<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Health Checks in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732731#M578647</link>
    <description>&lt;P&gt;Great, thank you!&lt;/P&gt;&lt;P&gt;Ran the checks after I got your reply... Only took about a minute for the checks to complete.&lt;/P&gt;&lt;P&gt;Question. The Trust Store Certificate Validation has an exclamation point and shows "0/2"... I checked the Trusted Certificates page and don't see an expired Certs on that page or anything expiring anytime soon. Could that message mean something else?&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 17:14:14 GMT</pubDate>
    <dc:creator>Matthew Martin</dc:creator>
    <dc:date>2022-12-05T17:14:14Z</dc:date>
    <item>
      <title>ISE Health Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732710#M578645</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;ISE v2.7 patch 3&lt;/P&gt;&lt;P&gt;I am looking to install the latest Patch for v2.7. I noticed under Administration &amp;gt; System &amp;gt; Upgrade there's a message that says &lt;EM&gt;"Deployment is not healthy. Check the health in HealthChecks page&amp;nbsp;. Click continue to go to the upgrade page."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I know the patch install is done through Administration &amp;gt; System &amp;gt; Maintenance &amp;gt; Patch Management, and not the &lt;EM&gt;Upgrade&lt;/EM&gt; page. But, I'm thinking it might be a good idea to run the Health Checks prior to installing the patch...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can the Health Checks be run during business hours without impacting endpoints/clients on the network?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in Advance,&lt;BR /&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 16:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732710#M578645</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-12-05T16:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Health Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732723#M578646</link>
      <description>&lt;P&gt;Running ISE health check does not cause any interruption for your deployment. What ISE basically does with the health check is running a list of tasks, and based on the outcome it will judge if your deployment is healthy or not. That process won't have any auto-remediation or changes to your environment, hence, it is not disruptive.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 17:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732723#M578646</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-12-05T17:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Health Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732731#M578647</link>
      <description>&lt;P&gt;Great, thank you!&lt;/P&gt;&lt;P&gt;Ran the checks after I got your reply... Only took about a minute for the checks to complete.&lt;/P&gt;&lt;P&gt;Question. The Trust Store Certificate Validation has an exclamation point and shows "0/2"... I checked the Trusted Certificates page and don't see an expired Certs on that page or anything expiring anytime soon. Could that message mean something else?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 17:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732731#M578647</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-12-05T17:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Health Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732758#M578648</link>
      <description>&lt;P&gt;You welcome. Does it show you the Trust Store Certificate Validation as failed or passed the health check? Usually you would see 0/x if the health check task fails, in that case you will see it flagged in red, but if you see it in green with 0/2 I would ignore it.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 18:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732758#M578648</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-12-05T18:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Health Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732783#M578649</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MatthewMartin_0-1670267297531.png" style="width: 477px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169920i79034A34221F5CA0/image-dimensions/477x136?v=v2" width="477" height="136" role="button" title="MatthewMartin_0-1670267297531.png" alt="MatthewMartin_0-1670267297531.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I think I found the certs it was warning about under Certificates &amp;gt; Certificate Authority Certificates. There's 2 for each of our 2 nodes. One shows for OCSP Responder and the other says &lt;EM&gt;"...Endpoint Sub CA...".&lt;/EM&gt; See below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MatthewMartin_1-1670267593321.png" style="width: 1475px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169921i1E29C71E910C4A7F/image-dimensions/1475x59?v=v2" width="1475" height="59" role="button" title="MatthewMartin_1-1670267593321.png" alt="MatthewMartin_1-1670267593321.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I do see valid OCSP Responder and Endpoint Sub CA certs that are still valid. But, when I clicked to Delete one of these expired Certs I get the following message, which sounded a little scary so I clicked Cancel:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MatthewMartin_2-1670267824523.png" style="width: 671px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169922iEF7F70BA34F2BE37/image-dimensions/671x437?v=v2" width="671" height="437" role="button" title="MatthewMartin_2-1670267824523.png" alt="MatthewMartin_2-1670267824523.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks Again,&lt;BR /&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 19:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4732783#M578649</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-12-05T19:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Health Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4733090#M578656</link>
      <description>&lt;P&gt;Hi Matt, you can renew those certs by going into the Certificate Signing Requests section. Once you click on generate the request, you can select the usage from the usage drop down menu, alternatively you can remove them if they are not in use. One thing to keep in mind is that an upgrade process will fail if you have any expired certificate on ISE, however, I don't believe this would be the case with applying the patches.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 09:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-health-checks/m-p/4733090#M578656</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-12-06T09:35:30Z</dc:date>
    </item>
  </channel>
</rss>

