<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC 6.2 ISE 2.2 integration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215481#M433440</link>
    <description>&lt;P&gt;actually i found out what is the problem. the CN for FMC side i need to set FQDN. so FMC and ISE only can communicate. thanks for your help too&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2017 09:18:18 GMT</pubDate>
    <dc:creator>Tee Chin Poh</dc:creator>
    <dc:date>2017-11-13T09:18:18Z</dc:date>
    <item>
      <title>FMC 6.2 ISE 2.2 integration</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3198280#M433400</link>
      <description>&lt;P&gt;Hi all ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;intergration between FMC and ISE fails when testing .&lt;/P&gt;
&lt;P&gt;i see the below errors in the logs after a successful ssl handshake :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Captured Jabberwerx log:2017-10-13T10:37:52 [ INFO]: curl_easy_setopt() for CURLOPT_URL: '&lt;A href="https://ISE-1.cn.aura:8910/pxgrid/mnt/sd/getSessionListByTime" target="_blank"&gt;https://ISE-1.cn.aura:8910/pxgrid/mnt/sd/getSessionListByTime&lt;/A&gt;'&lt;BR /&gt;Captured Jabberwerx log:2017-10-13T10:37:52 [ ERROR]: curl_easy_perform() failed: (6) Couldn't resolve host name at file build/gcl/src/pxgrid_bulkdownload_curl.c line 240&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it seems a dns resolving problem but the FMC resolve ISE hostname .&lt;BR /&gt;&lt;BR /&gt;a detailed log file is attached .&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;thank you for your help .&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3198280#M433400</guid>
      <dc:creator>hedhli.wael</dc:creator>
      <dc:date>2020-02-21T14:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 ISE 2.2 integration</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215273#M433423</link>
      <description>do you have any solution for this problem?</description>
      <pubDate>Sun, 12 Nov 2017 20:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215273#M433423</guid>
      <dc:creator>Tee Chin Poh</dc:creator>
      <dc:date>2017-11-12T20:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 ISE 2.2 integration</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215277#M433427</link>
      <description>&lt;P&gt;the problem disappeared after I sync the two (FMC and ISE) with the same ntp server&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2017 21:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215277#M433427</guid>
      <dc:creator>hedhli.wael</dc:creator>
      <dc:date>2017-11-12T21:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 ISE 2.2 integration</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215438#M433432</link>
      <description>&lt;P&gt;now i have this problem.currently i'm using self sign certificate on ISE and import to FMC.&lt;/P&gt;
&lt;P&gt;Queried 1 bulk download hostnames:ISE.ddpg.com:8910&lt;BR /&gt;...successfully connected to ISE server.&lt;BR /&gt;Starting bulk download&lt;BR /&gt;Captured Jabberwerx log:2017-11-13T07:36:45 [&amp;nbsp;&amp;nbsp;&amp;nbsp; INFO]: curl_easy_setopt() for CURLOPT_URL: '&lt;A href="https://ISE.ddpg.com:8910/pxgrid/mnt/sd/getSessionListByTime" target="_blank"&gt;https://ISE.ddpg.com:8910/pxgrid/mnt/sd/getSessionListByTime&lt;/A&gt;'&lt;BR /&gt;Starting SSL Handshake, SSL state:before/connect initialization&lt;BR /&gt;Rejecting this certificate presented by foreign server: Certificate with Serial Number '0x5A0860370000000071E91C75D3E246CE', issued by 'CN = ISE.ddpg.com', to 'CN = ISE.ddpg.com'&lt;BR /&gt;...because SSL negotiation encountered error: self signed certificate&lt;BR /&gt;...while validating this entry in the certificate chain: Certificate with Serial Number '0x5A0860370000000071E91C75D3E246CE', issued by 'CN = ISE.ddpg.com', to 'CN = ISE.ddpg.com'&lt;BR /&gt;Sending SSL alert:unknown CA&lt;BR /&gt;Sending SSL alert:close notify&lt;BR /&gt;Captured Jabberwerx log:2017-11-13T07:36:45 [&amp;nbsp;&amp;nbsp; ERROR]: curl_easy_perform() failed: (60) Peer certificate cannot be authenticated with given CA certificates at file build/gcl/src/pxgrid_bulkdownload_curl.c line 240&lt;BR /&gt;bulk download iter next failed REST errorPeer certificate cannot be authenticated with given CA certificates&lt;BR /&gt;Failed to validate bulk download.&lt;BR /&gt;disconnecting pxgrid&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 07:56:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215438#M433432</guid>
      <dc:creator>Tee Chin Poh</dc:creator>
      <dc:date>2017-11-13T07:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 ISE 2.2 integration</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215459#M433436</link>
      <description>&lt;P&gt;It seems like a certification authentication problem, did you checked ISE/FMC docs about the integration using self signed certs?&lt;BR /&gt;it is recommended to use CA certs, you can generate one using the csr file retrieved from your ISE.&lt;BR /&gt;certs must be for both server and client authentication (in the enhanced key usage) .&lt;/P&gt;
&lt;P&gt;Don't forget to upload the root certificate too .&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 08:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215459#M433436</guid>
      <dc:creator>hedhli.wael</dc:creator>
      <dc:date>2017-11-13T08:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 ISE 2.2 integration</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215481#M433440</link>
      <description>&lt;P&gt;actually i found out what is the problem. the CN for FMC side i need to set FQDN. so FMC and ISE only can communicate. thanks for your help too&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 09:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215481#M433440</guid>
      <dc:creator>Tee Chin Poh</dc:creator>
      <dc:date>2017-11-13T09:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 ISE 2.2 integration</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215483#M433446</link>
      <description>&lt;P&gt;Good &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 09:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-ise-2-2-integration/m-p/3215483#M433446</guid>
      <dc:creator>hedhli.wael</dc:creator>
      <dc:date>2017-11-13T09:22:28Z</dc:date>
    </item>
  </channel>
</rss>

