<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Node not able to join deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5224226#M593190</link>
    <description>&lt;P&gt;You seem to have a firewall in between these two ISE nodes. Just make sure please that you have all the required ports opened as mentioned by the others, or you can open up all the ports between these nodes on the firewall if they are in segregated secured segments and then look at the firewall logs to narrow down the policy based on the utilised ports you see on the logs.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2024 11:48:22 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2024-11-14T11:48:22Z</dc:date>
    <item>
      <title>Node not able to join deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223843#M593167</link>
      <description>&lt;P&gt;I am unable to join a node to the deployment even though I am able to ping PAN to new node and vice versa? What could be stopping this?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NetworkMonkey101_0-1731515527565.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/233791iE43923D1CAFDBC28/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NetworkMonkey101_0-1731515527565.png" alt="NetworkMonkey101_0-1731515527565.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 16:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223843#M593167</guid>
      <dc:creator>NetworkMonkey101</dc:creator>
      <dc:date>2024-11-13T16:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Node not able to join deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223844#M593168</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1495947"&gt;@NetworkMonkey101&lt;/a&gt; is DNS setup and working? Can you ping the FQDN?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 16:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223844#M593168</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-11-13T16:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Node not able to join deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223845#M593169</link>
      <description>&lt;P&gt;I would check this guide that the ports are open between the nodes for all communication.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 16:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223845#M593169</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2024-11-13T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Node not able to join deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223859#M593170</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/install_guide/b_ise_installationGuide34/b_ise_InstallationGuide_chapter_7.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/install_guide/b_ise_installationGuide34/b_ise_InstallationGuide_chapter_7.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 17:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223859#M593170</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-11-13T17:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Node not able to join deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223885#M593174</link>
      <description>&lt;P&gt;As mentioned check the DNS, can you resolve from node a to node b with the command nslookup nodea.domain.com ? And also from node a to the node b? Finally, I'd highly recommend collecting a packet capture. Use the following documentation, it includes the ports for replication and synchronization:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE id="persona-node-ports__ID-1420-00000015" class="table" border="1" width="100%"&gt;
&lt;TBODY id="persona-node-ports__ID-1420-0000002c" class="tbody"&gt;
&lt;TR id="persona-node-ports__ID-1420-00000043"&gt;
&lt;TD class="entry align-left"&gt;
&lt;P class="p"&gt;Replication and Synchronization&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry align-left"&gt;
&lt;UL class="ul"&gt;
&lt;LI id="persona-node-ports__li_35C4E893CFE84C989D4723A9834B2066" class="li"&gt;
&lt;P class="p"&gt;HTTPS (SOAP): TCP/443&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="persona-node-ports__li_C91BE77EC5824DC3AAEA168D95FFA7EF" class="li"&gt;
&lt;P class="p"&gt;Data Synchronization/ Replication (JGroups): TCP/12001 (Global)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;ISE Messaging Service: SSL: TCP/8671&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;ISE internal communication: TCP/15672&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Profiler Endpoint Ownership Synchronization/ Replication: TCP/6379&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 18:25:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5223885#M593174</guid>
      <dc:creator>dalbanil</dc:creator>
      <dc:date>2024-11-13T18:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Node not able to join deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5224226#M593190</link>
      <description>&lt;P&gt;You seem to have a firewall in between these two ISE nodes. Just make sure please that you have all the required ports opened as mentioned by the others, or you can open up all the ports between these nodes on the firewall if they are in segregated secured segments and then look at the firewall logs to narrow down the policy based on the utilised ports you see on the logs.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 11:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/node-not-able-to-join-deployment/m-p/5224226#M593190</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-11-14T11:48:22Z</dc:date>
    </item>
  </channel>
</rss>

