<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.7 Clustering Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4859135#M582378</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Consider migrating to (more) recent version(s) of ISE :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2023 06:14:47 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2023-06-21T06:14:47Z</dc:date>
    <item>
      <title>ISE 2.7 Clustering Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4859122#M582377</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I have a total of 4 ISE nodes on a VM medium size. Previously, it was on 2.3 where we are facing multiple issues. Recently I migrated that server with the fresh installation on version 2.7 patch 9 on a newly created VM host using ISO image. I have installed these nodes one by one in standalone mode, configured the same policies and IP schema, and dismantled the old VM host servers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Out of 4 nodes, 3 nodes successfully get into the cluster and working fine. One was able to reregister but not getting synced with others.&lt;/P&gt;
&lt;P&gt;I tried to de-register, service start-stop, reload, and factory reset, but still, it was not able to sync. The error is de-register the node and register it again.&lt;/P&gt;
&lt;P&gt;I have also checked the reachability part and I can able to ping and get the DNS lookup of all other nodes from the affected node.&lt;/P&gt;
&lt;P&gt;Please suggest any further troubleshooting if possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 05:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4859122#M582377</guid>
      <dc:creator>viv42</dc:creator>
      <dc:date>2023-06-21T05:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 Clustering Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4859135#M582378</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Consider migrating to (more) recent version(s) of ISE :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 06:14:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4859135#M582378</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-06-21T06:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 Clustering Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4859690#M582392</link>
      <description>&lt;P&gt;Did you try the "application reset-config ise" on the node that is giving these issues? if so, maybe you can move the primary PAN persona to the secondary PAN and see if that helps. Alternatively, I would try to get TAC engaged.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 16:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4859690#M582392</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-21T16:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 Clustering Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861084#M582427</link>
      <description>&lt;P&gt;Hi Aref,&lt;/P&gt;
&lt;P&gt;The affected node is a PSN that is not able to sync with other nodes. I have already tried&amp;nbsp;&lt;SPAN&gt;"application reset-config ISE" but it didn't work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The node was able to register within a minute but after that it was not able sync.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 03:46:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861084#M582427</guid>
      <dc:creator>viv42</dc:creator>
      <dc:date>2023-06-23T03:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 Clustering Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861481#M582434</link>
      <description>&lt;P&gt;I would try to move the primary PAN as suggested before, alternatively I think TAC could help. If not, maybe redeploying that node from the scratch would be a fairly quick option.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861481#M582434</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-23T15:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 Clustering Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861593#M582437</link>
      <description>&lt;P&gt;Check things in the following order:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;PAN should be able to do both forward and reverse nslookup of the affected node.&lt;/LI&gt;
&lt;LI&gt;Check if communication is allowed between PAN and the problematic node for TCP 443, 12001 and 8671.&lt;/LI&gt;
&lt;LI&gt;Take a packet capture on PAN while registering the node and check communication with problematic server's IP. (Check if SSL handshake is getting completed for TCP port mentioned in #2)&lt;/LI&gt;
&lt;LI&gt;You can also do "show logging application replication.log tail" on the problematic node while doing the registration and check if any exceptions or error message seen.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If nothing conclusive found, would suggest reaching out to TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 19:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861593#M582437</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-06-23T19:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 Clustering Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861615#M582439</link>
      <description>&lt;P&gt;Hi Aref, Thank you for the suggestion. I&amp;nbsp; will go for redeploying if any of the troubleshooting not works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Nancy,&lt;/P&gt;
&lt;P&gt;I will check all of the things which you mentioned in your reply and will let you know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 20:46:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-clustering-issue/m-p/4861615#M582439</guid>
      <dc:creator>viv42</dc:creator>
      <dc:date>2023-06-23T20:46:54Z</dc:date>
    </item>
  </channel>
</rss>

