<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iPSK - New ISE PSN node in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4518326#M571646</link>
    <description>&lt;P&gt;Like Thomas said, do refer to that guide. Also, use another MySQL client on a Windows or macOS or Linux to test and verify the connectivity and the credentials for the user&amp;nbsp;ipsk-ise-user.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Dec 2021 02:47:56 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2021-12-14T02:47:56Z</dc:date>
    <item>
      <title>iPSK - New ISE PSN node</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4516043#M571573</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Reaching out here and hopefully someone can help me. We have a working iPSK server that is connected to our ISE deployment.&lt;BR /&gt;&lt;BR /&gt;I'm currently installing new ISE PSN nodes but am getting issues with having the new nodes speaking with the iPSK portal.&lt;BR /&gt;&lt;BR /&gt;On ISE I can only see that it fails to query the database.&lt;/P&gt;&lt;P&gt;24878 Retry failed ODBC operation&lt;BR /&gt;24849 Connecting to external ODBC database&lt;BR /&gt;24851 Connection to external ODBC database failed&lt;BR /&gt;24874 Fetching of the user attributes in external ODBC database failed&lt;BR /&gt;15048 Queried PIP - iPSK.ExternalGroups&lt;BR /&gt;24869 Perform fetching of the user groups in external ODBC database&lt;BR /&gt;24849 Connecting to external ODBC database&lt;BR /&gt;24851 Connection to external ODBC database failed&lt;BR /&gt;24878 Retry failed ODBC operation&lt;BR /&gt;24849 Connecting to external ODBC database&lt;BR /&gt;24851 Connection to external ODBC database failed&lt;BR /&gt;24871 Fetching of the user groups in external ODBC database failed&lt;BR /&gt;24872 Perform fetching of the user attributes in external ODBC database&lt;BR /&gt;24849 Connecting to external ODBC database&lt;BR /&gt;24851 Connection to external ODBC database failed&lt;BR /&gt;24878 Retry failed ODBC operation&lt;BR /&gt;24849 Connecting to external ODBC database&lt;BR /&gt;24851 Connection to external ODBC database failed&lt;BR /&gt;24874 Fetching of the user attributes in external ODBC database failed&lt;BR /&gt;15048 Queried PIP - iPSK.ExternalGroups&lt;BR /&gt;24869 Perform fetching of the user groups in external ODBC database&lt;BR /&gt;24849 Connecting to external ODBC database&lt;BR /&gt;24851 Connection to external ODBC database failed&lt;BR /&gt;24878 Retry failed ODBC operation&lt;BR /&gt;According to the firewall in between all traffic is allowed.&lt;BR /&gt;&lt;BR /&gt;A packet capture on the IPSK shows:&lt;BR /&gt;ISE PSN -&amp;gt; IPSK - [SYN]&lt;BR /&gt;IPSK -&amp;gt; ISE PSN - [SYN, ACK]&lt;BR /&gt;ISE PSN -&amp;gt; IPSK - [ACK]&lt;BR /&gt;&lt;STRONG&gt;IPSK -&amp;gt; ISE PSN - [MySQL server greeting]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ISE PSN -&amp;gt; IPSK -&amp;gt; [RST, ACK]&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Packet capture from the ISE shows:&lt;BR /&gt;ISE PSN -&amp;gt; IPSK - [SYN]&lt;BR /&gt;IPSK -&amp;gt; ISE PSN - [SYN, ACK]&lt;BR /&gt;ISE PSN -&amp;gt; IPSK - [ACK]&lt;BR /&gt;&lt;STRONG&gt;IPSK -&amp;gt; ISE PSN -&amp;gt; [RST, ACK]&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Compared with a capture on our working setup this looks very different.&lt;BR /&gt;&lt;BR /&gt;I've been suspecting that something in the iPSK Linux Server (MySQL server) is only allowing connections from certain hosts but haven't been able to find anything in any config file. Neither is the IPTables blocking anything.&lt;BR /&gt;&lt;BR /&gt;Please let me know if anyone can give me any pointers on what I could check. I could share PCAP screenshoots (with sensitive information blurred) if needed. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 15:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4516043#M571573</guid>
      <dc:creator>stefan.tabell</dc:creator>
      <dc:date>2021-12-09T15:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: iPSK - New ISE PSN node</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4518097#M571622</link>
      <description>&lt;P&gt;By "iPSK server" I assume you mean an instance of the &lt;STRONG&gt;&lt;A href="https://github.com/CiscoDevNet/iPSK-Manager" target="_self"&gt;iPSK Manager&lt;/A&gt;&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;You did not explicitly state if that is the software you are using or if you are using your own custom software.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you follow the &lt;LI-MESSAGE title="iPSK (Identity Pre-Shared-Key) Manager portal server for ISE" uid="3904265" url="https://community.cisco.com/t5/security-documents/ipsk-identity-pre-shared-key-manager-portal-server-for-ise/m-p/3904265#U3904265"&gt;&lt;/LI-MESSAGE&gt; guide to get it configured?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 18:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4518097#M571622</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-13T18:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: iPSK - New ISE PSN node</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4518326#M571646</link>
      <description>&lt;P&gt;Like Thomas said, do refer to that guide. Also, use another MySQL client on a Windows or macOS or Linux to test and verify the connectivity and the credentials for the user&amp;nbsp;ipsk-ise-user.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 02:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4518326#M571646</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-12-14T02:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: iPSK - New ISE PSN node</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4520429#M571781</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for responding. It is indeed the Cisco iPSK manager that I'm working with.&lt;/P&gt;&lt;P&gt;It was setup by my predecessor according to the guide, but not sure if he took extra steps to add security. What I can say is that we have several PSN nodes that the setup is working with, it's just the new PSNs it doesn't work for. Almost like the MySQL service doesn't allow for connections from those hosts.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 09:38:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4520429#M571781</guid>
      <dc:creator>stefan.tabell</dc:creator>
      <dc:date>2021-12-17T09:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: iPSK - New ISE PSN node</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4521577#M571842</link>
      <description>&lt;P&gt;Hi, after some further digging I found that a firewall on the path was blocking the mysql traffic (but it allowed the traffic on TCP3306 where it was establishing the TCP session with 3-way handshake).&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 12:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-new-ise-psn-node/m-p/4521577#M571842</guid>
      <dc:creator>stefan.tabell</dc:creator>
      <dc:date>2021-12-20T12:51:48Z</dc:date>
    </item>
  </channel>
</rss>

