02-21-2023 05:41 AM
We have 2 ISE nodes. We upgraded from 2.4 to 2.7 P9.
After the upgrade i noticed that the (ISE Messaging Service) is not running on Node 2. It keeps flapping between Initializing and not running. I applied patch 9 but that didn't change the situation.
I'm not sure of what is the actual impact. And how to solve this. I tried to regenrate CSR for this service, but didn't help. Also restarting the services or rebooting didn't help.
Solved! Go to Solution.
02-21-2023 06:03 AM
02-21-2023 06:17 AM
From the 2.6 Release Notes:
Syslog over ISE MessagingFrom Cisco ISE, Release 2.6, Monitoring and Troubleshooting (MnT) WAN Survivability is available for UDP syslog collection. Syslogs are recorded using ISE Messaging Service. The Remote Logging Targets, where the syslogs are collected and stored uses port TCP 8671 and the Secure Advanced Message Queuing Protocols (AMQPs) for sending syslogs to MnT.
By default, the ISE Messaging Service option is disabled until Cisco ISE, Release 2.6 Patch 1.
From Cisco ISE, Release 2.6 Patch 2 onwards, by default, the ISE Messaging Service option is enabled.
For more information, see the Cisco Identity Services Engine Administrator Guide, Release 2.6
Business Outcome: Operational data will be retained for a finite duration even when the MnT node is unreachable.
02-21-2023 06:03 AM
02-21-2023 06:21 AM
Thanks for your response. I also noticed something... when i regenerate the CSR, i don't see the certificate in the Certificate Authority Certificates page. No matter how long i wait, it just doesn't show up. Not sure if this is normal. I tried multiple times already.
02-21-2023 06:36 AM
You wouldn't see it under the certificate authority section, depending on which certs you will regenerate, you would see the new generated certs under the trusted and system certs sections.
02-22-2023 11:48 PM
If i regenerate the ISE Root CA certificate first as explained here... is it confirmed that it doesn't have any whatsoever impact?
https://www.adamhollifield.com/2022/09/fix-cisco-ise-messaging-service.html
02-21-2023 06:11 AM
Hello. Thanks for the reply. As i stated that i tried to regenerate the CSR for this service but it didn't help. What is the impact of disabling (Use ISE Messaging Service for UDP Syslogs delivery to MnT)? And if this is disabled, should it fix it?
Also, i see Radius Live Logs already. This service is not running on the secondary node. It is already running on the primary node.
What is the impact of this service not running?
02-21-2023 06:17 AM
From the 2.6 Release Notes:
Syslog over ISE MessagingFrom Cisco ISE, Release 2.6, Monitoring and Troubleshooting (MnT) WAN Survivability is available for UDP syslog collection. Syslogs are recorded using ISE Messaging Service. The Remote Logging Targets, where the syslogs are collected and stored uses port TCP 8671 and the Secure Advanced Message Queuing Protocols (AMQPs) for sending syslogs to MnT.
By default, the ISE Messaging Service option is disabled until Cisco ISE, Release 2.6 Patch 1.
From Cisco ISE, Release 2.6 Patch 2 onwards, by default, the ISE Messaging Service option is enabled.
For more information, see the Cisco Identity Services Engine Administrator Guide, Release 2.6
Business Outcome: Operational data will be retained for a finite duration even when the MnT node is unreachable.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide