<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.7 Queue Link Error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274093#M564820</link>
    <description>&lt;P&gt;You can this to fix it yourself, and if that doesn't work, then I would suggest TAC.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;First regenerate the root CA cert for the deployment&lt;/LI&gt;
&lt;LI&gt;Then regenerate the ISE messaging cert for the deployment (selecting all nodes)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Do this from here&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 17 Jan 2021 19:18:02 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2021-01-17T19:18:02Z</dc:date>
    <item>
      <title>Cisco ISE 2.7 Queue Link Error</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274076#M564818</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to know if some1 seen this error as i am not getting this information any place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Queue Link Error: Message=From ISE1 To ISE2; Cause={tls_alert;"handshake Failure"}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help to get this fixed would be great help.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2021 18:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274076#M564818</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2021-01-17T18:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.7 Queue Link Error</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274079#M564819</link>
      <description>&lt;P&gt;Before Installing Ca&lt;BR /&gt;Queue Link Error: Message=From ISE1 To ISE2; Cause={tls_alert;"unknown Ca"}&lt;BR /&gt;Post Installating CA using Multi-Use&lt;BR /&gt;Queue Link Error: Message=From ISE1 To ISE2; Cause={tls_alert;"handshake Failure"}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as we installed External CA using Multi-Use i stared to get this error.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2021 19:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274079#M564819</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2021-01-17T19:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.7 Queue Link Error</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274093#M564820</link>
      <description>&lt;P&gt;You can this to fix it yourself, and if that doesn't work, then I would suggest TAC.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;First regenerate the root CA cert for the deployment&lt;/LI&gt;
&lt;LI&gt;Then regenerate the ISE messaging cert for the deployment (selecting all nodes)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Do this from here&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2021 19:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274093#M564820</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-01-17T19:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.7 Queue Link Error</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274095#M564822</link>
      <description>&lt;P&gt;there is no option for self signed and i have node which integrated with DNAC should i remove all those? or re-generate will effect integration between it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Remove my DNA integration first?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;So i have a 2xNodes which are there so should i re-generate for both Node using generate CSR and then do this?&lt;/P&gt;&lt;P&gt;Please suggest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2021 19:21:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4274095#M564822</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2021-01-17T19:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.7 Queue Link Error</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4283232#M565135</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to update you i was able to fix the issue and it also had a underlying issue of the Root CA and pxgrid integration as well.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So Please find this information for future use as well:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. regenerated the ise messaging certificate --&amp;gt; fixed the queue link error and also i was not able to see my root ca in one of my nodes. before when i was trying to check the certificates it was getting error. post doing that it fixed that certificate pulling&lt;/P&gt;&lt;P&gt;2. regenerated the ise root ca certificate as well --&amp;gt; so far fixing this queue link error regnerated the internal CA certificate which fixed everythig. So ISE got sorted out but now issue was pxgrid certificate was changed so i had to fix the DNA and ISE pxgrid as wel.&lt;/P&gt;&lt;P&gt;3. logged in to DNA --&amp;gt; click on edit and just put your password, DNA will re-integrate itself and issue a new certificate.&lt;/P&gt;&lt;P&gt;4. i learned this also post check the Network setting were giving error post this change so its better to go and re put all the ISE servers and provision or resync your devices to remove that error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So now all is good.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for all the help from tac and support forums.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 04:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4283232#M565135</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2021-02-01T04:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.7 Queue Link Error</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4694279#M577405</link>
      <description>&lt;P&gt;Thank you for that quick and easy tutorial. I was able to fix the QL-Link errors of a couple if ISE clusters in the past by regenerating the root / messaging certs.&lt;/P&gt;
&lt;P&gt;today i encountered an ISE cluster where the option to regenerate those certs is missing:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="samuelheinrich_0-1664263612152.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/163451iC1C8AC2B72F5A983/image-size/medium?v=v2&amp;amp;px=400" role="button" title="samuelheinrich_0-1664263612152.png" alt="samuelheinrich_0-1664263612152.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;is that the case, where i have to engage with TAC or are i'm missing something here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT: I found the answer.&lt;/P&gt;
&lt;P&gt;The internal ISE CA Feature was disabled, thus the options to regenerate ISE Root CAs were missing.&lt;/P&gt;
&lt;P&gt;After I enabled the CA Feature, the options showed up. Enabling the feature was painless, no app server restart required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 16:27:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-7-queue-link-error/m-p/4694279#M577405</guid>
      <dc:creator>samuel.heinrich</dc:creator>
      <dc:date>2022-10-01T16:27:48Z</dc:date>
    </item>
  </channel>
</rss>

