Showing results for 
Search instead for 
Did you mean: 

ISE Nodes both become Primary



We are deploying 2 x 3415 ISE appliances for a customer as a Primary/Secondary admin cluster. We are running Version Everything was going to plan with the deployment and when we manually promoted the Secondary all worked well. We then attempted some testing prior to going into production. We simulated a switch port failure which in effect isolated our Primary ISE. We then promoted our Secondary ISE and resolved the switch issue so we then had both ISE's as Primary Admins. It would be good at this point to simply 'demote' the Secondary back to Secondary but this is not an option. We tried to break the cluster by de-registering the Secondary from the Primary. We then got into a situation where we couldn't fully break the cluster and the end result is that the secondary is showing a 500-Internal error (see attached) and we are unable to browse to the GUI. I suspect I need to re-image the secondary now and re-join it back to the cluster.

Is there anything documented as to how recover a situation when both appliances become Primary? You would think this should be fairly straightforward. Also has anyone come across the 500-Internal error when attempting to Log into the appliance and if so how did you resolve. From CLI all services are running.

Any assistance/guidence would be appreciated,


1 Accepted Solution

Accepted Solutions

I have the same scenario as yours:  ise1 is primary Admin/MNT and ise2 is secondary Admin/MNT.  ise1 ip address is and ise2 is  They are both on the same subnet.

simulate a disaster: shutdown the switchport that ise1 is connected to.

1- manually promote ise to primary Admin/MNT.  After that make a bunch of changes to ise2.

2- bring back ise1.  At this point, both ise1 and ise2 are shown as Primary Admin

3- from the WebUI in ise2, highlight ise and hit the button "sync-up".  That will force ise1 to become Secondary Admin

4- Once everything is sync'ed, log into the ise1 WebUI and manually promote ise1 to be Primary Admin/MNT again.

Does that make sense?

View solution in original post

6 Replies 6

Naresh Ginjupalli
Cisco Employee
Cisco Employee

Do you have any IP restriction enabled ? Seems like node promotion had some issue in this case.

Sent from Cisco Technical Support iPad App