06-28-2018 03:28 AM - edited 02-21-2020 10:59 AM
Hi
I have two ise does used for device administration, one is primary for both administration and monitoring and the other is secondary for both.
Since both ISE in across two Data centers i have configured Primary ISE as the first authentication server for devices in datacenter 1 and the secondary ise as the first authentication server for devices in datacenter 2.
Now, i am not able to see tacacs/radius live logs from the secondary ISE on the primary.
Any reason on why and do i get it working. For now i live with changing the monitoring role to primary on the secondary ise in case i have to debug an failed auth, which is not a ideal solution on a long run.
any advice ?
06-28-2018 03:35 AM
06-28-2018 03:43 AM
08-25-2021 02:04 AM
I have this problem, too (Version 2.7.0356 / Patch 3).
Did anyone resolve it?
08-25-2021 05:46 AM
What do you have under "Administration --> System ---> Logging"? Under "local log settings", is the box "ISE Messaging Settings" checked? If it is, "uncheck" it. The box is "checked" by default. I think it will solve your issue.
08-25-2021 05:55 AM
@david.tran Thank you very much. This solved the problem.
Does this mean, that "ISE Messaging Service" doesn't work as expected?
Is it a bug?
08-25-2021 06:07 AM
@stephan.ochs: No, it is not a bug. If you have this box check, you will need to setup certificates on all of your nodes for it to work properly. Otherwise, you will have issues like this.
01-05-2022 09:56 AM
Hi,
I have the same problem but running
with the log4j hotfix. The system was upgraded from 2.4 recently, patched and hot fixed. I am not sure when this started to happen, after it was first upgarded, after installing ptch 5 or after the log4j hotfix.
01-05-2022 10:49 AM
@george.chung check the ISE alarm widget on the home page for queue link errors. If you see them, go into the system certificates and generate a new CSR for the the ISE CA. That will replace the internal CA root certificate and its issued certificates and fix the message queuing between nodes. It's actually a mandatory post-upgrade step that is often overlooked.
08-29-2023 08:02 AM
I do not have the option for generating a CSR for my ISE messaging what are my other options?
08-29-2023 08:41 AM
@Nick O why not? Is it not allowed in your environment or you don't know how?
08-29-2023 08:46 AM
the only options I have are the Multi Use, Admin, EAP Authentication, Radius DTLS, Portal, pxGrid, SAML.
08-29-2023 09:23 AM
@Nick O check that the internal CA is enabled first. Administration > System > Certificates > Certificate Authority > Internal CA settings.
Once it is enabled, you should then be able to generate a CSR and select the Usage option "ISE Root CA".
08-29-2023 11:00 AM
I have it enabled already. And I still do not have the ISE Root CA option in the Usage drop down.
08-29-2023 11:42 AM
That's odd. Are you logged in to the Primary PAN as an admin superuser? What version of ISE?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide