cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1219
Views
0
Helpful
5
Replies

ISE 2.1 TC-NAC with AMP

alice.jessie
Level 1
Level 1

In ISE 2.1, after the third party vendor account for AMP is created, the connection is established but after a while we see that the account becomes unreachable. I have tried reloading the ISE and redoing the integration but often observe that the connectivity disconnects at times. Has anyone come across this issue?

1 Accepted Solution

Accepted Solutions

Hi Alice,

I just did a fresh connection in my lab to double check if something's wrong with the connectivity in general.

Here are some observations:

1) When you see the blank screen after AMP redirects back to ISE, just click on the browser couple of times, the ISE page will load. And then hit the 'Finish' button.

2) Yes, I did see the status as 'Configured' and 'Disconnected'. But I gave it a few seconds and hit a refresh button and now things are looking good:

Screen Shot 2016-10-14 at 12.40.04 PM.png

View solution in original post

5 Replies 5

hariholla
Cisco Employee
Cisco Employee

Hi Alice, our engineering team claims to have seen this issue internally, when the AMP cloud goes through maintenance. Do let us know if the issue persists with valid configurations in place.

Hi Hariprasad

Thanks for the quick response.

But now, I'm facing a new issue, In Amp configuration I chose AMP:THREAT as a third party vendor so after configuring it will redirect to AMP for authentication and after successful authentication it will redirect to ISE. But all of the sudden I am facing issue in redirection i.e, After authentication in AMP the pages goes blank its not redirecting to ISE… Previously it was working fine for the past 2 weeks and now I am facing this issue. The Third Party Vendor page in ISE constantly shows Connectivity as Disconnected and Status as Configuration Progress. Is this a part of Maintenance too?

Hi Alice,

I just did a fresh connection in my lab to double check if something's wrong with the connectivity in general.

Here are some observations:

1) When you see the blank screen after AMP redirects back to ISE, just click on the browser couple of times, the ISE page will load. And then hit the 'Finish' button.

2) Yes, I did see the status as 'Configured' and 'Disconnected'. But I gave it a few seconds and hit a refresh button and now things are looking good:

Screen Shot 2016-10-14 at 12.40.04 PM.png

Hi Hariprasad

I tried the step that you had suggested, but unlike you, after clicking reload multiple times on the blank screen takes me back to the AMP login screen. Also, which cloud are you using? I'm using the EU cloud.

Mo Pourmirza
Level 1
Level 1

Hi Alice,

Delete the AMP instance that you configured on ISE. Login to AMP for Endpoint Console and go to Applications which is under Accounts. Click on Deregister on Cisco ISE application. Once it has been registered,  re-add  and configure the AMP instance by following below guide.

Configure ISE 2.1 Threat-Centric NAC (TC-NAC) with AMP and Posture Services - Cisco

I hope it helps.

Mohammad

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: