with AD we can't expect good things.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-If I helped you somehow, please, rate it as useful.-&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2017 16:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3202927#M553411</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-10-21T16:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Secondary Server authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3203365#M553421</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've experienced the same issue. These two new bugs might be related.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CSCvg19243:&amp;nbsp;ISE is sensitive to high values of "Root Dispersion" for NTP server&lt;/P&gt;
&lt;P&gt;CSCvg19246: ISE unable to make persistent changes to ntp.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;workaround is to change&amp;nbsp;ntp.conf file : tos maxdist 16. But if the appliance is reloaded the issue will re-occur. Only TAC can do the workaround&amp;nbsp; by installing root patch.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 08:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3203365#M553421</guid>
      <dc:creator>Mady</dc:creator>
      <dc:date>2017-10-23T08:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Secondary Server authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3203907#M553433</link>
      <description>&lt;P&gt;Thanks for your response but all the errors cleared after a reboot and the ISE server is communicating with the DC but for some reason it is no longer authenticating.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 00:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3203907#M553433</guid>
      <dc:creator>quentincorbett</dc:creator>
      <dc:date>2017-10-24T00:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Secondary Server authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3203909#M553445</link>
      <description>&lt;P&gt;Thanks, I will open a TAC case to see if they can resolve the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 00:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-secondary-server-authentication-issue/m-p/3203909#M553445</guid>
      <dc:creator>quentincorbett</dc:creator>
      <dc:date>2017-10-24T00:05:20Z</dc:date>
    </item>
  </channel>
</rss>

