<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Nodes Sync &amp;amp;  Anyconnect Authentication Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5246288#M594140</link>
    <description>&lt;P&gt;Hi Rob, actually&amp;nbsp; I have been facing a problem renewing the EAP, Portal and Admin for Node2,&amp;nbsp; I did very well with node one but when trying to generate CSR for node 2, i get the error attached&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dkiptoo_0-1736747581459.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237432i78BEE961E966AD84/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Dkiptoo_0-1736747581459.png" alt="Dkiptoo_0-1736747581459.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For VPN, am facing connectivity problem. Authentication is integrated with DUO MFA. I am&amp;nbsp; able to enter credentials at the AnyConnect client but am not able to get DUO push on the&amp;nbsp; phone. The sessions times out. It was working well before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2025 06:17:04 GMT</pubDate>
    <dc:creator>Dkiptoo</dc:creator>
    <dc:date>2025-01-13T06:17:04Z</dc:date>
    <item>
      <title>ISE Nodes Sync &amp;  Anyconnect Authentication Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5245522#M594118</link>
      <description>&lt;P&gt;Hello, am still new to the ISE AAA. I have 2 Ise nodes which are deployed in HA. Recently I had an issue with expired certs. Some self signed and others CA-signed by a local CA.&amp;nbsp; EAP, Portal and Admin uses one Cert issued by CA. While renewing the EAP, Portal and Admin cert, I included ISE Messaging Cert on the PAN&amp;nbsp; and later realized that It is stand alone self signed Cert on the Secondary meaning there is an inconsistency, which I believe is the reason the two nodes are not in sync as shown on the image below.&amp;nbsp; I reverted it back to EAP, Portal and Admin, and imported the self signed&amp;nbsp; ISE Messaging Cert from the Secondary Node to PAN hoping they will now sync but since they are still node in sync. What could be the other reason? What steps should I take to ensure they are in Sync.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dkiptoo_0-1736491192372.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237315iEB951EE4B4BBACF2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Dkiptoo_0-1736491192372.png" alt="Dkiptoo_0-1736491192372.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondly, still on the issues with expired certs, DTLS cert is expired and also had issues with Anyconnect remote access. ISE is integrated to authenticate&amp;nbsp; remote user via AD. Currently am able to input credentials by MFA is not able to reach my device as it times out, which I believe could be related to the DTLS cert which enables ISE communication with NAD (FMC/FTD). I renewed the cert but still the problem persist. Any input towards troubleshooting is greatly appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 06:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5245522#M594118</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-01-10T06:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Nodes Sync &amp;  Anyconnect Authentication Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5245561#M594121</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt; ISE uses the admin certificate for secure communication, so both ISE nodes must trust each others admin certificate. Do both ISE nodes have an admin certificate issued by the same CA? I assume the ISE services were restarted on both nodes?. If the secondary node is still out of sync, click the "Syncup" button and wait a while.&lt;/P&gt;
&lt;P&gt;ISE and FMC won't be using DTLS to communicate, that is used for RADSec on the switches. Please provide more information in regard to this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 08:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5245561#M594121</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-10T08:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Nodes Sync &amp;  Anyconnect Authentication Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5246288#M594140</link>
      <description>&lt;P&gt;Hi Rob, actually&amp;nbsp; I have been facing a problem renewing the EAP, Portal and Admin for Node2,&amp;nbsp; I did very well with node one but when trying to generate CSR for node 2, i get the error attached&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dkiptoo_0-1736747581459.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237432i78BEE961E966AD84/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Dkiptoo_0-1736747581459.png" alt="Dkiptoo_0-1736747581459.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For VPN, am facing connectivity problem. Authentication is integrated with DUO MFA. I am&amp;nbsp; able to enter credentials at the AnyConnect client but am not able to get DUO push on the&amp;nbsp; phone. The sessions times out. It was working well before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 06:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5246288#M594140</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-01-13T06:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Nodes Sync &amp;  Anyconnect Authentication Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5247882#M594240</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;1st&lt;/STRONG&gt;,&amp;nbsp; at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Deployment &amp;gt;&lt;/STRONG&gt; put your mouse on the &lt;STRONG&gt;Node Status icon&lt;/STRONG&gt; to check the error:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Node Status Info.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237708i454A47906EB1D2A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Node Status Info.png" alt="Node Status Info.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd&lt;/STRONG&gt;, at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Certificate Management &amp;gt; System Certificates&lt;/STRONG&gt;, compare your &lt;STRONG&gt;Nodes Certificate&lt;/STRONG&gt;, looking for any &lt;U&gt;missing&lt;/U&gt; &lt;STRONG&gt;Certificate&lt;/STRONG&gt;&amp;nbsp;(for example).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 03:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-sync-amp-anyconnect-authentication-issue/m-p/5247882#M594240</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-16T03:46:32Z</dc:date>
    </item>
  </channel>
</rss>

