<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't access ISE secondary node via CLI / GUI after joining deploy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287577#M596210</link>
    <description>&lt;P&gt;Hi Marcelo,&lt;/P&gt;
&lt;P&gt;Thanks for the feedback. Yes, that probably ends up being the solution - but I surely hope Cisco/TAC are interested in finding the rootcause to prevent other users getting hits by the same issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The deployment is only used for tacacs and that part is still working.&lt;/SPAN&gt;&lt;BR /&gt;So the only issue we see is that we cannot login to ISE, so we have time to wait for Cisco to find the rootcause.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 03 May 2025 14:35:19 GMT</pubDate>
    <dc:creator>jyla</dc:creator>
    <dc:date>2025-05-03T14:35:19Z</dc:date>
    <item>
      <title>Can't access ISE secondary node via CLI / GUI after joining deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5013273#M587098</link>
      <description>&lt;P class="p1"&gt;Hey gang!&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;I'm running into a strange deployment issue in my lab.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;Using ISE 3.2 Patch 4.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;The primary server is running fine as PAN/PSN/MNT.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;When I try to add a secondary server to the deployment, it is added successfully and the status of the new server shows up as green on the deployment page.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;However, after that point I can no longer login to the secondary via GUI or CLI.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;When I try via GUI, there is no web page presented and I just get TCP RST from the server.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;When I try to log into the CLI, it accepts the credentials but immediately logs me out.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;It also will not process AAA requests from NADs.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;I've tried rebuilding the secondary and repeating the whole process, and got the same results again.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;Any ideas?&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 23:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5013273#M587098</guid>
      <dc:creator>Ryan H</dc:creator>
      <dc:date>2024-02-05T23:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ISE secondary node via CLI / GUI after joining deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5013306#M587100</link>
      <description>&lt;P&gt;You might be hitting this bug -&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi33361" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi33361&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Your best bet would be to open a TAC case to confirm if this is the issue and, if so, see if they have a hotfix available (since there is no patch available yet with the bug fix).&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 00:59:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5013306#M587100</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-02-06T00:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ISE secondary node via CLI / GUI after joining deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5013544#M587109</link>
      <description>&lt;P&gt;Thanks Greg.&amp;nbsp; TAC support would be tricky as this is a lab environment. However, the description of this bug doesn't quite fit... it suggests the GUI is accessible (which in my case it is not,) and also the specific error wording for the bug, "&lt;SPAN&gt;Failed to connect to ConfD: Connection refused" suggests a flat-out rejection of the SSH connect attempt.&amp;nbsp; In my case the SSH/console session connects fine, but it is immediately disconnected after successful authentication.&amp;nbsp; Interestingly, if I intentionally supply the wrong password upon connection attempt, I'm re-prompted to put in the pw multiple times.&amp;nbsp; It's only when I put in the correct pw that the session is established and then immediately&amp;nbsp;disconnected again.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 13:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5013544#M587109</guid>
      <dc:creator>Ryan H</dc:creator>
      <dc:date>2024-02-06T13:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ISE secondary node via CLI / GUI after joining deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287085#M596193</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt;
&lt;P&gt;Sorry for waking up this old thread - but we might have hit the same issue as you, and I wonder if you ever got it fixed (and found the rootcause) ?&lt;/P&gt;
&lt;P&gt;We upgraded from 3.2p6 to 3.3p4.&lt;/P&gt;
&lt;P&gt;Issue shows up clearly using securecrt as ssh client, here the ssh session is disconnected when trying to login, but you can actually see the reason for the disconnect stated:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE GUI not loading after upgrade to 3.3 Patch 4.png" style="width: 727px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244409iF2440EDE3839055F/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE GUI not loading after upgrade to 3.3 Patch 4.png" alt="ISE GUI not loading after upgrade to 3.3 Patch 4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I booted up a centos rescue image and mounted the ISE disk to try to see what happens.&lt;/P&gt;
&lt;P&gt;Looking at the /etc/passwd file I can see that our static user (acsadmin) has the UID 500&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE GUI not loading after upgrade to 3.3 Patch 4-UID.png" style="width: 770px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244410iBE7C32FC248BDF26/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE GUI not loading after upgrade to 3.3 Patch 4-UID.png" alt="ISE GUI not loading after upgrade to 3.3 Patch 4-UID.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But the homedirectory is for some reason assigned to a user with UID 1000, and the same ownership is set for all files within the folder:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE GUI not loading after upgrade to 3.3 Patch 4 - Homedir.png" style="width: 628px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244411i819A26BD7BD08D07/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE GUI not loading after upgrade to 3.3 Patch 4 - Homedir.png" alt="ISE GUI not loading after upgrade to 3.3 Patch 4 - Homedir.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The UID 1000 is non-existing on the unix side of this deployment, and it prevents the user from changing its work directory to its homedir if I understand correctly.&lt;/P&gt;
&lt;P&gt;I have TAC involved in troubleshooting, to find the reason why the update would change the ownership of the folder and content.&lt;BR /&gt;I hope there is a log somewhere detailing the upgrade/patch process/progress which can hopefully give us the cause. We are hesitant to continue upgrading other deployments until then.&lt;/P&gt;
&lt;P&gt;Any inputs are more than welcome.&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2025 06:21:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287085#M596193</guid>
      <dc:creator>jyla</dc:creator>
      <dc:date>2025-05-02T06:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ISE secondary node via CLI / GUI after joining deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287515#M596207</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/439051"&gt;@jyla&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please use the &lt;STRONG&gt;Backup and Restore&lt;/STRONG&gt; upgrade method, i.e. install an &lt;STRONG&gt;ISE 3.3 P4&lt;/STRONG&gt; from scratch and &lt;STRONG&gt;Restore&lt;/STRONG&gt; the &lt;STRONG&gt;ISE 3.2 P6&lt;/STRONG&gt; backup on it.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 May 2025 07:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287515#M596207</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-05-03T07:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ISE secondary node via CLI / GUI after joining deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287577#M596210</link>
      <description>&lt;P&gt;Hi Marcelo,&lt;/P&gt;
&lt;P&gt;Thanks for the feedback. Yes, that probably ends up being the solution - but I surely hope Cisco/TAC are interested in finding the rootcause to prevent other users getting hits by the same issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The deployment is only used for tacacs and that part is still working.&lt;/SPAN&gt;&lt;BR /&gt;So the only issue we see is that we cannot login to ISE, so we have time to wait for Cisco to find the rootcause.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 May 2025 14:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287577#M596210</guid>
      <dc:creator>jyla</dc:creator>
      <dc:date>2025-05-03T14:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ISE secondary node via CLI / GUI after joining deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287590#M596212</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/439051"&gt;@jyla&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;what you said makes sense to me ... let's try to "dig a little deeper" ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;This kind of weird stuff reminds me of &lt;A href="https://software.cisco.com/download/home/283801620/type/283802505/release/2.7.0?releaseIndicator=DEFERRED" target="_blank" rel="noopener"&gt;ISE 2.7 P8&lt;/A&gt;, a very good patch that fixes a bizarre &lt;STRONG&gt;Field Notice&lt;/STRONG&gt; (&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/740/fn74005.html" target="_blank" rel="noopener"&gt;Field Notice: FN74005 - Identity Services Engine: Java Heap Size May Significantly Impact System Performance - Software Upgrade Recommended&lt;/A&gt;), but at the same time has issues whenever you upgrade from &lt;STRONG&gt;ISE 2.7 P1&lt;/STRONG&gt; or &lt;STRONG&gt;P2&lt;/STRONG&gt; to it, and that's why it became a &lt;STRONG&gt;Deferred Release&lt;/STRONG&gt; !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ISE 2.7 P8 Deferred.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244544iF330468F814DE1CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE 2.7 P8 Deferred.png" alt="ISE 2.7 P8 Deferred.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You said that you upgrade from &lt;STRONG&gt;ISE 3.2 P6&lt;/STRONG&gt; to &lt;STRONG&gt;ISE 3.3 P4&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Did you notice the issue when you reach to &lt;STRONG&gt;ISE 3.3&lt;/STRONG&gt; or only when you update to &lt;STRONG&gt;ISE 3.3 P4&lt;/STRONG&gt; ?&lt;/LI&gt;
&lt;LI&gt;Have you tried updating first from &lt;STRONG&gt;ISE 3.2 P6&lt;/STRONG&gt; to &lt;STRONG&gt;P7&lt;/STRONG&gt; and then to &lt;STRONG&gt;ISE 3.3 P4&lt;/STRONG&gt; to check if the issue exists ?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 May 2025 16:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5287590#M596212</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-05-03T16:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ISE secondary node via CLI / GUI after joining deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5289442#M596268</link>
      <description>&lt;P&gt;This actually turned out to be the issue. So after regenerating the kong certificates, we could login to the ISE CLI/console again and the webgui started up.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 13:37:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-access-ise-secondary-node-via-cli-gui-after-joining/m-p/5289442#M596268</guid>
      <dc:creator>jyla</dc:creator>
      <dc:date>2025-05-09T13:37:55Z</dc:date>
    </item>
  </channel>
</rss>

