06-20-2023 10:41 PM
Hi Team,
I have a total of 4 ISE nodes on a VM medium size. Previously, it was on 2.3 where we are facing multiple issues. Recently I migrated that server with the fresh installation on version 2.7 patch 9 on a newly created VM host using ISO image. I have installed these nodes one by one in standalone mode, configured the same policies and IP schema, and dismantled the old VM host servers.
Out of 4 nodes, 3 nodes successfully get into the cluster and working fine. One was able to reregister but not getting synced with others.
I tried to de-register, service start-stop, reload, and factory reset, but still, it was not able to sync. The error is de-register the node and register it again.
I have also checked the reachability part and I can able to ping and get the DNS lookup of all other nodes from the affected node.
Please suggest any further troubleshooting if possible.
Solved! Go to Solution.
06-23-2023 12:11 PM
Check things in the following order:
If nothing conclusive found, would suggest reaching out to TAC.
06-20-2023 11:14 PM
- Consider migrating to (more) recent version(s) of ISE : https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html
M.
06-21-2023 09:35 AM
Did you try the "application reset-config ise" on the node that is giving these issues? if so, maybe you can move the primary PAN persona to the secondary PAN and see if that helps. Alternatively, I would try to get TAC engaged.
06-22-2023 08:46 PM
Hi Aref,
The affected node is a PSN that is not able to sync with other nodes. I have already tried "application reset-config ISE" but it didn't work.
The node was able to register within a minute but after that it was not able sync.
06-23-2023 08:09 AM
I would try to move the primary PAN as suggested before, alternatively I think TAC could help. If not, maybe redeploying that node from the scratch would be a fairly quick option.
06-23-2023 12:11 PM
Check things in the following order:
If nothing conclusive found, would suggest reaching out to TAC.
06-23-2023 01:46 PM
Hi Aref, Thank you for the suggestion. I will go for redeploying if any of the troubleshooting not works.
Hi Nancy,
I will check all of the things which you mentioned in your reply and will let you know.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide