<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I'm using ISE 2.0.306 with in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792970#M56807</link>
    <description>&lt;P&gt;I'm using ISE 2.0.306 with PI3 P1 and have the same issue. Any news from BU?&lt;/P&gt;</description>
    <pubDate>Sat, 12 Dec 2015 14:39:48 GMT</pubDate>
    <dc:creator>cisco_tac_cr</dc:creator>
    <dc:date>2015-12-12T14:39:48Z</dc:date>
    <item>
      <title>Prime Infrastructure integration with ISE 2.0 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792968#M56799</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;I recently upgraded an ISE 1.4 (patch3) distributed deployment to version 2.0.0.306 to fix a known bug. The upgrade was successful in fixing the bug but seems to have broke Prime Infrastructure&amp;nbsp;integration.&lt;/P&gt;
&lt;P&gt;After the ISE upgrade, Prime Infrstructure's ISE server (the ISE deployment's primary pan/mnt node) is listed as unreachable.PI version is 2.2.&lt;/P&gt;
&lt;P&gt;When I try and make changes to PI's ISE server I get the error:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Identity Services Engine update failed : Some unexpected internal error has occurred. If the problem persists please report to the Tech Support&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I tried integrating PI 3.0 with the upgraded ISE but when I try and add the ISE 2.0 server I get the error:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Error(s): You must correct the following error(s) before proceeding:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Error: The connection to Identity Services Engine with IP Address &amp;lt;ISE_IP&amp;gt; has timed out. Please check the network connectivity and the user account status on the Identity Services Engine&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;A TCP dump on ISE for both PI 2.2 and 3.0 show a TLS 1.2 Handshake Failure (40). I found a similar issue in the following thread:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;A href="https://supportforums.cisco.com/discussion/12615841/cisco-prime-infrastructure-and-ise-integration" target="_blank"&gt;https://supportforums.cisco.com/discussion/12615841/cisco-prime-infrastructure-and-ise-integration&lt;/A&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I don't have access to view the bug CSCur43834 - can anyone tell me if this affects my environment of ISE 2.0.0.306 and PI 2.2.0/3.0&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;
&lt;P&gt;ps ISE uses 3rd party certificates for EAP/GUi and work fine - root/intermediate are listed in ISE as trusted&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792968#M56799</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-03-11T06:12:57Z</dc:date>
    </item>
    <item>
      <title>Tested this with latest</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792969#M56803</link>
      <description>&lt;P&gt;Tested this with latest versions of PI (3.01 and 2.2.3) and saw the same issue. PI sends a client hello with TLS version 1.0 and ISE 2.0 responds with handshake failure with TLS version 1.2.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Contacted TAC - PI isn't currently compatible with ISE 2.0 for integration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 07:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792969#M56803</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2015-11-10T07:21:21Z</dc:date>
    </item>
    <item>
      <title>I'm using ISE 2.0.306 with</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792970#M56807</link>
      <description>&lt;P&gt;I'm using ISE 2.0.306 with PI3 P1 and have the same issue. Any news from BU?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 14:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792970#M56807</guid>
      <dc:creator>cisco_tac_cr</dc:creator>
      <dc:date>2015-12-12T14:39:48Z</dc:date>
    </item>
    <item>
      <title>I spoke with the TAC on this</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792971#M56809</link>
      <description>&lt;P&gt;I spoke with the TAC on this issue just yesterday.&lt;/P&gt;
&lt;P&gt;The issue is indeed arising from a TLS handshake error. I grabbed a packet capture from my lab system and see it as well. The TAC engineer confirmed this is the root cause.&lt;/P&gt;
&lt;P&gt;BugID&amp;nbsp;&lt;SPAN&gt;CSCur43834, while similar, is confirmed NOT to be the one affecting ISE 2.0. There is a new bugID (not published publicly yet) that covers this particular issue. I didn't get the ID from the TAC engineer.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The TAC engineer told me that BU that owns Prime Infrastructure has slated PI 3.1 to include a fix for this behavior. The projected release date is February 2016.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 19:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792971#M56809</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-12T19:08:00Z</dc:date>
    </item>
    <item>
      <title>Still not supported. Cisco</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792972#M56812</link>
      <description>&lt;P&gt;Still not supported. Cisco software is getting worse and worse. Tried to upgrade a Cisco 3850 stack with PI to Denali and ended in a boot loop.&lt;BR /&gt;&lt;BR /&gt;Prime/Ise/Denali feel like a beta test&amp;nbsp;@the customer...&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 06:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792972#M56812</guid>
      <dc:creator>Patrik Rapposch</dc:creator>
      <dc:date>2016-01-27T06:54:26Z</dc:date>
    </item>
    <item>
      <title>Good afternoon. There were</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792973#M56815</link>
      <description>&lt;P&gt;Good afternoon. &lt;BR /&gt;There were news? Same problem...&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 05:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792973#M56815</guid>
      <dc:creator>diesel315</dc:creator>
      <dc:date>2016-02-25T05:11:35Z</dc:date>
    </item>
    <item>
      <title>Ciao Andrew,</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792974#M56817</link>
      <description>&lt;P&gt;Ciao Andrew,&lt;/P&gt;
&lt;P&gt;do you have BugID? Cannot associate ISE (2.0 patch 2) on PI (2.2).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 13:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792974#M56817</guid>
      <dc:creator>Marco Aresu</dc:creator>
      <dc:date>2016-03-02T13:35:49Z</dc:date>
    </item>
    <item>
      <title>Hi Marco. I didn't get a</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792975#M56822</link>
      <description>&lt;P&gt;Hi Marco. I didn't get a BugID from TAC. I was told this would be fixed early 2016 in PI 3 (no mention of this being fixed with PI 2.X). Other posters indicate this will be fixed in the yet unreleased PI 3.1&lt;/P&gt;
&lt;P&gt;hth&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 13:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792975#M56822</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2016-03-02T13:51:41Z</dc:date>
    </item>
    <item>
      <title>Just installed the newest</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792976#M56824</link>
      <description>&lt;P&gt;Just installed the newest update - Prime 3.0.3 released 15MAR2016 and the issue is still not resolved.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The BU had relayed in the past that the Fix for this issue would be out by the end of February and that Prime 3.1 would be released by the end of the First quarter. Needless to say this was also back in January so the timelines could have changed.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 15:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792976#M56824</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2016-03-18T15:08:21Z</dc:date>
    </item>
    <item>
      <title>According to presentations</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792977#M56830</link>
      <description>&lt;P&gt;According to presentations given during Cisco Live Berlin, Prime 3.1 is due out this month.&lt;/P&gt;
&lt;P&gt;See BRKNMS-2701, slide 199:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Prime Infrastructure 3.1 Highlights&lt;BR /&gt;Available March 2016&lt;/P&gt;
&lt;P&gt;NEW SWIM Workflow– support for external 3rd party S/FTP servers for distributed distribution&lt;BR /&gt;Enhanced Config baseline Compliance –&lt;BR /&gt;Support for AirOS and the ability to e-mail reports/job results&lt;BR /&gt;Global Variable across all templates– Define configuration variables and use them across any/all templates&lt;BR /&gt;Global Search from Web Search Bar– search configs, clients, devices etc. e.g. search for serial numbers within search bar, search for every config that has "no aaa new-model"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Sun, 20 Mar 2016 14:38:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792977#M56830</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-20T14:38:57Z</dc:date>
    </item>
    <item>
      <title>On an unrelated note, the</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792978#M56834</link>
      <description>&lt;P&gt;On an unrelated note, the ability to search configs is a nice step in the right direction.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 13:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792978#M56834</guid>
      <dc:creator>Toivo Voll</dc:creator>
      <dc:date>2016-03-21T13:02:29Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792979#M56836</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No Prime 3.1 yet. I asked our Cisco SE contact the other week when it is due, he said heard end of March, just watched the ciscolive presentation, now says April.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2016 19:37:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792979#M56836</guid>
      <dc:creator>Craig Le-Butt</dc:creator>
      <dc:date>2016-04-02T19:37:58Z</dc:date>
    </item>
    <item>
      <title>Don't bother with installing</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792980#M56840</link>
      <description>&lt;P&gt;Don't bother with installing Prime 3.1,&amp;nbsp;ISE 2.0 integration does not work with Prime 3.1 either:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just upgraded Prime to 3.1.0.0.132 (via upgrade bundle), &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Version information of installed applications&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;---------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cisco Prime Infrastructure&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;********************************************************&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Version : 3.1.0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Build : 3.1.0.0.132&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;still not able to connect to ISE 2.0:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cisco Identity Services Engine&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;---------------------------------------------&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Version : 2.0.1.130&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Build Date : Thu Mar 3 02:38:48 2016&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;same error message as before: "Some unexpected internal error has occured. ....."&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rgs&lt;/P&gt;
&lt;P&gt;Frank&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 08:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792980#M56840</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2016-04-26T08:26:34Z</dc:date>
    </item>
    <item>
      <title>UPS !!!</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792981#M56842</link>
      <description>&lt;P&gt;&lt;STRONG&gt;UPS !!!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Seems that I was wrong with the last post, the user-id that is used by Prime to connect to ISE was disabled on ISE.... !!!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Adding ISE monitoring nodes to Prime works now, nevertheless, the error message is quite confusing !!!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 08:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792981#M56842</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2016-04-26T08:44:24Z</dc:date>
    </item>
    <item>
      <title>Hello Frank ,</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792982#M56843</link>
      <description>&lt;P&gt;Hello Frank ,&lt;/P&gt;
&lt;P&gt;Could you please elaborate how to enable the user-id on ISE and which user-id the PI was using to try to connect to ISE ? Is it the " web_root " user-id ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 06:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792982#M56843</guid>
      <dc:creator>uma dash</dc:creator>
      <dc:date>2016-05-12T06:17:05Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792983#M56845</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;the userid which is used by PI to connect to ISE has to be configured on ISE as an "Admin User" account (Administration/Admin Access/Admin Users).&lt;/P&gt;
&lt;P&gt;This would be a GUI Admin account, not a CLI admin ......!!!&lt;/P&gt;
&lt;P&gt;In my case I have given this user an recognizable name (CPItoISE), gave a password to it, enabled it ("Change Status") and granted "Super Admin" role to it.&lt;/P&gt;
&lt;P&gt;I don't know, if this would also work with a role with lesser rights (haven't checked that out yet, still a test deployment ....).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/admin_users_0.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rgs&lt;/P&gt;
&lt;P&gt;Frank&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 13:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792983#M56845</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2016-05-12T13:32:25Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792984#M56846</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;ISE 2.0&amp;nbsp;requires PI 3.1.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/compatibility/ise_sdt.html#pgfId-216582"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/compatibility/ise_sdt.html#pgfId-216582&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 06:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/2792984#M56846</guid>
      <dc:creator>jedolphi</dc:creator>
      <dc:date>2016-07-06T06:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/3341159#M56847</link>
      <description>&lt;P&gt;worked for me , thanks&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 12:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-integration-with-ise-2-0-issue/m-p/3341159#M56847</guid>
      <dc:creator>amolchavan</dc:creator>
      <dc:date>2018-03-02T12:10:59Z</dc:date>
    </item>
  </channel>
</rss>

