<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Post 3.4, Patch 4, replication stop with PAN and CLI failed to con in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357510#M599378</link>
    <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/661113"&gt;@anilraj_003&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;thanks for your feedback. Please keep us posted !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: I've had issues in the past that would occur only in a &lt;STRONG&gt;Distributed Deployment&lt;/STRONG&gt;. When I removed the &lt;STRONG&gt;SPAN&lt;/STRONG&gt; from the &lt;STRONG&gt;Cluster&lt;/STRONG&gt; and it became a &lt;STRONG&gt;Standalone&lt;/STRONG&gt;, the problem was fixed, and from that point on I could recreate the &lt;STRONG&gt;Cluster&lt;/STRONG&gt; via this &lt;STRONG&gt;SPAN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Dec 2025 17:29:01 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2025-12-24T17:29:01Z</dc:date>
    <item>
      <title>Post 3.4, Patch 4, replication stop with PAN and CLI failed to connect</title>
      <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357255#M599360</link>
      <description>&lt;P&gt;Post 3.4, patch 4, Replication stop between PAN and PSNs, error, Jediss replication failed, CLI access issue-error failed to connect to the server.&amp;nbsp;throwing an error in the debug log :&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error, Failed to connect to server, could not connect to test-ise-01.net.lab/198.XX.XX.01:12001&lt;/P&gt;&lt;P&gt;replication error: from psn debug:-FullSync:- Primary address is null&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Dec 2025 12:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357255#M599360</guid>
      <dc:creator>anilraj_003</dc:creator>
      <dc:date>2025-12-23T12:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Post 3.4, Patch 4, replication stop with PAN and CLI failed to con</title>
      <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357370#M599366</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/661113"&gt;@anilraj_003&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;check the &lt;STRONG&gt;12001 ports&lt;/STRONG&gt; on both &lt;STRONG&gt;Nodes&lt;/STRONG&gt;:&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;ise/admin# &lt;FONT color="#3366FF"&gt;show ports | include 12001&lt;/FONT&gt;&lt;BR /&gt; ...&lt;BR /&gt; &lt;FONT color="#3366FF"&gt;198.xx.xx.01:12001&lt;/FONT&gt;, &lt;BR /&gt; ...&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;check the &lt;STRONG&gt;Services&lt;/STRONG&gt; for any &lt;U&gt;initializing&lt;/U&gt; or &lt;U&gt;not running&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;State&lt;/STRONG&gt;:&lt;/P&gt;
&lt;PRE&gt;ise/admin# &lt;FONT color="#3366FF"&gt;show application status ise&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt; ISE PROCESS NAME              STATE     PROCESS ID &lt;BR /&gt; --------------------------------------------------&lt;BR /&gt; Database Listener             &lt;FONT color="#3366FF"&gt;running&lt;/FONT&gt;   8436 &lt;BR /&gt; Database Server               running   203 PROCESSES&lt;BR /&gt; Application Server            running   27824 &lt;BR /&gt; ...&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if there is anything &lt;U&gt;blocking the communication&lt;/U&gt; between the &lt;STRONG&gt;Nodes&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For &lt;STRONG&gt;Cisco ISE&lt;/STRONG&gt; port reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/install_guide/b_ise_installationGuide34/b_ise_InstallationGuide_chapter_7.html" target="_blank" rel="noopener"&gt;Cisco ISE Installation Guide - Release 3.4 - Port Reference&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Dec 2025 21:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357370#M599366</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-12-23T21:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Post 3.4, Patch 4, replication stop with PAN and CLI failed to con</title>
      <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357422#M599368</link>
      <description>&lt;P&gt;Thanks for the input. In our case, CLI access is not possible on any node (SSH / CIMC / serial all drop immediately after the login prompt), so we are unable to run 'show application status ise' or verify ports locally. We have a total of 15 Physical nodes, SNS36XX, all of which we can say are technically dead.&lt;/P&gt;&lt;P&gt;Problem :&amp;nbsp;This is not a replication problem — this is an OS / shell / service-layer collapse on all 15 nodes after 3.4 Patch 4, where CLI sessions cannot start, PAN replication services are not responding, and the cluster is effectively brain-dead.&lt;/P&gt;&lt;P&gt;PSN logs confirm repeated connection attempts to PAN on port 12001, but the PAN replication service is not responding, and the Primary address becomes null. This is being investigated with TAC as an OS-level issue requiring recovery.&lt;/P&gt;&lt;P&gt;That’s it.&lt;BR /&gt;No back-and-forth needed.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2025 07:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357422#M599368</guid>
      <dc:creator>anilraj_003</dc:creator>
      <dc:date>2025-12-24T07:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Post 3.4, Patch 4, replication stop with PAN and CLI failed to con</title>
      <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357465#M599370</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/661113"&gt;@anilraj_003&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;interesting ... I'm a bit curious, no &lt;STRONG&gt;CLI&lt;/STRONG&gt; access via &lt;STRONG&gt;SSH&lt;/STRONG&gt; or &lt;STRONG&gt;Console&lt;/STRONG&gt;, correct ?&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Are you able to remove &lt;STRONG&gt;2x Nodes&lt;/STRONG&gt; from your &lt;STRONG&gt;15-Node Cluster&lt;/STRONG&gt;, the &lt;STRONG&gt;SPAN&lt;/STRONG&gt; and a&amp;nbsp;&lt;STRONG&gt;PSN&lt;/STRONG&gt;, to create a &lt;STRONG&gt;Small Deployment&lt;/STRONG&gt;, and test the replication of this new &lt;STRONG&gt;Cluster&lt;/STRONG&gt; ?&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note 1: if the answer is yes, the &lt;STRONG&gt;SPAN&lt;/STRONG&gt; will be the &lt;STRONG&gt;PPAN&lt;/STRONG&gt; of the new &lt;STRONG&gt;Cluster&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note 2:&amp;nbsp;I'm thinking of testing whether the problem was specific to &lt;STRONG&gt;PPAN&lt;/STRONG&gt; or also to &lt;STRONG&gt;SPAN&lt;/STRONG&gt;. If &lt;STRONG&gt;SPAN&lt;/STRONG&gt; is OK, then you can rebuild your entire &lt;STRONG&gt;Cluster&lt;/STRONG&gt; using &lt;STRONG&gt;SPAN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Please keep us posted about the &lt;STRONG&gt;TAC&lt;/STRONG&gt; investigation !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Best regards&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2025 12:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357465#M599370</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-12-24T12:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Post 3.4, Patch 4, replication stop with PAN and CLI failed to con</title>
      <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357498#M599375</link>
      <description>&lt;P&gt;Thanks for the suggestion. Unfortunately, in our case, CLI access is not available(lost) on any node (P-PAN, S-PAN, PSNs, pxGrid, MNT). SSH, console, and CIMC KVM all exhibit the same behaviour where authentication succeeds, but the shell session immediately closes. I can't share a screenshot on this platform, but cli output is saying " failed to connect server" after passing login credentials.&lt;/P&gt;&lt;P&gt;We already attempted a PAN role switch to S-PAN as a new P-PAN was introduced, but not help. This indicates the issue is not specific to the P-PAN role but is systemic across the cluster. Saw replication log collected from debug: "org.jgroups.protocols.TUNNEL -:::::- Failed connecting to GossipRouter at pan-test.com/192.168.1.1:12001"&lt;/P&gt;&lt;P&gt;We are currently working with Cisco TAC/BU/Engineering, who are investigating this as an OS-level / recovery scenario. We’ll share updates once TAC completes the analysis.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2025 15:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357498#M599375</guid>
      <dc:creator>anilraj_003</dc:creator>
      <dc:date>2025-12-24T15:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Post 3.4, Patch 4, replication stop with PAN and CLI failed to con</title>
      <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357510#M599378</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/661113"&gt;@anilraj_003&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;thanks for your feedback. Please keep us posted !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: I've had issues in the past that would occur only in a &lt;STRONG&gt;Distributed Deployment&lt;/STRONG&gt;. When I removed the &lt;STRONG&gt;SPAN&lt;/STRONG&gt; from the &lt;STRONG&gt;Cluster&lt;/STRONG&gt; and it became a &lt;STRONG&gt;Standalone&lt;/STRONG&gt;, the problem was fixed, and from that point on I could recreate the &lt;STRONG&gt;Cluster&lt;/STRONG&gt; via this &lt;STRONG&gt;SPAN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2025 17:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5357510#M599378</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-12-24T17:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Post 3.4, Patch 4, replication stop with PAN and CLI failed to con</title>
      <link>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5362173#M599561</link>
      <description>&lt;P&gt;RCA by the engineering team. The combination of the upgrade path -3.4.0-608-&amp;gt;pathc-3-patch-4 and this SNMP config caused the CLI to break. This patch does not accepting location that has a special character "[]" in snmp locaiton field. and breakthe whole cluster.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Restoration: boot from rescue image, mount sysimage, remove locaiton filed from initial_configuration.xml. under opt.confd/confd-cdb. Then de-registeered node and registered it back to the cluster.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 14:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/post-3-4-patch-4-replication-stop-with-pan-and-cli-failed-to/m-p/5362173#M599561</guid>
      <dc:creator>anilraj_003</dc:creator>
      <dc:date>2026-01-16T14:24:05Z</dc:date>
    </item>
  </channel>
</rss>

