cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2135
Views
4
Helpful
5
Replies

ISE Node deregistration issue

Community,

I was having some communications issues with one of my ISE nodes in my deployment. I went ahead and deregistered the node from the PAN. The PAN has processed the deregistration and no longer sees the node (a PSN). However, the PSN still believe it is part of the deployment, so its been orphaned in a way. How do I get the PSN back into a standalone state?

These are physical appliances (3755 PAN and 3715 PSN).

Thank you.

1 Accepted Solution

Accepted Solutions

Reset config of the application using CLI.

application reset-config ise

Then re register the node in deployment.

View solution in original post

5 Replies 5

This Topic belongs to Cisco CCIE Security, In this video tutorial I have explained how to generate a CSR and Request CA server for an Identity certificate, how to bind an Identity certificate. Following the certificate part I have explained how to register Two ISE nodes in primary and secondary ...

Reset config of the application using CLI.

application reset-config ise

Then re register the node in deployment.

Thank you. Ill try that and respond momentarily.

When you run the "application reset-config ise" command you can decide if you want to wipe our all the configs (except for the network settings) or if you want to keep the certificates.

Another thing you could do I think would be to change the deregistered PSN persona to administration and then change it back to PSN.

Seems if you try to connect to that PSN via this URL and you use the admin credentials to login then you don't have to use the reset command, I never tried it though:

https://< PSN IP address >/deployment-rpc/deregister-node