12-03-2024 06:26 PM
I have a standalone Cisco ISE-PIC virtual machine and as of a few days ago whenever I browse to the web interface (https://isepic_IP_FQDN) I get "ISEPIC_FQDN refused to connect". I have tried the following:
ISEPIC version: 3.2.0.542, patch 5 and 6 installed, running on virtual machine, single ISE-PIC node. Otherwise the ISEPIC seems to be working.
I wonder if the web server is not starting but do not know how to check. I can see from our WSA cli > isedata that it is connected to the ISE-PIC and receiving username-ip mappings, so ISE-PIC seems to otherwise be working.
Anyone have any ideas on what may be causing this, further troubleshooting ideas and if someone can post the output of "show ports" so I can compare that would be helpful.
I have logged TAC case SR698359589 and am waiting for an update.
Thanks
12-04-2024 06:58 AM
Why a single node? What about HA? Did a certificate expire? what is the use-case for ISE-PIC in the first place?
12-04-2024 03:14 PM
I am using ISE-PIC to monitor Active Directory user logins and pass username-to-IP mappings the Cisco WSA. No certificates expired.
12-04-2024 03:39 PM
12-05-2024 04:27 PM
The ISE-PIC VM has 8 CPUs, 16 GB RAM, 400 GB disk (thin provisioned). Snapshots are enabled.
12-05-2024 05:14 PM
12-09-2024 08:03 PM
Thanks ahollifield. I don't understand understand how it can be a resource or snapshot issue. The CPU, RAM and disk utilisation is very low. However I increased CPU to 16 and RAM to 64GB. Utilisation graphs attached. The spikes are during reload after making the changes.
There are no snapshots taken for this VM. Our sys admin told me that to disable snapshots there is a setting that limits the max number of VMs to zero but that will make no difference is we have taken no snapshots anyway. Can you please explain why limiting snapshots to zero will help?
12-09-2024 08:15 PM
12-10-2024 08:22 AM
I totally agree with Adam, snapshots are not supported with ISE.
"If the Snapshot feature is enabled on the VM, it might corrupt the VM configuration. If this issue occurs, you might have to reimage the VM and disable VM snapshot."
12-11-2024 07:45 PM
Thanks guys, that is good information. The ISE-PIC vm (RHEL8, compatibility ESXi 70. U2 and later) is on VMware vCenter 7.0.3T build 24322018.
I have taken a snapshot of the ISE-PIC VM in the past so perhaps that has caused the web interface service to fail. Interesting that the ISE-PIC is still receiving user logon events from the AD agents and passing username-ip mappings to the WSA proxy. The only use case for ISE-PIC in my environment is to detect user logons to Microsoft Active Directory and pass username-IP mappings to Cisco WSA web proxy.
I am planning to restore the vm from a backup when I know the web interface worked then disable snapshots for the vm by setting vm > Options > Advanced > General > Configuration Parameters > snapshot.MaxSnapshots = 0 . Do you think this setting will do the trick?
I the web interface does not come up then I will be build a new ISE-PIC vm.
Cheers
12-12-2024 01:07 AM
Yeah I think that's the way to turn the snapshots off.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide