cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
26654
Views
36
Helpful
11
Replies

Cisco ISE factory reset

Ricky S
Level 3
Level 3

Good morning,  is there a way to reset the ISE appliance 3595 back where it asks to type "setup" to begin configuration?

1 Accepted Solution

Accepted Solutions

Timothy Abbott
Cisco Employee
Cisco Employee

To do that, you will have to re-image the server.  If you want to reset ISE back to factory defaults with out having to go through the process of assigning an IP address, FQDN, domain, etc.  you can use the below:

 

application reset-config ise

 

Regards,

-Tim

View solution in original post

11 Replies 11

Timothy Abbott
Cisco Employee
Cisco Employee

To do that, you will have to re-image the server.  If you want to reset ISE back to factory defaults with out having to go through the process of assigning an IP address, FQDN, domain, etc.  you can use the below:

 

application reset-config ise

 

Regards,

-Tim

How do you re-image the server?

How do you re-image the server?

once you apply the command

 

 application reset-config ise

 

it will ask you if you want to retain your existing certificates. either yes or no. it will reset your box/applicance to a new fresh install. however, it will keep the existing config forexample the ip address of the ise interface and the ip-default gateway.

 

 

 

 

please do not forget to rate.

Does this clear the license?

Yup.

Hello Team,

 

what if i want to remove ip address as well.

 

Also does factory reset removes ISE Image ??

'application reset-config ise' this command will erase all the policies and identities users on GUI?

Hi @victormanuelsolis ,

 yes, but please take a look at the y/n questions of this command:

ise/admin# application reset-config ise
Initialize your Application configuration to factory defaults? (y/n): y
This node is part of the deployment. It is recommended you first deregister this node from the deployment before resetting the configuration. Proceed with factory reset? (y/n): y
Leaving currently connected AD domains if any...
Please rejoin to AD domains from the administrative GUI
Smart Licensing is Not Enabled. Not possible to Disable.
Retain existing Application server certificates? (y/n): y
Reinitializing local configuration to factory defaults...
M&T Log Collector is disabled
M&T Log Processor is disabled
PassiveID WMI Service is disabled
PassiveID Syslog Service is disabled
PassiveID API Service is disabled
PassiveID Agent Service is disabled
PassiveID Endpoint Service is disabled
PassiveID SPAN Service is disabled
ISE pxGrid processes are disabled
Stopping ISE Application Server...
Certificate Authority Service is disabled
EST Service is disabled
ISE Sxp Engine Service is disabled
Stopping TC-NAC Service ...
Error: No such container: irf-core-engine-runtime
irf-core-engine-runtime is not running
Error: No such container: irf-rabbitmq-runtime
irf-rabbitmq-runtime is not running
Error: No such container: irf-mongo-runtime
irf-mongo-runtime is not running
VA Service is not running
ISE VA Database is not running
Error: No such container: wifisetup-container
wifisetup-container is disabled
Stopping RabbitMQ docker container...
Stopping docker daemon...
Stopping ISE Profiler Database...
ISE Indexing Engine is disabled
M&T Session Database is disabled
Stopping ISE AD Connector...
Stopping ISE Database processes...
Enter the administrator username to create[admin]:
Enter the password for 'admin':
Re-enter the password for 'admin':
Extracting ISE database content...
Starting ISE database processes...
Creating ISE M&T session directory...
Creating ISE VA timesten database...
Performing ISE database priming...
Starting ISE Indexing Engine...
TimeoutStartUSec=20min
TimeoutStopUSec=20min
Cleaning up TC-NAC docker configuration...
...


Hope this helps !!!

Thank you so much Marcelo!

cmhc
Level 1
Level 1

Ok I ran into problem where I forgot to deregister the node before moving the node to a diffrent DC. If you want to re ip the node what you need to do id deregidter the node from Primary eventhough the node is not reachable. do application reset which wil say prime db fail but ok . that will allow you to change ip of the interface. Make sure you retain certificates. After the interfaces are configured and reachable. do reset again.which will make the node clear. after that join the node to deployment.