<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Queue Link Error: Message=From Primary_ISE To Secondary_ISE; Cause in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633323#M575546</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-queue-link-error/ta-p/4625179" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-queue-link-error/ta-p/4625179&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 16:35:38 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2022-06-16T16:35:38Z</dc:date>
    <item>
      <title>Queue Link Error: Message=From Primary_ISE To Secondary_ISE; Cause=</title>
      <link>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4631070#M575446</link>
      <description>&lt;P&gt;I have a pair of ISE 3.1 patch-3 running as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;node1:&amp;nbsp; Primary Admin; Primary MNT; PSN&lt;/P&gt;&lt;P&gt;node2:&amp;nbsp; Secondary Admin; Secondary MNT; PSN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything is working fine until as security audit, the security team uses Qualys to scan these ISE devices.&amp;nbsp; During the scan, I got the following these messages:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Queue Link Error: Message=From node2 To node1; Cause={tls_alert;{unknown_ca;"tls Client: In State Certify At Ssl_handshake.erl:1887 Generated Client Alert: Fatal - Unknown Ca\n"}&lt;/P&gt;&lt;P&gt;Queue Link Error: Message=From node1 To node2; Cause={tls_alert;{unknown_ca;"tls Client: In State Certify At Ssl_handshake.erl:1887 Generated Client Alert: Fatal - Unknown Ca\n"}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During the Qualys scan, both the radius &amp;amp; tacacs logs came up empty, and the system is very slow responding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that expected?&amp;nbsp; I thought SNS-3615 should be able to handle Qualys scan.&amp;nbsp; Thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 20:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4631070#M575446</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-06-13T20:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Queue Link Error: Message=From Primary_ISE To Secondary_ISE; Cause</title>
      <link>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4632471#M575504</link>
      <description>&lt;P&gt;This has nothing to do with the Qualys scan.&amp;nbsp; This is the ISE messaging certificate.&amp;nbsp; You need to re-generate the ISE root CA and then re-generate the ISE messaging service certificate for all nodes.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 15:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4632471#M575504</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-06-15T15:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Queue Link Error: Message=From Primary_ISE To Secondary_ISE; Cause</title>
      <link>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633198#M575535</link>
      <description>&lt;P&gt;I resolved the issue by blocking Qualys from scanning this ISE and haven't seen this issue for the past few days.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 13:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633198#M575535</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-06-16T13:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Queue Link Error: Message=From Primary_ISE To Secondary_ISE; Cause</title>
      <link>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633323#M575546</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-queue-link-error/ta-p/4625179" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-queue-link-error/ta-p/4625179&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 16:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633323#M575546</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-06-16T16:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Queue Link Error: Message=From Primary_ISE To Secondary_ISE; Cause</title>
      <link>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633611#M575567</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;interesting ... could you please double check your &lt;STRONG&gt;Qualys&lt;/STRONG&gt; configuration via the&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=EVKXqqfJD_M" target="_blank" rel="noopener"&gt;ThreatCentric NAC with Qualys and ISE&lt;/A&gt;.?&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 06:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633611#M575567</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-17T06:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Queue Link Error: Message=From Primary_ISE To Secondary_ISE; Cause</title>
      <link>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633848#M575581</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;:&amp;nbsp; As I've said before, I blocked qualys from scanning the ISE appliances and have not seen queue-link error since.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 15:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/queue-link-error-message-from-primary-ise-to-secondary-ise-cause/m-p/4633848#M575581</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-06-17T15:08:03Z</dc:date>
    </item>
  </channel>
</rss>

