<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS 5.5 - External Identity Stores - AD - node 2 - Node Not Responding in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-5-external-identity-stores-ad-node-2-node-not/m-p/2616733#M74728</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I login&amp;nbsp;Node1 GUI [Primary node], found node 2 [Secondary node] status: Node Not Responding.&amp;nbsp;Join/Test Connection from Node1&amp;nbsp;for Node2&amp;nbsp;failed.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cisco ACS 5.5 - External Identity Stores - AD - node 2 - status: Node Not Responding&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I login to Node2 GUI and verified that Node2 to AD is Joint and Connected. Join/Test Connection from Node2 are&amp;nbsp;all passed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuration replication is working fine. I believe Node1 is using IP to communicate with Node2&lt;/P&gt;&lt;P&gt;&lt;EM&gt;System Administration, Operations, Distributed System Management, Node2 status: Updated and Replication time&amp;nbsp;is recent.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For AD, it seems like Node1 couldn't talk to Node2 to check the communication between Node2 and AD. But Node2 is able to communicate with AD.&lt;/P&gt;&lt;P&gt;Are they using DNS to resolve from nodename to IP? Do we have to register A record on DNS server for both ACS nodes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSH to both nodes and show application status, all running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:24:56 GMT</pubDate>
    <dc:creator>hujian</dc:creator>
    <dc:date>2019-03-11T05:24:56Z</dc:date>
    <item>
      <title>Cisco ACS 5.5 - External Identity Stores - AD - node 2 - Node Not Responding</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-5-external-identity-stores-ad-node-2-node-not/m-p/2616733#M74728</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I login&amp;nbsp;Node1 GUI [Primary node], found node 2 [Secondary node] status: Node Not Responding.&amp;nbsp;Join/Test Connection from Node1&amp;nbsp;for Node2&amp;nbsp;failed.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cisco ACS 5.5 - External Identity Stores - AD - node 2 - status: Node Not Responding&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I login to Node2 GUI and verified that Node2 to AD is Joint and Connected. Join/Test Connection from Node2 are&amp;nbsp;all passed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuration replication is working fine. I believe Node1 is using IP to communicate with Node2&lt;/P&gt;&lt;P&gt;&lt;EM&gt;System Administration, Operations, Distributed System Management, Node2 status: Updated and Replication time&amp;nbsp;is recent.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For AD, it seems like Node1 couldn't talk to Node2 to check the communication between Node2 and AD. But Node2 is able to communicate with AD.&lt;/P&gt;&lt;P&gt;Are they using DNS to resolve from nodename to IP? Do we have to register A record on DNS server for both ACS nodes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSH to both nodes and show application status, all running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-5-external-identity-stores-ad-node-2-node-not/m-p/2616733#M74728</guid>
      <dc:creator>hujian</dc:creator>
      <dc:date>2019-03-11T05:24:56Z</dc:date>
    </item>
    <item>
      <title>I've seen the same issue ...</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-5-external-identity-stores-ad-node-2-node-not/m-p/2616734#M74729</link>
      <description>&lt;P&gt;I've seen the same issue ... seems to be a bug.&lt;/P&gt;&lt;P&gt;https://tools.cisco.com/quickview/bug/CSCuv10688&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 19:44:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-5-external-identity-stores-ad-node-2-node-not/m-p/2616734#M74729</guid>
      <dc:creator>eoinwhite1</dc:creator>
      <dc:date>2015-07-22T19:44:13Z</dc:date>
    </item>
    <item>
      <title>In order to join Secondary</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-5-external-identity-stores-ad-node-2-node-not/m-p/2616735#M74730</link>
      <description>&lt;P&gt;In order to join Secondary Node and PSNs to Primary PAN Node is mandatory to have a DNS Entry for the FQDN Name of the Secondary and PSNs ISEs&amp;nbsp;and valid certificate on those signed by a trusted certificate authority registered on Primary ISE Local Certificate Store.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2015 17:01:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-5-external-identity-stores-ad-node-2-node-not/m-p/2616735#M74730</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2015-07-24T17:01:59Z</dc:date>
    </item>
  </channel>
</rss>

