<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.1.2 failover - Syncronization issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-1-2-failover-syncronization-issue/m-p/2278116#M92401</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I may have misunderstood your problem, but.... for your first problem, are you expecting the Monitor node status to change when you promote node 2? You're only promoting the admin role, the monitor role will remain unchanged unless you choose to change which is primary monitor node too (totally separate).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd problem. Sounds like certificate maybe? What are you using in the way of certs for the nodes to auth each other? Did you swap the self signed certs for instance between nodes? Changed certs recently and not delete old ones? I've seen old certs which seem to have been deleted hang around until a full reload.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Sep 2013 22:57:54 GMT</pubDate>
    <dc:creator>bikespace</dc:creator>
    <dc:date>2013-09-30T22:57:54Z</dc:date>
    <item>
      <title>ISE 1.1.2 failover - Syncronization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-2-failover-syncronization-issue/m-p/2278115#M92383</link>
      <description>&lt;P&gt;Hi everone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenário:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I've deployed two Cisco ISE 1.1.2 nodes as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Node 1 as Primrary Admin, Policy Server and Monitoring&lt;/P&gt;&lt;P&gt;Node 2 as Secondary Admin, Policy Server and Monitoring&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All configured roles works as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Once I promote the &lt;STRONG style="font-size: 10pt;"&gt;Node &lt;/STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="font-size: 10pt; "&gt;2 &lt;/STRONG&gt;&lt;SPAN style="color: #000000; font-size: 10pt; "&gt;(S&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; color: #000000;"&gt;econdary node) to become the Primary the problem takes place as described bellow:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- The &lt;STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt;Node&lt;/SPAN&gt;&lt;SPAN style="color: #ff0000;"&gt; 2&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN style="font-size: 10pt;"&gt;restarts the ISE Application and assumes the Primary &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Admin, Policy Server roles (but Monitoring role remains as Primary&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2- The &lt;STRONG&gt;Node&lt;SPAN style="color: #ff0000;"&gt; 1&lt;/SPAN&gt;&lt;/STRONG&gt; restarts the ISE Application too and Second&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;ary Admin, Policy Server &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;roles (but Monitoring role remains as Secondaary)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the ISE Application becomes up in both nodes the syncronization status appear as &lt;SPAN style="color: #ff0000;"&gt;NODE NOT REACHABLE&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone faced this issue before, or have any idea about it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-2-failover-syncronization-issue/m-p/2278115#M92383</guid>
      <dc:creator>Paulo Moreira Magalhaes</dc:creator>
      <dc:date>2019-03-26T00:31:07Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.2 failover - Syncronization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-2-failover-syncronization-issue/m-p/2278116#M92401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I may have misunderstood your problem, but.... for your first problem, are you expecting the Monitor node status to change when you promote node 2? You're only promoting the admin role, the monitor role will remain unchanged unless you choose to change which is primary monitor node too (totally separate).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd problem. Sounds like certificate maybe? What are you using in the way of certs for the nodes to auth each other? Did you swap the self signed certs for instance between nodes? Changed certs recently and not delete old ones? I've seen old certs which seem to have been deleted hang around until a full reload.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 22:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-2-failover-syncronization-issue/m-p/2278116#M92401</guid>
      <dc:creator>bikespace</dc:creator>
      <dc:date>2013-09-30T22:57:54Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.2 failover - Syncronization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-2-failover-syncronization-issue/m-p/2278117#M92411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got the problem solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both nodes are in diferent location and they are behind a firewall in each location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem was a wrong NAT statement on firewall in which the node 2 resides behind to. This NAT was preventing Node 2 to iniciate the database syncronization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 20:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-2-failover-syncronization-issue/m-p/2278117#M92411</guid>
      <dc:creator>Paulo Moreira Magalhaes</dc:creator>
      <dc:date>2013-10-03T20:50:05Z</dc:date>
    </item>
  </channel>
</rss>

