<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Distributed Deployment Not Authenticating with Primary Node in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4724100#M578363</link>
    <description>&lt;P&gt;Turns out 1/3 DNS servers had a second, old POR for the node in question that was responding first, despite rx'ing the correct response from nslookup in the node. Had to go into the DNS server and delete the old POR. Cert error message resolved right after that.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2022 18:59:50 GMT</pubDate>
    <dc:creator>jdmaybe</dc:creator>
    <dc:date>2022-11-18T18:59:50Z</dc:date>
    <item>
      <title>ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4722612#M578294</link>
      <description>&lt;P&gt;After a storage failure, had to recreate a new ISE instance. Upon rebuilding and relicensing, attempting to re-register the node into the distributed deployment (after confirming most up to date version and patch across sites), getting the following error,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Unable to authenticate ISE (FQDN) Please check certificate configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure from 'Primary Admin Node' system certificate chain of registering node is present in 'Trusted certificates' and 'Trust for authentication with ISE' Option selected."&lt;/P&gt;&lt;P&gt;After doing both of those things, (using self-signed) and manually importing the appropriate certificates to each node, still receiving the same error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 17:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4722612#M578294</guid>
      <dc:creator>jdmaybe</dc:creator>
      <dc:date>2022-11-16T17:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723216#M578306</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/td-p/2673444" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-unable-to-register-a-node/td-p/2673444&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 13:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723216#M578306</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-11-17T13:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723315#M578311</link>
      <description>&lt;P&gt;DNS resolves both ways and both nodes have the corresponding cert from the other as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 16:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723315#M578311</guid>
      <dc:creator>jdmaybe</dc:creator>
      <dc:date>2022-11-17T16:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723330#M578312</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- When trying to register, on both the 'client' node and the &lt;STRONG&gt;Primary Node&lt;/STRONG&gt; issue :&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;show logging system ade/ADE.log&amp;nbsp;&lt;/STRONG&gt; , check if any additional info's can be found (&lt;EM&gt;use the command on&lt;U&gt; both nodes&lt;/U&gt;&lt;/EM&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 17:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723330#M578312</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-11-17T17:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723417#M578320</link>
      <description>&lt;P&gt;Nothing there, nor anything relevant in system general log for either node 30 min prior or after attempted registration&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 19:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723417#M578320</guid>
      <dc:creator>jdmaybe</dc:creator>
      <dc:date>2022-11-17T19:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723423#M578322</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1433906"&gt;@jdmaybe&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You've double confirmed that your self-signed certificate indeed contains FQDN of ISE server? On both PAN and newly installed node? And you have both forward and reverse DNS records, for both servers?&lt;/P&gt;
&lt;P&gt;You are also using FQDN for registration, not IP address?&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 20:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723423#M578322</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-17T20:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723433#M578325</link>
      <description>&lt;P&gt;I always add the FQDN as a SAN DNS and the IP Address as a SAN IP, on top of having the FQDN as the common name. Some browsers require it in the SAN DNS field.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, can you verify it from a linux server?&amp;nbsp; For example, on my linux server I use an openssl call to see the certificate chain, separate from my Windows machine:&lt;BR /&gt;&lt;BR /&gt;openssl s_client ise.yourdomain.com:443&lt;BR /&gt;&lt;BR /&gt;Then, I check the first few results:&lt;BR /&gt;&lt;BR /&gt;depth=2 CN =&amp;nbsp;YOURROOT&lt;BR /&gt;verify return:1&lt;BR /&gt;depth=1 DC = com, DC = yourdomain, CN = YOURISSUER&lt;BR /&gt;verify return:1&lt;BR /&gt;depth=0 C = US, ST = NY, L = City, O = Your Company, Inc, OU = SOMEOU, CN = ise.yourdomain.com&lt;BR /&gt;verify return:1&lt;BR /&gt;CONNECTED(00000003)&lt;BR /&gt;---&lt;BR /&gt;Certificate chain&lt;BR /&gt;&lt;BR /&gt;0 s:C = US, ST = NY, L = City, O = Your Company, Inc, OU = SOMEOU, CN = ise.yourdomain.com&lt;BR /&gt;i:DC = com, DC = yourdomain, CN = YOURISSUER&lt;BR /&gt;1 s:DC = com, DC = yourdomain, CN = YOURISSUER&lt;BR /&gt;i:CN = YOURROOT&lt;BR /&gt;2 s:CN = YOURROOT&lt;BR /&gt;i:CN = YOURROOT&lt;BR /&gt;&lt;BR /&gt;There is a lot more after that, but the first few lines show the installed chain, no worrying about IE, Edge, Mozilla or Chrome configs.&amp;nbsp; If I find it looks good with the openssl check, then the rest is just some browser crap and the Admin GUI was correct.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 20:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723433#M578325</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2022-11-17T20:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723442#M578327</link>
      <description>&lt;P&gt;Thanks Milos, yes to both. Multiple folks have confirmed certs are good. Also have a third node in the deployment to match against that is working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 20:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723442#M578327</guid>
      <dc:creator>jdmaybe</dc:creator>
      <dc:date>2022-11-17T20:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723814#M578341</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Make sure that the involved FQDN(s) also have correct PTR-records,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 13:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4723814#M578341</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-11-18T13:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment Not Authenticating with Primary Node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4724100#M578363</link>
      <description>&lt;P&gt;Turns out 1/3 DNS servers had a second, old POR for the node in question that was responding first, despite rx'ing the correct response from nslookup in the node. Had to go into the DNS server and delete the old POR. Cert error message resolved right after that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 18:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-not-authenticating-with-primary-node/m-p/4724100#M578363</guid>
      <dc:creator>jdmaybe</dc:creator>
      <dc:date>2022-11-18T18:59:50Z</dc:date>
    </item>
  </channel>
</rss>

