cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1587
Views
0
Helpful
3
Replies

ISE 2.6 replication status not Not Applicable

Hi All

We found issue.When we join HA.Node status on deployment in admin page both Connected but when we show tech-support. We found replication status on primary is not applicable and status on secondary is SYNC COMPLETED.

How to fix it ?

 

ISE2.JPG

 

ISE.JPG

3 Replies 3

Surendra
Cisco Employee
Cisco Employee
That is expected behaviour since PAN does not replicate anything to itself. Hence it is not applicable. It only synchronizes data or replicates the data to the other nodes and hence the SYNC_COMPLETED status.

The real issue is when we configure authorization profile and configure policy in primary. If we make secondary to primary and verify authorization profile and configure policy. authorization profile are missing 

and when we test aaa-server authentication from ASA. primary node success but secondary node deny access. (Use same user and password)  

Then what it really means is that the replication is not working between the nodes. Check the connectivity on TCP port 12001 between the PSN and the PAN. PAN will listen on 12001.