cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
252
Views
0
Helpful
7
Replies

HA after re-image

i was have 2 node 

ISE-1 << Prim(PAN) Prim (MNT)

ISE-2 << SEC(PAN) SEC(MNT)

after upgrade some thing happaned to the ISE-1 MNT and after talk with cisco we descided to Re-image the ISE-1

now ISE-2 is standalone 

and ISE-1 standalone with no configuration yet only the licince 

i need to know spefically what i will do to back the ISE-1 to the deployment please i need the step ....

3 Accepted Solutions

Accepted Solutions

Hi @saeedabdelhalimhamada 

 1st Restore your CONFIG and OPER backup to ISE-1.

In Administration > System > Repository ... create your Repository

In Administration > System > Backup & Restore > Select the Repository, choose your Backup and click Restore.

Backup & Restore.png

 

2nd Change the ISE-1 Role from Standalone to Primary

In Administration > System > Deployment > select the Node > click Make Primary:

Make Primary.png

 

3rd Register the ISE-2 to the new Cluster.

In Administration > System > Deployment > click Register and enter the ISE-2 Data:

Register Data.png

 

Note: what is your ISE version & patch

 

Hope this helps !!!

 

View solution in original post

ammahend
VIP Alumni
VIP Alumni
  1. re-image does not update patch, so make sure ISE 1 is on same patch as ISE2
  2. Perform initial setup and install certificates to built trust between ISE 1 and 2
  3. Promote ISE 2 to primary as suggested below
  4. Register ISE 1 in deployment with required roles and wait for Sync.
  5. make sure both nodes and Synced and veryfy AD status as well on ISE1.
  6. make ISE 1 primary again.
  7. take another backup (optional)
-hope this helps-

View solution in original post

Hi @saeedabdelhalimhamada ,

 please take a look at ISE - Queue Link Error.

 

Hope this helps !!!

View solution in original post

7 Replies 7

marce1000
Hall of Fame
Hall of Fame

 

   @saeedabdelhalimhamada wrote : >...and after talk with cisco we decided to Re-image the ISE-1
                                                         You can use your contact with Cisco to ask for the needed steps too , for adding the (a) node to the deployment. The benefit being that you get an authoritative response,

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hi @saeedabdelhalimhamada 

 1st Restore your CONFIG and OPER backup to ISE-1.

In Administration > System > Repository ... create your Repository

In Administration > System > Backup & Restore > Select the Repository, choose your Backup and click Restore.

Backup & Restore.png

 

2nd Change the ISE-1 Role from Standalone to Primary

In Administration > System > Deployment > select the Node > click Make Primary:

Make Primary.png

 

3rd Register the ISE-2 to the new Cluster.

In Administration > System > Deployment > click Register and enter the ISE-2 Data:

Register Data.png

 

Note: what is your ISE version & patch

 

Hope this helps !!!

 

ammahend
VIP Alumni
VIP Alumni
  1. re-image does not update patch, so make sure ISE 1 is on same patch as ISE2
  2. Perform initial setup and install certificates to built trust between ISE 1 and 2
  3. Promote ISE 2 to primary as suggested below
  4. Register ISE 1 in deployment with required roles and wait for Sync.
  5. make sure both nodes and Synced and veryfy AD status as well on ISE1.
  6. make ISE 1 primary again.
  7. take another backup (optional)
-hope this helps-

Thanks @ammahend  @Marcelo Morais  all work done , but i have an iusse , i used certificate from Private CA and install the Root CA to  ISE-1 and ISE-2 and i made  Certificate Signing Requests for Both ise and this certifcate i used it form Admin , Auth etc as i show in the pic , but the massage service each one use selfsigned certifacte  now i have problem with  Queue Link Error  so what is your suggestion to solve this problem ??

saeedabdelhalimhamada_0-1737371195324.png

saeedabdelhalimhamada_1-1737371285626.png

 

 

Hi @saeedabdelhalimhamada ,

 please take a look at ISE - Queue Link Error.

 

Hope this helps !!!

Thanks @Marcelo Morais 

i just rege the ISE ROOT CA and it`s working fine ā™„

Hi @saeedabdelhalimhamada ,

great news !!! I'm glad I could help !!!

 

Note: I hope you enjoyed the article: ISE - Queue Link Error, if you have any suggestion for improvement, just let me know !!!