cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

962
Views
0
Helpful
5
Replies
alice.jessie
Beginner

ISE 2.1 TC-NAC with AMP

In ISE 2.1, after the third party vendor account for AMP is created, the connection is established but after a while we see that the account becomes unreachable. I have tried reloading the ISE and redoing the integration but often observe that the connectivity disconnects at times. Has anyone come across this issue?

1 ACCEPTED SOLUTION

Accepted Solutions

Hi Alice,

I just did a fresh connection in my lab to double check if something's wrong with the connectivity in general.

Here are some observations:

1) When you see the blank screen after AMP redirects back to ISE, just click on the browser couple of times, the ISE page will load. And then hit the 'Finish' button.

2) Yes, I did see the status as 'Configured' and 'Disconnected'. But I gave it a few seconds and hit a refresh button and now things are looking good:

Screen Shot 2016-10-14 at 12.40.04 PM.png

View solution in original post

5 REPLIES 5
hariholla
Cisco Employee

Hi Alice, our engineering team claims to have seen this issue internally, when the AMP cloud goes through maintenance. Do let us know if the issue persists with valid configurations in place.

Hi Hariprasad

Thanks for the quick response.

But now, I'm facing a new issue, In Amp configuration I chose AMP:THREAT as a third party vendor so after configuring it will redirect to AMP for authentication and after successful authentication it will redirect to ISE. But all of the sudden I am facing issue in redirection i.e, After authentication in AMP the pages goes blank its not redirecting to ISE… Previously it was working fine for the past 2 weeks and now I am facing this issue. The Third Party Vendor page in ISE constantly shows Connectivity as Disconnected and Status as Configuration Progress. Is this a part of Maintenance too?

Hi Alice,

I just did a fresh connection in my lab to double check if something's wrong with the connectivity in general.

Here are some observations:

1) When you see the blank screen after AMP redirects back to ISE, just click on the browser couple of times, the ISE page will load. And then hit the 'Finish' button.

2) Yes, I did see the status as 'Configured' and 'Disconnected'. But I gave it a few seconds and hit a refresh button and now things are looking good:

Screen Shot 2016-10-14 at 12.40.04 PM.png

Hi Hariprasad

I tried the step that you had suggested, but unlike you, after clicking reload multiple times on the blank screen takes me back to the AMP login screen. Also, which cloud are you using? I'm using the EU cloud.

Mo Pourmirza
Beginner

Hi Alice,

Delete the AMP instance that you configured on ISE. Login to AMP for Endpoint Console and go to Applications which is under Accounts. Click on Deregister on Cisco ISE application. Once it has been registered,  re-add  and configure the AMP instance by following below guide.

Configure ISE 2.1 Threat-Centric NAC (TC-NAC) with AMP and Posture Services - Cisco

I hope it helps.

Mohammad

Create
Recognize Your Peers
Content for Community-Ad

ISE Webinars


Miss a previous ISE webinar?
Never miss one again!

CiscoISE on YouTube