<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Connectivity critical Error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411814#M1081220</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TLDR: Can someone using FMC 6.6+ and ISE PIC have a look at his FMC 6.6 Health policy and check if ISE Health Policy is disabled ? Thanks !&lt;/P&gt;&lt;P&gt;/TLDR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I the only one to sense that TAC is no more what it used to be ?&lt;/P&gt;&lt;P&gt;It's been 5 WEEKS since this ticket was created and I'm still struggling with incoherent requests.&lt;/P&gt;&lt;P&gt;Last(Yesterday) of them is a complete copy/paste of an already non working attempt we tested one month ago: ditch all certs, use the ISE PKI instead on both ISE and FMC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course, as FMC show both bulk downloaded (on ADI restart) and updated sessions flawlessly, we know there's no problem with certs. I however tested one more time this configuration, and, Of course, it exhibits exactly the same behavior: Sessions are working, ISE Health monitor fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did one more test: On the brand new FMC 6.6.4, I changed the Health Policy to enable ISE Health Module.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It fails because its ISE Attributes checker is down. Sure. Lack of Attributes is one of ISE PIC limitations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone with FMC 6.6 + ISE PIC have a look at FMC Health policy and verify ISE Health module is disabled ?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jun 2021 07:11:32 GMT</pubDate>
    <dc:creator>Erwan LE BIHAN</dc:creator>
    <dc:date>2021-06-02T07:11:32Z</dc:date>
    <item>
      <title>FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Connectivity critical Error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4405434#M1080897</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;I've opened a Case with TAC (# 691307739) and, as It seems to be handled at turtle speed (20+ days) , I'm wondering if someone will have a good hint - or perhaps a solution ?&lt;/P&gt;&lt;P&gt;(TLDR:&lt;/P&gt;&lt;P&gt;My FMC is displaying a cosmetic error about ISE integration. This FMC 6.6 was connected to a Full ISE 3.0 trial and working, but as ISE 3.0 is not supported on FMC 6.6 compatibility matrix and I had no license, I had to go back to ISE PIC 2.6 and since this reinstall the error is displayed, but all is working.)&lt;/P&gt;&lt;P&gt;Here we have:&lt;/P&gt;&lt;P&gt;1 Firepower Management Center v6.6.3, handling two FTD 6.6.3 devices (1x FPR1120, 1xFTD5508x)&lt;/P&gt;&lt;P&gt;1 ISE PIC 2.6Patch5 - (Well, now, it's an ISE PIC 2.6... More on that later)&lt;/P&gt;&lt;P&gt;MS AD (4 DCs) ,MS DNS, Microsoft CA PKI (Single level) for internal cert, and a DUOProxy for Radius VPN Auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Internal Root CA Cert was imported in both ISE and FMC&lt;/P&gt;&lt;P&gt;* No problem for creating the realm, using LDAPS, and connect to the 4 DCs. LDAP Download is working.&lt;/P&gt;&lt;P&gt;* No problem for connecting ISE to FMC. Test is ok, Active sessions are correctly imported from ISE and displayed on dashboards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I've an error in Health, ISE Connection Status Monitor Display : "Check connectivity to ISE".&lt;/P&gt;&lt;P&gt;So far, what was tested by TAC:&lt;/P&gt;&lt;P&gt;* Discard all certs and subscriptions, use ISE PIC as a root CA, create FMC cert on ISE PIC Root CA and use all certs belonging to ISE PIC CA instead of AD PKI CA:&lt;/P&gt;&lt;P&gt;=&amp;gt; Same, integration works, test is ok, but error is still displayed.&lt;/P&gt;&lt;P&gt;=&amp;gt; I prefer to have certs belonging to our PKI, so I reverted 48 Hours later to a new batch of certs: no change (test ok, integration ok, error displayed).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This FMC was integrated multiple time with different ISE versions (PIC 2.4, full 2.4, 2.7,3.0 and now PIC 2.6) all sharing the same name and ip address.&lt;/P&gt;&lt;P&gt;(I had to try different versions because I was trying to use ISE Radius / Posture to get DUO working for MFA VPN access, and now it's working using DUOProxy directly as a radius server connected to AD and DUO so no need for a full ISE to get Radius server).&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use expert mode on FMC and start ADI with --debug, I can clearly see ADI connecting without problems to all 4 DCs, then to ISE-VM, all SSL Handshakes are ok, pxgrid_connection_connect ok, subscription &amp;amp;_on_connect called, callback fired...&lt;/P&gt;&lt;P&gt;Communications using PXGrid and then:&lt;/P&gt;&lt;PRE&gt;May 19 09:21:51  SF-IMS[32627]: [32677] ADI:adi.ISEConnection [INFO] adi.cpp:623:HandleLog(): ISEConnection queries find the following capability states: [sessionDirectory: 1, endpointProfileMeta
Data: 0, securityGroupTagMetaData: 0, EPS: 0, ANC: 0, SXP: 0]
May 19 09:21:51  SF-IMS[32627]: [32677] ADI:adi.Health [DEBUG] adi.cpp:620:HandleLog(): ISE Services is DOWN, as ISE Identityis DOWN&lt;BR /&gt;May 19 09:21:51 SF-IMS[32627]: [32677] ADI:adi.ISEConnection [INFO] adi.cpp:623:HandleLog(): Preparing subscription objects...&lt;BR /&gt;May 19 09:21:51 SF-IMS[32627]: [32677] ADI:adi.pxGridAdapter [DEBUG] adi.cpp:620:HandleLog(): pxgrid_capability_create(capability**:0x7f09f00085f8)...&lt;BR /&gt;May 19 09:21:51 SF-IMS[32627]: [32677] ADI:adi.pxGridAdapter [DEBUG] adi.cpp:620:HandleLog(): returns [OK|0x7f09f000b990]&lt;BR /&gt;[...]&lt;BR /&gt;May 19 09:21:51 SF-IMS[32627]: [32677] ADI:adi.ISEConnection [DEBUG] adi.cpp:620:HandleLog(): registered callback for capability SessionDirectoryCapability&lt;BR /&gt;May 19 09:21:51 SF-IMS[32627]: [32677] ADI:adi.Health [DEBUG] adi.cpp:620:HandleLog(): ISE Services is DOWN, as ISE Identityis DOWN&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;Only Session Directory Topic is checked in Identity Source - Not SXP Topic as ISE PIC is unable to handle them -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bulk Download start, and each entry is integrated without errors.&lt;/P&gt;&lt;P&gt;Then every new callback since bulk download is parsed...&lt;/P&gt;&lt;P&gt;So both ways are working ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm very open to any idea.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 13:55:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4405434#M1080897</guid>
      <dc:creator>Erwan LE BIHAN</dc:creator>
      <dc:date>2021-05-19T13:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Connectivity critical Error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411153#M1081188</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/167360" target="_self"&gt;&lt;SPAN class=""&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/167360"&gt;@Erwan LE BIHAN&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;P&gt;I had this problem and solved it by simply unchecking and checking a subscription topic (in my case, I've both options enable) and save it. In this way, the module will reload and then you can wait or force the health policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this works for you too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 May 2021 23:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411153#M1081188</guid>
      <dc:creator>#Mat</dc:creator>
      <dc:date>2021-05-31T23:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Connectivity critical Error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411326#M1081200</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/108846"&gt;@#Mat&lt;/a&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've made it a try (check Session Directory / SXP - save - uncheck both - save - check only session Directory - Save - Health Monitor / ISE Connectivity run) and it failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I took another route: I installed another FMC 6.6.4 from scratch on trial license, installed our internal PKI Root Cert, Created realm, downloaded users and Integrated it with ISE PIC.&lt;/P&gt;&lt;P&gt;Guess what ? Sessions integrations Working. No errors. At all.&lt;/P&gt;&lt;P&gt;So I looked at Health monitor and BY DEFAULT on FMC 6.6.4, ISE Health monitor is not enabled.&lt;/P&gt;&lt;P&gt;I exported initial Health Policy from this FMC and integrated it on my running FMC.&lt;/P&gt;&lt;P&gt;No more errors of course, as this Health module is not running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm waiting for TAC's response.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 09:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411326#M1081200</guid>
      <dc:creator>Erwan LE BIHAN</dc:creator>
      <dc:date>2021-06-01T09:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Connectivity critical Error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411384#M1081205</link>
      <description>&lt;P&gt;Well done! But that's correct, TAC should have a more logical answer for your case.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 12:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411384#M1081205</guid>
      <dc:creator>#Mat</dc:creator>
      <dc:date>2021-06-01T12:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Connectivity critical Error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411814#M1081220</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TLDR: Can someone using FMC 6.6+ and ISE PIC have a look at his FMC 6.6 Health policy and check if ISE Health Policy is disabled ? Thanks !&lt;/P&gt;&lt;P&gt;/TLDR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I the only one to sense that TAC is no more what it used to be ?&lt;/P&gt;&lt;P&gt;It's been 5 WEEKS since this ticket was created and I'm still struggling with incoherent requests.&lt;/P&gt;&lt;P&gt;Last(Yesterday) of them is a complete copy/paste of an already non working attempt we tested one month ago: ditch all certs, use the ISE PKI instead on both ISE and FMC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course, as FMC show both bulk downloaded (on ADI restart) and updated sessions flawlessly, we know there's no problem with certs. I however tested one more time this configuration, and, Of course, it exhibits exactly the same behavior: Sessions are working, ISE Health monitor fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did one more test: On the brand new FMC 6.6.4, I changed the Health Policy to enable ISE Health Module.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It fails because its ISE Attributes checker is down. Sure. Lack of Attributes is one of ISE PIC limitations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone with FMC 6.6 + ISE PIC have a look at FMC Health policy and verify ISE Health module is disabled ?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 07:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4411814#M1081220</guid>
      <dc:creator>Erwan LE BIHAN</dc:creator>
      <dc:date>2021-06-02T07:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Co</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4452430#M1083032</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;We are near the end of august and guess what... Case is still open. Nearly 5 MONTHS.&lt;/P&gt;&lt;P&gt;I never had such a bad experience with TAC. In fact, I never had such awful experience with any tech support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I'm working in IT since '93 - and worked with Digital Equipment when they sold PC Gears - &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's the first time one of my case is supported by ESTARTA SOLUTIONS for Cisco.&lt;/P&gt;&lt;P&gt;As a customer, I'm asked to supply trace file I never heard of. With no information on how to get it.&lt;/P&gt;&lt;P&gt;"As per escalation team request, can you please collect pcap captures from both FMC and ISE while you are performing connectivity test and upload them to the ticket ?"&lt;/P&gt;&lt;P&gt;And so I'm supposed to know that FMC is linux based, and that on ssh, expert mode, I'm able to do a capture with tcpdump and dump it in /var/common ? (I knew it, so I remembered it quite easily, but it's not simple task and will never ask this to one of my customer).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to get my case out of ESTARTA and get real answers from TAC ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 13:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4452430#M1083032</guid>
      <dc:creator>Erwan LE BIHAN</dc:creator>
      <dc:date>2021-08-20T13:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Co</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4480292#M1084211</link>
      <description>&lt;P&gt;Holy god !&lt;/P&gt;&lt;P&gt;Today, at 13:23 CET Time, the bug is acknowledged :&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz80535" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz80535&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So beware: don't connect your FMC to a PXGrid 2.0 ISE if you are not sure to keep it. There's no downgrade afterwards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4480292#M1084211</guid>
      <dc:creator>Erwan LE BIHAN</dc:creator>
      <dc:date>2021-10-05T12:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.6.3 - ISE PIC 2.6 Integration. Working but FMC Health ISE Co</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4822885#M1099957</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your suggestion. Having the same issue on 7.0.5 version. Unchecking and checking Subscription Topic solved. However opened a case to identify the root cause.&lt;/P&gt;&lt;P&gt;And yea completely agrre with the way Cisco TAC support has been handling the cases in the last two years. It's been an awful experience.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 11:04:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-6-3-ise-pic-2-6-integration-working-but-fmc-health-ise/m-p/4822885#M1099957</guid>
      <dc:creator>rubenmachado</dc:creator>
      <dc:date>2023-04-27T11:04:04Z</dc:date>
    </item>
  </channel>
</rss>

