07-31-2018 02:57 AM
Hi, first post here and I'm hoping someone can point me in the right direction please.
The circumstances: Our Cisco/network engineer left our company last week and I have been left to deal with everything, my network knowledge = 1 ICND1 course about two months ago!
The issue: We can get to the login page of Cisco ISE however once you click on 'login' we just get a blank page and it never loads (no matter what browser we use). Everything is still functioning correctly in the background although there seemed to be a migration of the VM (the Cisco ISE server is a VM) to another part of the data store, possibly due to corruption but like I say it is still functioning correctly.
I have attached a snapshot of the applications on the server taken via CLI if that helps any.
Any help very much appreciated thanks.
07-31-2018 03:07 AM
Hi
From CLI, have you tried to start the service?
application start ise
Might take several minutes to initialize
check by typing sh application status ise
07-31-2018 03:11 AM
Hi, many thanks for your quick reply. I had run the status command and it is attached on my first post, it looks as if the application is already running?
07-31-2018 03:31 AM
Hi
try to stop the service
application stop ise,
then check the status
then application start ise
07-31-2018 04:05 AM
Thanks for that - I'll hold off on this just for now as I want to pass it via my line manager who is not around but will update as soon as possible.
Thanks again.
07-31-2018 08:14 AM
Why type of Deployment is this? Is it Distributed, You have admin nodes that are separate from the PSNs?
If it is Distributed you can restart services on the Admin node without affecting the PSN.
07-31-2018 08:25 AM
Thanks for your reply Cory, really appreciate it, unfortunately I have no idea what you mean - imagine you're talking to a small child :-) ....
After trying to understand what you mean I believe we only have one admin node and one local network, does that make sense in relation to your question?
Many thanks.
07-31-2018 08:32 AM
Ha! No worries.
It sounds like a standalone deployment, in that case I would error on the side of caution and do the services restart after hours and expect there to be an outage in regards to authentications.
07-31-2018 08:37 AM
Ok will do! We have a support call in for this but have been waiting 2 days for a response (BT not Cisco) so wanted to try and figure it out myself, it looks as if it maybe worth just hanging on.
Very much appreciate your help.
07-31-2018 03:12 PM
The database server should be running (no matter type of node this might be - PAN, MnT or PSN). So an application stop, followed by a start is probably a wise move. To be honest, if you had a VM migration then you won't be worse off by simply reloading the entire server (Linux reboot). It will add 1min to the job but so what. If it's already in such a bad shape then you might as well go the whole hog.
Might be worth doing a config backup if you're able to.
If you have a repository configured, then take a quick snapshot of the box just in case it all goes pear shaped
.
On the CLI perform a
show run | begin repository
and see if one is configured. The assumption here is also that the repo is reachable and that the credentials work. A small leap of faith :)
Here is the CLI syntax to create a backup called "safetynet" on a repository called "backup"
backup safetynet repository backup ise-config encryption-key plain MySecret123
08-01-2018 02:57 AM
Hi Arne, many thanks for that, that's really useful.
Looks like I will have to setup a new repository via CLI (if anyone has the steps to do this via CLI or a link that would be great, can't find anything so far).
Also - do I need to backup any certificates even though we only run base licenses (not even sure if the two are related but thought I would ask).
Thanks.
08-01-2018 03:36 AM
Well nearly got there and then got the attached error, any ideas? Thanks.
08-01-2018 05:51 AM
Hi
Might want to look at http://labminutes.com/, free videos on how to, also some on udemy.com, but have to pay around £10 ish for them.
08-01-2018 06:14 AM
Oh dear. I think you're not on the PAN node. You need to be on the active PAN node. You can only perform backups on the primary PAN.
BTW, if you do a show repository QMUISE do you see the contents of the remote FTP/SFTP? Might be worth as a sanity check. SFTP requires an extra step (crypto .... to exchange public keys between you and remote host). Keep it simple if you can by using FTP :)
08-01-2018 06:27 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide