<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi RG, I'm having the same in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724091#M57428</link>
    <description>&lt;P&gt;Hi RG,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having the same problem. A TCPDump on ISE shows that ISE is replying with a TLSv1 "handshake failure" to Prime's SSLv2 "client hello".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If possible, keep this post updated with TACs reply. My environment:&lt;/P&gt;&lt;P&gt;Prime: 2.1.0.0.87&lt;/P&gt;&lt;P&gt;ISE: 1.4.0.253 patch 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2015 08:06:06 GMT</pubDate>
    <dc:creator>tjoliveira</dc:creator>
    <dc:date>2015-09-29T08:06:06Z</dc:date>
    <item>
      <title>Cisco Prime Infrastructure and ISE Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724084#M57393</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm current struggling to get PI and ISE to integrate, these are running:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISE 1.3.0.876&lt;/LI&gt;&lt;LI&gt;PI 2.1.0.0.87&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;To integrate ISE with PI, on the PI server I browse to&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Design &amp;gt; Management Tools &amp;gt;External Management Servers &amp;gt;&amp;nbsp;&amp;nbsp; ISE Servers&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;I enter all the correct details but I get an error message:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Error: Identity Service Engine with IP Address XXX.XXX.XXX.XXX is not reachable. Please check the network connectivity of the Identity Services Engine.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Both devices are in the same subnet, there’s no filtering taking place. Both servers can see each other without an issue. From the CLI I can confirm I can see an ARP and can ping each other without issue. Both the CPI primary and ISE Primary server are located on the same ESX host.&lt;/P&gt;&lt;P&gt;Any ideas?????&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:05:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724084#M57393</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2019-03-11T06:05:40Z</dc:date>
    </item>
    <item>
      <title>Is your ISE deployment single</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724085#M57400</link>
      <description>&lt;P&gt;Is your ISE deployment single node? If it's distributed, you should be pointing to the M&amp;amp;T server(s).&lt;/P&gt;&lt;P&gt;We recently discussed &lt;A href="https://supportforums.cisco.com/discussion/12609076/pi30-and-ise-integration"&gt;over in the Network Management forum&lt;/A&gt; where I showed some examples.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 12:30:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724085#M57400</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-25T12:30:58Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,This was sourced</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724086#M57405</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;This was sourced from my primary MnT/PAN (Primary for both roles at present)&lt;/P&gt;&lt;P&gt;Do you think its a version conflict?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;RG&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 12:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724086#M57405</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2015-09-25T12:49:39Z</dc:date>
    </item>
    <item>
      <title>I doubt it's a version</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724087#M57414</link>
      <description>&lt;P&gt;I doubt it's a version conflict. I've integrated ISE 1.2, 1.3 and 1.4 with PI 2.0, 2.1 and 2.2 at various times (though I can't say with certainty I've done your exact mix).&lt;/P&gt;&lt;P&gt;If I were troubleshooting I'd dig into the packets a bit to see what's going on (or open a TAC case). You can initiate a packet capture from either system - PI from the root shell or ISE from the troubleshooting tools in the GUI.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 12:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724087#M57414</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-25T12:55:01Z</dc:date>
    </item>
    <item>
      <title>Just to confirm, I have also</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724088#M57416</link>
      <description>&lt;P&gt;Just to confirm, I have also moved the roles over but still seeing the same error..&lt;/P&gt;&lt;TABLE border="1" cellpadding="1" cellspacing="1" style="width: 500px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Host&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;PAN&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;MnT&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;PSN&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;DC1 Server 1&lt;/TD&gt;&lt;TD&gt;PRI&lt;/TD&gt;&lt;TD&gt;SEC&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;DC2 Server 1&lt;/TD&gt;&lt;TD&gt;SEC&lt;/TD&gt;&lt;TD&gt;PRI&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;DC1 Server 2&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;YES&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;DC2 Server 2&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;YES&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 13:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724088#M57416</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2015-09-25T13:02:47Z</dc:date>
    </item>
    <item>
      <title>Marvin,great shout on the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724089#M57425</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;&lt;P&gt;great shout on the packet capture.. looks like I have a TLS/SSL issues which I think I known why.. I'll keep you posted.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;RG&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 13:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724089#M57425</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2015-09-25T13:18:26Z</dc:date>
    </item>
    <item>
      <title>I thought the issue was due</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724090#M57426</link>
      <description>&lt;P&gt;I thought the issue was due to a certificate issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have updated the management certificates on all ISE and PI servers, these&amp;nbsp;are allocated via our internal CA. The management certificates have been working not throwing errors since they were installed (my laptop has the CA certs installed via AD CS)&lt;/P&gt;&lt;P&gt;On the ISE servers I had&amp;nbsp;uploaded&amp;nbsp;the CA certs but missed this off the PI servers. I presumed it was due to the PI not trusting the certificate allocated to the ISE server (As it didn't have the CA certs). After updating the CA certs I still get the same issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do see a TLSv1 Handshake error in the packet capture, this hasn't&amp;nbsp;changed&amp;nbsp;post CA cert upload.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Going to raise a TAC case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 09:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724090#M57426</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2015-09-28T09:10:02Z</dc:date>
    </item>
    <item>
      <title>Hi RG, I'm having the same</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724091#M57428</link>
      <description>&lt;P&gt;Hi RG,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having the same problem. A TCPDump on ISE shows that ISE is replying with a TLSv1 "handshake failure" to Prime's SSLv2 "client hello".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If possible, keep this post updated with TACs reply. My environment:&lt;/P&gt;&lt;P&gt;Prime: 2.1.0.0.87&lt;/P&gt;&lt;P&gt;ISE: 1.4.0.253 patch 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 08:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724091#M57428</guid>
      <dc:creator>tjoliveira</dc:creator>
      <dc:date>2015-09-29T08:06:06Z</dc:date>
    </item>
    <item>
      <title>Interesting. I wonder what</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724092#M57429</link>
      <description>&lt;P&gt;Interesting. I wonder what would happen if you imported the Prime Infrastructure server certificate into ISE's store as a trusted certificate.&lt;/P&gt;&lt;P&gt;Are both ISE and PI certificates issues from the same trusted root CA. Do you have any intermediate certificates loaded into ISE in addition to the root?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 10:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724092#M57429</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-29T10:58:13Z</dc:date>
    </item>
    <item>
      <title>If I can answer with my case,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724093#M57430</link>
      <description>&lt;P&gt;If I can answer with my case, the SSL breaks just after the first client hello, the server certificate is not even changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering if it's not because ISE don't accept any of the ciphers proposed by Prime (see attached).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 15:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724093#M57430</guid>
      <dc:creator>tjoliveira</dc:creator>
      <dc:date>2015-09-29T15:50:33Z</dc:date>
    </item>
    <item>
      <title>TJ - that might very well be</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724094#M57431</link>
      <description>&lt;P&gt;TJ - that might very well be the case.&lt;/P&gt;&lt;P&gt;I came across a handy utility use for nmap to check supported cipher specs on a host. You might give it a whirl to check your hypothesis:&lt;/P&gt;&lt;P&gt;https://nmap.org/nsedoc/scripts/ssl-enum-ciphers.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 16:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724094#M57431</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-29T16:13:23Z</dc:date>
    </item>
    <item>
      <title>TAC have informed me this is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724095#M57432</link>
      <description>&lt;P&gt;TAC have informed me this is a bug, you need to upgrade via a patch which is downloadable from CCO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The bug ID is&amp;nbsp;CSCur43834&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not completed the patch as yet, I will keep you posted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RG&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 16:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724095#M57432</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2015-09-29T16:53:32Z</dc:date>
    </item>
    <item>
      <title>RG,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724096#M57433</link>
      <description>&lt;P&gt;RG,&lt;/P&gt;
&lt;P&gt;Were you ever able to get this patch?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 00:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724096#M57433</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-03T00:04:20Z</dc:date>
    </item>
    <item>
      <title>Yes, installed and working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724097#M57434</link>
      <description>&lt;P&gt;Yes, installed and working without issue since.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;RG&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 00:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724097#M57434</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2015-12-03T00:34:44Z</dc:date>
    </item>
    <item>
      <title>Thanks for the update. I'll</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724098#M57435</link>
      <description>&lt;P&gt;Thanks for the update. I'll open a TAC case myself to get it now that I've run across the same issue. I had forgotten this thread conversation until Google reminded me. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I see the same TLS 1.0 - 1.2 negotiation failure you ran across when I did a tcpdump from ISE 2.0. It even happens with PI 3.02. The BugID still isn't public. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 01:42:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724098#M57435</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-03T01:42:39Z</dc:date>
    </item>
    <item>
      <title>FYI the BugID you cited is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724099#M57436</link>
      <description>&lt;P&gt;FYI the BugID you cited is only applicable to the ISE 1.x and PI2.x scenario.&lt;/P&gt;
&lt;P&gt;The integration is broken (again) in ISE 2.0 - PI 3.0. There's an unpublished BugID on the issue.&lt;/P&gt;
&lt;P&gt;My TAC engineer told me that PI 3.1 (ca. February 2016) will fix it.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2015 16:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-infrastructure-and-ise-integration/m-p/2724099#M57436</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-13T16:05:53Z</dc:date>
    </item>
  </channel>
</rss>

