07-15-2017 07:25 AM - edited 03-11-2019 12:51 AM
Hi, Guys
I have accidentally lockout our cisco ISE, I think added wrongly the IP address int the "IP ACCESS" field in the ISE.
"IP Access" list in the Administration > Admin Access > Settings > Access page.
Now I am not able to login via web or CLI. But our ISE is running on a VM so I can still console in.
Now I tried the command "application start safe" but its not working.
Anyone have encounter this issue who can share their knowledge and experience?
Thanks all.
03-23-2021 01:35 PM
Did you ever fix this? I see no one replied (posted 2017, I am replying in 2021).
03-23-2021 02:54 PM
Hi @DMel
if you have a valid backup, please try to:
application reset-config ise
restore <backup> repository <repository> encryption-key plain <key>
Hope this helps !!!
03-23-2021 03:56 PM
Starting the application in safe mode (application start ise safe) should negate the IP Access restrictions until the services are stopped again.
Did you stop the ise services before starting in safe mode (application stop ise)?
Does the Application Server show a Running state (show app status ise)?
If the answers to both questions are Yes and it's still not allowing GUI access, I would suggest calling TAC to investigate further.
03-24-2021 05:12 AM
Yes, this actually was the fix for me.
I found another article in the community that mentioned these steps.
Thanks for the reply!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide