09-30-2023 01:43 AM
Hi Guys, I am a bit puzzled about this. I have implemented 2 ISE nodes in Simple Two Node Deployment. Each node holds all personas. If I split it up, Ise03 holds, Admin and MnT, and Ise02 holds PSN personas, It still works, and clients gets AuthZ. NAD tacacs+ also works, however the live logs are empty?
Any ideas?
Both servers has certifcate from MS AD, NTP are in sync, and DNS records are in place.
Regards Kasper
Solved! Go to Solution.
09-30-2023 10:08 AM
Hi, So I've disabled the "Use "ISE Messaging Service" for UDP Syslogs delivery to MnT" and then I have livelogs again. Then I reissued certificates for ISE Messaging Service on both node, but using the pxgrid template(it has both server and client). Reenabled the ISE Messaging Service" for UDP Syslogs delivery to MnT, and now it works.
09-30-2023 02:16 AM
what version of ISE - I am bit confused here, you mentioned 2 Node deployment, do you have 3rd node admin and Mnt ?
The Live Logs you looking hope Operations > TACACS > Live Logs
what switch model ? (may be run some debug and check is the logs shipping to ISE)
09-30-2023 06:09 AM - edited 09-30-2023 06:12 AM
Hi @balaji.bandi First it's a test lab that I have running. The deployment was as described ISE02, and ISE03, holding all personas, PSN, MnT and Admin. Everythin works, Radius, and Tacacs, and there are logs in both Operation->live logs, and operations->tacacs->livelogs. and ofcause my policy sets get hits. Then I split deployment up, and ISE03 now only has admin and MnT, and ISE02 now only has PSN. Everything works like before. Clients get dot1x authZ and there are hits in the policies, Tacacs works, however now there are no logs in any of the live logs.
ISE 3.1.0.518 patch 7
Switch is a WS-C3650-48PD
Br. Kasper
09-30-2023 10:08 AM
Hi, So I've disabled the "Use "ISE Messaging Service" for UDP Syslogs delivery to MnT" and then I have livelogs again. Then I reissued certificates for ISE Messaging Service on both node, but using the pxgrid template(it has both server and client). Reenabled the ISE Messaging Service" for UDP Syslogs delivery to MnT, and now it works.
09-30-2023 11:02 AM
glad to know all working, cheers for sharing your solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide