<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Primary Admin failover and failback issue. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5362975#M599585</link>
    <description>&lt;P&gt;Nothing surprises me anymore with ISE. I don't think you have done anything wrong to cause this issue. It's just the usual software quality that bites when you least expect it. I find that gremlins creep into the system after upgrades and patching, especially the more upgrades that have been done. The best run I have had has been after rebuilding ISE from scratch (painfully) instead of upgrading. But since 3.3 to 3.4 the gremlins have returned. But I can't afford to rebuild the entire thing again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But an operational activity such as promoting the PAN should never result in such an a catastrophic outcome.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jan 2026 00:59:26 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2026-01-20T00:59:26Z</dc:date>
    <item>
      <title>Cisco ISE Primary Admin failover and failback issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5362941#M599583</link>
      <description>&lt;P data-start="168" data-end="331"&gt;I need advice from experts on this forum regarding a very strange issue that occurred in March 2025 at my current workplace, one month before I joined the company.&lt;/P&gt;
&lt;P data-start="333" data-end="418"&gt;We have a Cisco ISE 3.1 Patch 10 cluster deployed across two data centers as follows:&lt;/P&gt;
&lt;UL data-start="420" data-end="644"&gt;
&lt;LI data-start="420" data-end="480"&gt;
&lt;P data-start="422" data-end="480"&gt;&lt;STRONG data-start="422" data-end="431"&gt;ise01&lt;/STRONG&gt;: Primary Admin / Secondary MnT (Data Center A)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="481" data-end="541"&gt;
&lt;P data-start="483" data-end="541"&gt;&lt;STRONG data-start="483" data-end="492"&gt;ise02&lt;/STRONG&gt;: Secondary Admin / Primary MnT (Data Center B)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="542" data-end="576"&gt;
&lt;P data-start="544" data-end="576"&gt;&lt;STRONG data-start="544" data-end="553"&gt;ise03&lt;/STRONG&gt;: PSN (Data Center A)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="577" data-end="611"&gt;
&lt;P data-start="579" data-end="611"&gt;&lt;STRONG data-start="579" data-end="588"&gt;ise04&lt;/STRONG&gt;: PSN (Data Center A)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="612" data-end="644"&gt;
&lt;P data-start="614" data-end="644"&gt;&lt;STRONG data-start="614" data-end="623"&gt;ise05&lt;/STRONG&gt;: PSN (Data Center B)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="646" data-end="901"&gt;In March 2025, we performed a Disaster Recovery (DR) exercise that required completely cutting off connectivity to Data Center A. Prior to disconnecting Data Center A, we promoted &lt;STRONG data-start="826" data-end="835"&gt;ise02&lt;/STRONG&gt; to Primary Admin / Primary MnT, resulting in the following state:&lt;/P&gt;
&lt;UL data-start="903" data-end="1127"&gt;
&lt;LI data-start="903" data-end="965"&gt;
&lt;P data-start="905" data-end="965"&gt;&lt;STRONG data-start="905" data-end="914"&gt;ise01&lt;/STRONG&gt;: Secondary Admin / Secondary MnT (Data Center A)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="966" data-end="1024"&gt;
&lt;P data-start="968" data-end="1024"&gt;&lt;STRONG data-start="968" data-end="977"&gt;ise02&lt;/STRONG&gt;: Primary Admin / Primary MnT (Data Center B)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1025" data-end="1059"&gt;
&lt;P data-start="1027" data-end="1059"&gt;&lt;STRONG data-start="1027" data-end="1036"&gt;ise03&lt;/STRONG&gt;: PSN (Data Center A)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1060" data-end="1094"&gt;
&lt;P data-start="1062" data-end="1094"&gt;&lt;STRONG data-start="1062" data-end="1071"&gt;ise04&lt;/STRONG&gt;: PSN (Data Center A)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1095" data-end="1127"&gt;
&lt;P data-start="1097" data-end="1127"&gt;&lt;STRONG data-start="1097" data-end="1106"&gt;ise05&lt;/STRONG&gt;: PSN (Data Center B)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1129" data-end="1445"&gt;After the promotion, everything looked good, and we cut off connectivity to and from Data Center A. During the outage, we were able to successfully authenticate 802.1X on both wired and wireless networks between ISE and Cisco switches and Cisco wireless controllers. MAC Address Bypass (MAB) also worked as expected.&lt;/P&gt;
&lt;P data-start="1447" data-end="1702"&gt;After completing the DR exercise, we restored network connectivity to and from Data Center A. Once connectivity was restored, the ISE cluster appeared healthy, with all nodes in green status. The following day, we promoted &lt;STRONG data-start="1670" data-end="1679"&gt;ise01&lt;/STRONG&gt; back to Primary Admin.&lt;/P&gt;
&lt;P data-start="1704" data-end="2053"&gt;At that point, everything appeared normal; however, we discovered that &lt;STRONG data-start="1775" data-end="1829"&gt;all MAC addresses in the MAB database were missing&lt;/STRONG&gt;, which caused a widespread outage affecting printers and Cisco IP phones. To recover, I restored a previous ISE backup to a lab evaluation instance, extracted the MAB database, and restored it to the production environment.&lt;/P&gt;
&lt;P data-start="2055" data-end="2201"&gt;We opened a support case with Cisco, but the root cause was inconclusive. Since then, we have upgraded the ISE environment to &lt;STRONG data-start="2181" data-end="2200"&gt;ISE 3.3 Patch 7&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="2203" data-end="2391"&gt;We are planning another DR exercise in approximately five weeks, and I am very nervous about failover and failback with Cisco ISE. What is the likelihood that this issue could occur again?&lt;/P&gt;
&lt;P data-start="2393" data-end="2402"&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 21:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5362941#M599583</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2026-01-19T21:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Primary Admin failover and failback issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5362975#M599585</link>
      <description>&lt;P&gt;Nothing surprises me anymore with ISE. I don't think you have done anything wrong to cause this issue. It's just the usual software quality that bites when you least expect it. I find that gremlins creep into the system after upgrades and patching, especially the more upgrades that have been done. The best run I have had has been after rebuilding ISE from scratch (painfully) instead of upgrading. But since 3.3 to 3.4 the gremlins have returned. But I can't afford to rebuild the entire thing again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But an operational activity such as promoting the PAN should never result in such an a catastrophic outcome.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 00:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5362975#M599585</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2026-01-20T00:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Primary Admin failover and failback issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5364467#M599618</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;before promoting the &lt;STRONG&gt;SPAN&lt;/STRONG&gt; to a new &lt;STRONG&gt;PPAN&lt;/STRONG&gt;, I recommend a &lt;STRONG&gt;Syncup&lt;/STRONG&gt; (at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Deployment&lt;/STRONG&gt;) with the &lt;STRONG&gt;PPAN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 01:24:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5364467#M599618</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2026-01-23T01:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Primary Admin failover and failback issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5365638#M599658</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;before promoting the &lt;STRONG&gt;SPAN&lt;/STRONG&gt; to a new &lt;STRONG&gt;PPAN&lt;/STRONG&gt;, I recommend a &lt;STRONG&gt;Syncup&lt;/STRONG&gt; (at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Deployment&lt;/STRONG&gt;) with the &lt;STRONG&gt;PPAN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Everything is already Sync'ed as showing "green" status in the UI.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2026 20:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-primary-admin-failover-and-failback-issue/m-p/5365638#M599658</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2026-01-27T20:31:33Z</dc:date>
    </item>
  </channel>
</rss>

