<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PassiveID problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5365329#M599643</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1104283"&gt;@Janne K.&lt;/a&gt;&amp;nbsp;since the port is not listening please verify in the GUI that a valid system certificate is assigned to the passive identity role.. if the certificate is correct, try disabling and then re-enabling the Passive Identity service checkbox under the Deployment settings to force the service to reload&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jan 2026 20:24:44 GMT</pubDate>
    <dc:creator>Stefan Mihajlov</dc:creator>
    <dc:date>2026-01-26T20:24:44Z</dc:date>
    <item>
      <title>PassiveID problems</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5361198#M599540</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Im having som trouble setting up PassiveID in a new ISE install.&lt;BR /&gt;ise version 3.4 patch 4&lt;/P&gt;&lt;P&gt;I have 3 nodes, all of them have passiveid enabled, and i can see the service running in cli with 'sh app stat ise'&lt;/P&gt;&lt;P&gt;in the ise passiveid-agent.log i see this continuously:&lt;BR /&gt;2026-01-14 13:28:33,941 ERROR [Timer-0][[]] com.cisco.idc.agent-probe -:::::- Agent DC04.domain.dk did not set DCs status during the last 5 minutes - marking it down.&lt;BR /&gt;2026-01-14 13:28:33,942 ERROR [Timer-0][[]] com.cisco.idc.agent-probe -:::::- Make sure agent is up and running.. Identity Mapping.probe = Agent , Identity Mapping.dc-host = DC04.domain.dk , Identity Mapping.server = ISEPAN-01 ,&lt;BR /&gt;2026-01-14 13:28:33,942 ERROR [Timer-0][[]] com.cisco.idc.agent-probe -:::::- Make sure agent is up and running.. Identity Mapping.probe = Agent , Identity Mapping.dc-host = DC04.domain.dk , Identity Mapping.server = ISEPSN-01 ,&lt;BR /&gt;2026-01-14 13:28:33,942 ERROR [Timer-0][[]] com.cisco.idc.agent-probe -:::::- Make sure agent is up and running.. Identity Mapping.probe = Agent , Identity Mapping.dc-host = DC04.domain.dk , Identity Mapping.server = ISEMON-01 ,&lt;/P&gt;&lt;P&gt;and on the DC in the CiscoISEPICAgent log i see this:&lt;BR /&gt;2026-01-14 13:31:29,652 ERROR - Rest Client, Error getting configuration from &lt;A href="https://ISEPAN-01.domain.dk:9095" target="_blank"&gt;https://ISEPAN-01.domain.dk:9095&lt;/A&gt; : The operation has timed out&lt;BR /&gt;2026-01-14 13:31:29,652 ERROR - Rest Client, Error getting configuration from &lt;A href="https://ISEPSN-01.domain.dk:9095" target="_blank"&gt;https://ISEPSN-01.domain.dk:9095&lt;/A&gt; : The operation has timed out&lt;BR /&gt;2026-01-14 13:31:29,652 ERROR - Rest Client, Error getting configuration from &lt;A href="https://ISEMON-01.domain.dk:9095" target="_blank"&gt;https://ISEMON-01.domain.dk:9095&lt;/A&gt; : The operation has timed out&lt;BR /&gt;2026-01-14 13:31:30,672 ERROR - Configuration , Received empty config&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;the pic service is running fine, also after a restart.&lt;/P&gt;&lt;P&gt;when i do a tcp dump from ISE i see that ISE closes the incoming connection on port 9095 from the DC: (picture)&lt;/P&gt;&lt;P&gt;And doing a 'show ports' on ise cli It does not show any port 9095 anywhere.&lt;/P&gt;&lt;P&gt;Reloading the nodes does not help either.&lt;/P&gt;&lt;P&gt;Should i just go ahead and contact TAC? or does anyone have had similar problems?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 13:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5361198#M599540</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2026-01-14T13:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID problems</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5365324#M599642</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1104283"&gt;@Janne K.&lt;/a&gt;&amp;nbsp;Did you figure it out? To me, it looks that because it fails to get the config, the socket is not opened, thus you don't see port 9095 opened, although the service is running.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Looks like you're hitting the bug, see the proposed WA:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvy83653?rfs=qvlogin" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCvy83653?rfs=qvlogin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;If not, suggest to upgrade to the latest patch, however to avoid unnecessary bloat on the HDD, backups and taking all this crap with you in following upgrades, first rollback all patches, before applying only the latest patch:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215406-patch-installation-on-ise-and-faq-durin.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215406-patch-installation-on-ise-and-faq-durin.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 19:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5365324#M599642</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-26T19:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID problems</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5365329#M599643</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1104283"&gt;@Janne K.&lt;/a&gt;&amp;nbsp;since the port is not listening please verify in the GUI that a valid system certificate is assigned to the passive identity role.. if the certificate is correct, try disabling and then re-enabling the Passive Identity service checkbox under the Deployment settings to force the service to reload&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 20:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5365329#M599643</guid>
      <dc:creator>Stefan Mihajlov</dc:creator>
      <dc:date>2026-01-26T20:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID problems</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5365421#M599649</link>
      <description>&lt;P&gt;After uninstalling patch 4 it started working as intended.&lt;BR /&gt;I tried with patch 3 instead, but that nukes the ise application on the sns-3855, (no problem on the 3815 though...) even on a fresh 3.4 install and then i have to reimage the nodes.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Im gonna get TAC involved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2026 07:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5365421#M599649</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2026-01-27T07:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID problems</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5378647#M600086</link>
      <description>&lt;P&gt;I ran into a bug.&amp;nbsp;&lt;A href="https://bst.cisco.com/quickview/bug/CSCws65812" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCws65812&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Bug is present from 3.3 p8 forwards. fix will likely com in 3.3 p11, 3.4 p6 and 3.5 p4&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 08:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5378647#M600086</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2026-03-23T08:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: PassiveID problems</title>
      <link>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5550236#M600352</link>
      <description>&lt;P&gt;Looks like it didn't make the cut for 3.4 p6. Unless they just haven't updated the BugID yet.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 15:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passiveid-problems/m-p/5550236#M600352</guid>
      <dc:creator>jonathankarras</dc:creator>
      <dc:date>2026-05-04T15:52:28Z</dc:date>
    </item>
  </channel>
</rss>

