<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE - Loss of All Nodes in a Distributed Deployment, Recovery Using New IP Addresses and Hostnames in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-loss-of-all-nodes-in-a-distributed-deployment-recovery-using/m-p/2485339#M90548</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question regarding ISE disaster recovery with same hostname and IP. For step 2, is it a must to generate a self signed cert? is it possible to use back to original N1 CA- signed certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBl_BlockLabel" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-weight: bold; margin: 1px 0em 6px; line-height: normal;"&gt;esolution Steps&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073092" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNF_NumFirst" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;1.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;Obtain the N1 backup and restore it on N1A. See&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_backup.html#wp1053926" style="color: rgb(51, 102, 204);" target="_blank"&gt;"Restoring Data from a Backup" section&lt;/A&gt;&lt;SPAN class="cXRef_Color" style="color: blue;"&gt;&amp;nbsp;&lt;/SPAN&gt;for more information. The restore script will identify the hostname change and domain name change, and will update the hostname and domain name in the deployment configuration based on the current hostname.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073095" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNN_NumNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;SPAN style="color:#FF0000;"&gt;&lt;B&gt;2.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;You must generate a new self-signed certificate. See&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_man_cert.html#wpxref98538" style="color: rgb(51, 102, 204);" target="_blank"&gt;&lt;SPAN style="color:#FF0000;"&gt;"Generating a Self-Signed Certificate" section&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color:#FF0000;"&gt;&amp;nbsp;for more information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073099" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNN_NumNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;3.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;You must log in to the Cisco ISE user interface on N1A, choose&amp;nbsp;&lt;B class="cCN_CmdName"&gt;Administration &amp;gt; System &amp;gt; Deployment&lt;/B&gt;, and do the following:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073100" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNsF_NumsubFirst" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;a.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;Delete the old N2 node. See&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_dis_deploy.html#wpxref36346" style="color: rgb(51, 102, 204);" target="_blank"&gt;"Removing a Node from Deployment" section&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073102" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;b.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;Register the new N2A node as a secondary node. See&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_dis_deploy.html#wpxref46230" style="color: rgb(51, 102, 204);" target="_blank"&gt;"Registering and Configuring a Secondary Node" section&lt;/A&gt;&lt;SPAN class="cXRef_Color" style="color: blue;"&gt;&amp;nbsp;&lt;/SPAN&gt;for more information. Data from the N1A node will be replicated to the N2A node.&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_backup.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_backup.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:43:08 GMT</pubDate>
    <dc:creator>Tai Eric</dc:creator>
    <dc:date>2019-03-11T04:43:08Z</dc:date>
    <item>
      <title>ISE - Loss of All Nodes in a Distributed Deployment, Recovery Using New IP Addresses and Hostnames</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-loss-of-all-nodes-in-a-distributed-deployment-recovery-using/m-p/2485339#M90548</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question regarding ISE disaster recovery with same hostname and IP. For step 2, is it a must to generate a self signed cert? is it possible to use back to original N1 CA- signed certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBl_BlockLabel" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-weight: bold; margin: 1px 0em 6px; line-height: normal;"&gt;esolution Steps&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073092" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNF_NumFirst" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;1.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;Obtain the N1 backup and restore it on N1A. See&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_backup.html#wp1053926" style="color: rgb(51, 102, 204);" target="_blank"&gt;"Restoring Data from a Backup" section&lt;/A&gt;&lt;SPAN class="cXRef_Color" style="color: blue;"&gt;&amp;nbsp;&lt;/SPAN&gt;for more information. The restore script will identify the hostname change and domain name change, and will update the hostname and domain name in the deployment configuration based on the current hostname.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073095" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNN_NumNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;SPAN style="color:#FF0000;"&gt;&lt;B&gt;2.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;You must generate a new self-signed certificate. See&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_man_cert.html#wpxref98538" style="color: rgb(51, 102, 204);" target="_blank"&gt;&lt;SPAN style="color:#FF0000;"&gt;"Generating a Self-Signed Certificate" section&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color:#FF0000;"&gt;&amp;nbsp;for more information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073099" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNN_NumNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;3.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;You must log in to the Cisco ISE user interface on N1A, choose&amp;nbsp;&lt;B class="cCN_CmdName"&gt;Administration &amp;gt; System &amp;gt; Deployment&lt;/B&gt;, and do the following:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073100" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNsF_NumsubFirst" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;a.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;Delete the old N2 node. See&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_dis_deploy.html#wpxref36346" style="color: rgb(51, 102, 204);" target="_blank"&gt;"Removing a Node from Deployment" section&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1073102" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;b.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;Register the new N2A node as a secondary node. See&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_dis_deploy.html#wpxref46230" style="color: rgb(51, 102, 204);" target="_blank"&gt;"Registering and Configuring a Secondary Node" section&lt;/A&gt;&lt;SPAN class="cXRef_Color" style="color: blue;"&gt;&amp;nbsp;&lt;/SPAN&gt;for more information. Data from the N1A node will be replicated to the N2A node.&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNsN_NumsubNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.9in; text-indent: -0.25in; line-height: normal;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_backup.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/user_guide/ise_user_guide/ise_backup.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-loss-of-all-nodes-in-a-distributed-deployment-recovery-using/m-p/2485339#M90548</guid>
      <dc:creator>Tai Eric</dc:creator>
      <dc:date>2019-03-11T04:43:08Z</dc:date>
    </item>
    <item>
      <title>Hi,The reason for asking to</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-loss-of-all-nodes-in-a-distributed-deployment-recovery-using/m-p/2485340#M90550</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The reason for asking to create a self signed cert is , the subject name of the certificate should match&amp;nbsp; ISE node FQDN. If you import the N1 node CA- signed certificate, that certificate will have the hostname of N1 node as its subject name and it will not work.&lt;/P&gt;&lt;P&gt;So you have to create a self signed certificate or get a new CA signed certificate with subject name as&amp;nbsp;N1A node FQDN.&lt;/P&gt;&lt;P&gt;Hope this clarifies the reason of self signed certificate.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2014 17:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-loss-of-all-nodes-in-a-distributed-deployment-recovery-using/m-p/2485340#M90550</guid>
      <dc:creator>Naresh Ginjupalli</dc:creator>
      <dc:date>2014-09-10T17:46:31Z</dc:date>
    </item>
    <item>
      <title>As long as:- The newly built</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-loss-of-all-nodes-in-a-distributed-deployment-recovery-using/m-p/2485341#M90552</link>
      <description>&lt;P&gt;As long as:&lt;/P&gt;&lt;P&gt;- The newly built node has the same FQDN&lt;/P&gt;&lt;P&gt;- You have the original signed certificate and private key&lt;/P&gt;&lt;P&gt;- Root's and subordinate's (If any) CA certificates&lt;/P&gt;&lt;P&gt;Then you should be able to just re-import the cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 22:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-loss-of-all-nodes-in-a-distributed-deployment-recovery-using/m-p/2485341#M90552</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-09-11T22:18:19Z</dc:date>
    </item>
  </channel>
</rss>

