<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE disconnected node in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747188#M579036</link>
    <description>&lt;P&gt;what is the version of ISE -&amp;nbsp; is this a Local CA or signed by the Public CA Server?&lt;/P&gt;
&lt;P&gt;is the Certs used before from the same CA, or is the Local CA changed and generated a wildcard?&lt;/P&gt;
&lt;P&gt;if the local CA changed you need to add root CA to ISE to trust.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 31 Dec 2022 17:47:44 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-12-31T17:47:44Z</dc:date>
    <item>
      <title>Cisco ISE disconnected node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747187#M579035</link>
      <description>&lt;P&gt;ISE Nodes in deployment dissconnected after change self signed certificate to CA wildcard certificate .&lt;/P&gt;&lt;P&gt;when i tried to register ise i got below error, can some one help me to solve it please.&lt;/P&gt;&lt;P&gt;Unable to authenticate ISE (xxxise) Please check certificate configuration.&lt;BR /&gt;Make sure from 'Primary Admin node', system certificate chain of registering node is present in 'Trusted certificates' and is enabled with 'Trust for authentication within ISE' option selected&lt;/P&gt;&lt;P&gt;1 Deregister and register incomplete due to above error .&lt;BR /&gt;2 Sync icon do not working .&lt;BR /&gt;3 CA wildcard certificate present in system certificates on all nodes , and in Trusted in primary node .&lt;BR /&gt;4 As i understand need to have the Root CA certificate in Trusted certificates. can someone correct me if i am wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 17:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747187#M579035</guid>
      <dc:creator>assers001</dc:creator>
      <dc:date>2022-12-31T17:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE disconnected node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747188#M579036</link>
      <description>&lt;P&gt;what is the version of ISE -&amp;nbsp; is this a Local CA or signed by the Public CA Server?&lt;/P&gt;
&lt;P&gt;is the Certs used before from the same CA, or is the Local CA changed and generated a wildcard?&lt;/P&gt;
&lt;P&gt;if the local CA changed you need to add root CA to ISE to trust.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 17:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747188#M579036</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-12-31T17:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE disconnected node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747236#M579037</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the version of ISE&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Version: &lt;/SPAN&gt;&lt;SPAN&gt;2.6.0.156&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Patch Information: &lt;/SPAN&gt;&lt;SPAN&gt;7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp; is this a Local CA or signed by the Public CA Server?&amp;nbsp; Public CA Signed by third party .&lt;/P&gt;&lt;P&gt;is the Certs used before from the same CA, Not used by ise before .&lt;/P&gt;&lt;P&gt;or is the Local CA changed and generated a wildcard? We generate wildcard CSR and sent to CA&amp;nbsp;&lt;/P&gt;&lt;P&gt;if the local CA changed you need to add root CA to ISE to trust.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jan 2023 07:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747236#M579037</guid>
      <dc:creator>assers001</dc:creator>
      <dc:date>2023-01-01T07:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE disconnected node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747254#M579038</link>
      <description>&lt;P&gt;i would compare the primary node with other nodes below cisco certificate, also make sure the domain is not changed from previous to now.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="balajibandi_0-1672568639220.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172319i4B39214B30CF604B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="balajibandi_0-1672568639220.png" alt="balajibandi_0-1672568639220.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jan 2023 10:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747254#M579038</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-01T10:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE disconnected node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747527#M579045</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The temp solution to restore deployment , i deregister sec the secondary node and make it standalone then generate Self Signed&amp;nbsp; admin cert and re register the node to deployment .&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 09:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-disconnected-node/m-p/4747527#M579045</guid>
      <dc:creator>assers001</dc:creator>
      <dc:date>2023-01-02T09:51:17Z</dc:date>
    </item>
  </channel>
</rss>

