<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can no longer ssh into the Primary Admin/Secondary MnT node in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5306634#M597129</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp; &amp;nbsp;No , officially you will need to rely on TAC access to make&amp;nbsp; the necessary modifications,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jul 2025 17:26:06 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2025-07-07T17:26:06Z</dc:date>
    <item>
      <title>can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305044#M597065</link>
      <description>&lt;P&gt;My ISE cluster is 3.3 patch-4.&amp;nbsp; Everything is working, and I can GUI and SSH into ALL nodes with the exception of SSH into the PAN node.&amp;nbsp; I was able to ssh into it yesterday but today it stopped working and I received this message:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Pre-authentication banner message from server: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| Your account has expired; please contact your system administrator. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;End of banner message from server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I need to be able to ssh into the PAN.&amp;nbsp; All the password policy is NOT lockout/suspend account.&amp;nbsp; How do I go about in resolving this issue?&amp;nbsp; I can use mount the DVD to reset the password but in this case, it is telling me that the account is "expired" so this is definitely different.&lt;/P&gt;&lt;P&gt;Help!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 00:50:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305044#M597065</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2025-07-03T00:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305155#M597073</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp; &amp;nbsp;You&amp;nbsp; could try this one first :&amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-gui-login-error-quot-your-account-has-been-disabled-quot/m-p/1998905/highlight/true#M186840" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-gui-login-error-quot-your-account-has-been-disabled-quot/m-p/1998905/highlight/true#M186840&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To me , it looks like it is related to&amp;nbsp; password not being changed within a certain (required) interval ; so password recovery&amp;nbsp; procedures may still help,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 08:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305155#M597073</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-07-03T08:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305188#M597074</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;: Usually, the message should be "the password has expired" and NOT "the account has expired".&amp;nbsp; I've run into this multiple times in the past, but the message is different this time.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 11:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305188#M597074</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2025-07-03T11:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305204#M597076</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp; &amp;nbsp;I understand , but if my argument is correct and it is also displayed when a password was not changed in time, then try password recover procedures anyway (also the message could&amp;nbsp; get changed between subsequent ISE versions&amp;nbsp; &lt;STRONG&gt;(e.g.)&lt;/STRONG&gt;)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Also , for the time being &lt;U&gt;&lt;EM&gt;I can't see anything else to try&amp;nbsp;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 11:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305204#M597076</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-07-03T11:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305884#M597110</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;:&amp;nbsp; password recovery from DVD did NOT help.&amp;nbsp; I opened a TAC case with Cisco and the TAC engineer informed me that there are several customers also experiencing this issue.&amp;nbsp; I sent them the backup configuration for them to replicate it in their lab (hopefully).&amp;nbsp; They might have to hack into the /etc/passwd and/or /etc/shadown file since ISE under the hood is Redhat Linux.&amp;nbsp; Will keep you posted.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jul 2025 22:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305884#M597110</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2025-07-04T22:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305931#M597112</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;If you are using ISE&amp;nbsp; on VM nodes you might have options to change&amp;nbsp; /etc/shadow yourself :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Mount the root&amp;nbsp; partition on another virtual machine&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Each line in &lt;CODE&gt;/etc/shadow&lt;/CODE&gt; has 9 colon-separated fields :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;username:password:lastchg:min:max:warn:inactive:&lt;STRONG&gt;expire&lt;/STRONG&gt;:reserved&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;If you change that for a particular account into&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;username:password:lastchg:min:max:warn:inactive::&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Then the&lt;STRONG&gt; expire-info&lt;/STRONG&gt; for the account is removed :&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;e.g.&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;marc:$6$abc...:19909:0:99999:7:14:20000:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; change into&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; marc:$6$abc...:19909:0:99999:7:14::&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; M.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jul 2025 06:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5305931#M597112</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-07-05T06:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5306629#M597126</link>
      <description>&lt;P&gt;Is this method "supported" by Cisco?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 17:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5306629#M597126</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2025-07-07T17:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5306634#M597129</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp; &amp;nbsp;No , officially you will need to rely on TAC access to make&amp;nbsp; the necessary modifications,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 17:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5306634#M597129</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-07-07T17:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: can no longer ssh into the Primary Admin/Secondary MnT node</title>
      <link>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5311117#M597357</link>
      <description>&lt;P&gt;Update:&amp;nbsp; I was able to do this.&amp;nbsp; This is a known bug for version 3.3, regardless of patches.&amp;nbsp; You can do this without Cisco TAC (prefer to have TAC online but it is not needed).&amp;nbsp; Here is how to do it:&lt;/P&gt;&lt;P&gt;a- Mount the rescue iso on the VM,&lt;BR /&gt;b- Select the option “Rescue CISCO ISE system (Keyboard/Monitor)”&lt;BR /&gt;c- Select option “3) Skip to shell”&lt;BR /&gt;d- now you in shell mode, type "lsblk" to show you the system sda1, sda2, sda3, etc..&lt;BR /&gt;e- make dir and mount them: mkdir /mnt/sda2; mount /dev/sda2 /mnt/sda2; mkdir /mnt/sda3; mount /dev/sda3 /mnt/sda3&lt;BR /&gt;f- run lsblk just for the fun of it,&lt;BR /&gt;g- change shell with: "root /mnt/sda2&lt;BR /&gt;h- check the state of the account with the command: "chage -l adamscottmaster2013". The output will show you that the account expires,&lt;BR /&gt;i- to change it to never expire: chage -E -1 adamscottmaster2013,&lt;BR /&gt;j- to confirm the account is set to never expire: chage -l adamscottmaster2013&lt;BR /&gt;k- exit from shell&lt;BR /&gt;l- reboot&lt;BR /&gt;m- now you can ssh into the ISE with the account adamscottmaster2013 (or whatever account you created in your environment),&lt;/P&gt;&lt;P&gt;Hope that will help anyone with this issue from misery, LOL....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 14:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-no-longer-ssh-into-the-primary-admin-secondary-mnt-node/m-p/5311117#M597357</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2025-07-18T14:42:47Z</dc:date>
    </item>
  </channel>
</rss>

