<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TLS/SSL Weak Message Authentication Code Cipher Suites for PSN nod in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tls-ssl-weak-message-authentication-code-cipher-suites-for-psn/m-p/5201291#M592087</link>
    <description>&lt;P&gt;You can try a manual sync. If that doesn't work, then de-register the node and re-register it again. That should take care of the issue. In the worst case, you can also de-register the node, shutdown and delete the VM, and then build a new one. Of course that is a lot of work, but it's guaranteed to work, in case there was something wrong during the 3.2 to 3.3 upgrade and/or patching. I don't see a vulnerability report attached to your posting.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2024 21:06:19 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-09-30T21:06:19Z</dc:date>
    <item>
      <title>TLS/SSL Weak Message Authentication Code Cipher Suites for PSN node</title>
      <link>https://community.cisco.com/t5/network-access-control/tls-ssl-weak-message-authentication-code-cipher-suites-for-psn/m-p/5201191#M592085</link>
      <description>&lt;P&gt;We have recently upgraded our distributed ISE deployment from 3.2 to 3.3-patch3. After that, we have disabled the weak TLS/SSL ciphers and restarted the services. After that, all the PAN , MNT and PSN nodes in the deployment got remediated except one PSN node. All the nodes were restarted after the patching.&lt;/P&gt;&lt;P&gt;+ Deployment is healthy and all the nodes are showing Green&lt;/P&gt;&lt;P&gt;+ verify the Services and all looks good&lt;/P&gt;&lt;P&gt;Could you please suggest what could be the reason for this? Do we have to re-sync the PSN node from the deployment to check if it can be remediated or any other solution available to resolve this issue.&lt;/P&gt;&lt;P&gt;I have attached the Vulnerability scan report for that PSN node&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vulnerability Reported -&amp;nbsp;TLS/SSL Weak Message Authentication Code Cipher Suites&lt;/P&gt;&lt;P&gt;ISE deployment Version - 3.3 - Patch 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 18:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tls-ssl-weak-message-authentication-code-cipher-suites-for-psn/m-p/5201191#M592085</guid>
      <dc:creator>ajaykumar-rath</dc:creator>
      <dc:date>2024-09-30T18:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: TLS/SSL Weak Message Authentication Code Cipher Suites for PSN nod</title>
      <link>https://community.cisco.com/t5/network-access-control/tls-ssl-weak-message-authentication-code-cipher-suites-for-psn/m-p/5201291#M592087</link>
      <description>&lt;P&gt;You can try a manual sync. If that doesn't work, then de-register the node and re-register it again. That should take care of the issue. In the worst case, you can also de-register the node, shutdown and delete the VM, and then build a new one. Of course that is a lot of work, but it's guaranteed to work, in case there was something wrong during the 3.2 to 3.3 upgrade and/or patching. I don't see a vulnerability report attached to your posting.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 21:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tls-ssl-weak-message-authentication-code-cipher-suites-for-psn/m-p/5201291#M592087</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-09-30T21:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: TLS/SSL Weak Message Authentication Code Cipher Suites for PSN nod</title>
      <link>https://community.cisco.com/t5/network-access-control/tls-ssl-weak-message-authentication-code-cipher-suites-for-psn/m-p/5201302#M592089</link>
      <description>&lt;P&gt;Thanks Arne .&lt;/P&gt;&lt;P&gt;I have attached the vulnerability report. we are using Physical SNS3715 ISE appliance in our environment.&lt;/P&gt;&lt;P&gt;I will try to re-sync the node. If that is not helpful, then i will try to de-register and re-register it again. will update with the result.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 21:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tls-ssl-weak-message-authentication-code-cipher-suites-for-psn/m-p/5201302#M592089</guid>
      <dc:creator>ajaykumar-rath</dc:creator>
      <dc:date>2024-09-30T21:21:10Z</dc:date>
    </item>
  </channel>
</rss>

