<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change clock in ISE without impacting existing device admin via TA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466798#M1083682</link>
    <description>&lt;P&gt;Changing the timezone on an ISE server or deployment is generally not advised. It has been problematic and known to cause instability for the entire deployment. The suggested method is to rebuild new nodes with the correct desired timezone from scratch.&lt;/P&gt;
&lt;P&gt;If your timezone is correct but reflecting the incorrect time then the suggested method is to use a valid NTP server.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 09:13:57 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-09-15T09:13:57Z</dc:date>
    <item>
      <title>Change clock in ISE without impacting existing device admin via TACACS</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466791#M1083680</link>
      <description>&lt;P&gt;My ISE cube is made up of two nodes. I just enabled device admin to manage a few switches/routers via TACACS and it is working as expected. However, I noticed the system clock in ISE is different to the one of the routers/switches and to that of the AD controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The AD controller is set up with a time zone of UTC and the clock is correct. The switches/routers is using BST and their clock is also correct. ISE has it as UTC but it is one hour behind. I thought it would be a matter of just adjusting the clock in ISE using the command &lt;STRONG&gt;clock set Sep 15 15:00:00 2021 &lt;/STRONG&gt;but soon after I executed this command, I lost management access to the routers/switches via TACACS. Luckily, I did not save the configuration and rebooted ISE. When it came back up the clock went to be one hour behind again and I regained access to the NADs via TACACs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I setup the clock in ISE to match that of AD and the NADs without losing management via TACACS to the existing NADs. I would also like to change the time zone in ISE from UTC to BST.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to solve this issue before I go ahead and configure the rest of our network devices estate to use TACACS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your help will be much appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 09:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466791#M1083680</guid>
      <dc:creator>a.maldonado</dc:creator>
      <dc:date>2021-09-15T09:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466794#M1083681</link>
      <description>&lt;P&gt;First i would adviceto create a Local Account, and your AAA config should fall back to Local Admin, in case of ISE Fails - this is suggested approach always.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seconds, changing NTP should not cause any issue as i am ware,. i would suggest to use NTP Server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you like to change, change as below &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; for BST)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#clock timezone GB&lt;/P&gt;
&lt;P&gt;#ntp server x.x.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# show ntp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 09:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466794#M1083681</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-09-15T09:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466798#M1083682</link>
      <description>&lt;P&gt;Changing the timezone on an ISE server or deployment is generally not advised. It has been problematic and known to cause instability for the entire deployment. The suggested method is to rebuild new nodes with the correct desired timezone from scratch.&lt;/P&gt;
&lt;P&gt;If your timezone is correct but reflecting the incorrect time then the suggested method is to use a valid NTP server.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 09:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466798#M1083682</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-09-15T09:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466841#M1083691</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Changing the timezone should not impact your TACACS access unless it went&lt;BR /&gt;out of sync with AD. Are you using LDAP or LDAPS with AD? For LDAPS,&lt;BR /&gt;changing clock might be a problem for certificate validation. That is the&lt;BR /&gt;only thing I can think of. Otherwise, it should be fine.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Sep 2021 10:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4466841#M1083691</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-09-15T10:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467945#M1083750</link>
      <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure if we are using LDAP or LDAPs I will find out tomorrow and get back to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 19:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467945#M1083750</guid>
      <dc:creator>a.maldonado</dc:creator>
      <dc:date>2021-09-16T19:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467949#M1083751</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ISE cube was setup by a contractor a few months ago. The time zone is UTC and an hour and some minutes behind our AD and NADs.&lt;/P&gt;&lt;P&gt;I just started using it for device admin only and have a few NADs being managed via TACACS, so I guess it is going to cause problems I better d it now than later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your comments.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 19:10:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467949#M1083751</guid>
      <dc:creator>a.maldonado</dc:creator>
      <dc:date>2021-09-16T19:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467955#M1083752</link>
      <description>&lt;P&gt;I will try your suggestion Balaji tomorrow and let you know.&lt;/P&gt;&lt;P&gt;Will I need to use the clock command to setup the clock?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 19:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467955#M1083752</guid>
      <dc:creator>a.maldonado</dc:creator>
      <dc:date>2021-09-16T19:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467963#M1083753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing the clock will break AD as an external identity source if ISE is configured that way and will go out of sync. It happened to me.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 19:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4467963#M1083753</guid>
      <dc:creator>bbouchaiba</dc:creator>
      <dc:date>2021-09-16T19:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469262#M1083805</link>
      <description>&lt;P&gt;Balaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was trying the commands you sent me but soon after changing the timezone I got prompted with the below messages.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;% On ise distributed deployments, it is recommended all nodes be&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;% configured with the same time zone.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;% Changing the time zone may result in undesired side effects&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;% Recommended to reimage the node after changing the time zone&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody know if I need to remimage?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Sep 2021 12:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469262#M1083805</guid>
      <dc:creator>a.maldonado</dc:creator>
      <dc:date>2021-09-18T12:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469506#M1083815</link>
      <description>&lt;P&gt;As I mentioned on my 9/15 reply, reimage is the strongly recommended approach. The problems that may arise due to changing the timezone manually will cause many hours of avoidable troubleshooting.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Sep 2021 10:44:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469506#M1083815</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-09-19T10:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469557#M1083821</link>
      <description>&lt;P&gt;Thank you Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So by reimaging the box will I have to snch it again with AD, add all the NDAs and configure the policies for network admin, etc.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Sep 2021 15:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469557#M1083821</guid>
      <dc:creator>a.maldonado</dc:creator>
      <dc:date>2021-09-19T15:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Change clock in ISE without impacting existing device admin via TA</title>
      <link>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469869#M1083828</link>
      <description>&lt;P&gt;In a 2-node deployment you can re-image the nodes one at a time and then rejoin them.&lt;/P&gt;
&lt;P&gt;Start with the Secondary PAN, reimage and join the deployment. Join the node to AD and once everything is synced and healthy, promote it to Primary. Then repeat for the other node.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 04:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-clock-in-ise-without-impacting-existing-device-admin-via/m-p/4469869#M1083828</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-09-20T04:32:52Z</dc:date>
    </item>
  </channel>
</rss>

