cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3233
Views
0
Helpful
1
Replies

Cisco ISE 2.3 - Docker Daemon not running

Y4ssine
Level 1
Level 1

Hello everyone.

 

When I checked the application status of ISE, I saw that the Docker Daemon service was not running:

 

ISE-01/admin# show application status ise

 

ISE PROCESS NAME                       STATE            PROCESS ID 

--------------------------------------------------------------------

Database Listener                      running          24205      

Database Server                        running          74 PROCESSES

Application Server                     running          29726       

Profiler Database                      running          26075      

ISE Indexing Engine                    running          31533      

AD Connector                           running          1260       

M&T Session Database                   running          25977      

M&T Log Collector                      running          29865      

M&T Log Processor                      running          29776      

Certificate Authority Service          disabled                    

EST Service                            disabled                    

SXP Engine Service                     disabled                    

Docker Daemon                          not running                 

TC-NAC Service                         disabled       

Wifi Setup Helper Container            disabled                    

pxGrid Infrastructure Service          disabled                    

pxGrid Publisher Subscriber Service    disabled                    

pxGrid Connection Manager              disabled                     

pxGrid Controller                      disabled                    

PassiveID WMI Service                  disabled                    

PassiveID Syslog Service               disabled                    

PassiveID API Service                  disabled                    

PassiveID Agent Service                disabled                    

PassiveID Endpoint Service             disabled                    

PassiveID SPAN Service                 disabled                    

DHCP Server (dhcpd)                    disabled                    

DNS Server (named)                     disabled                    

 

ISE-01/admin#

 

After doing a stop and start of the ISE application I saw following error:

 

ISE-01/admin# application start ise

Starting ISE Monitoring & Troubleshooting Session Database...
Starting ISE Profiler Database...
su: warning: cannot change directory to /home/iseprofilerdb: No such file or directory
su: warning: cannot change directory to /home/iseprofilerdb: No such file or directory
su: warning: cannot change directory to /home/iseprofilerdb: No such file or directory
/bin/chown: cannot access â/home/iseadminportal/.keystoreâ: No such file or directory
/bin/chmod: cannot access â/home/iseadminportal/.keystoreâ: No such file or directory
Starting ISE Application Server...
Starting ISE Monitoring & Troubleshooting Log Processor...
Starting ISE Monitoring & Troubleshooting Log Collector...
Starting ISE Indexing Engine...
su: warning: cannot change directory to /home/iseelasticsearch: No such file or directory
Starting docker daemon ...
Job for docker.service failed because the control process exited with error code. See "systemctl status docker.service" and "journalctl -xe" for details.

WifiSetup is disabled.....
Starting ISE AD Connector...
Note: ISE Processes are initializing. Use 'show application status ise'
      CLI to verify all processes are in running state.

ISE-01/admin#

 

Is there anyone who already encountered this and knows how to get it running again ? This is the first time I see it in not running state.. However I haven't noticed something yet that isn't working properly due this.

 

Version we're running on:

# show version

Cisco Application Deployment Engine OS Release: 3.0
ADE-OS Build Version: 3.0.3.030
ADE-OS System Architecture: x86_64

Copyright (c) 2005-2014 by Cisco Systems, Inc.
All rights reserved.
Hostname: ISE-01


Version information of installed applications
---------------------------------------------

Cisco Identity Services Engine
---------------------------------------------
Version      : 2.3.0.298
Build Date   : Tue Jul 25 19:02:37 2017
Install Date : Mon Aug 28 12:38:57 2017

Cisco Identity Services Engine Patch
---------------------------------------------
Version      : 3
Install Date : Mon Jul 16 07:27:19 2018

ISE-01/admin#

 

Thanks a lot for taking a look into this and I'm looking forward to your replies.

 

 

Kind regards,

Yassine

Regards,
Yassine
Junior Network Engineer
1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee
The docker not starting is likely because you’re not using the wireless setup. This is only needed for those using secure access wizard

https://community.cisco.com/t5/security-documents/cisco-ise-secure-access-wizard-saw-guest-byod-and-secure-access/ta-p/3636602

Some more information as well - https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_010.html?bookSearch=true

Startup process behavior per release
2.2 and patch 1 - started by default
2.2 patch 2 - service disabled user directed via UI to enable in the CLI
2.3/2.4 - service disabled user directed via UI to enable via UI or CLI

If you’re experiencing an outage resulting to this then please open a tac case. Not sure about the profiling or other errors

View solution in original post

1 Reply 1

Jason Kunst
Cisco Employee
Cisco Employee
The docker not starting is likely because you’re not using the wireless setup. This is only needed for those using secure access wizard

https://community.cisco.com/t5/security-documents/cisco-ise-secure-access-wizard-saw-guest-byod-and-secure-access/ta-p/3636602

Some more information as well - https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_010.html?bookSearch=true

Startup process behavior per release
2.2 and patch 1 - started by default
2.2 patch 2 - service disabled user directed via UI to enable in the CLI
2.3/2.4 - service disabled user directed via UI to enable via UI or CLI

If you’re experiencing an outage resulting to this then please open a tac case. Not sure about the profiling or other errors