cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

2690
Views
0
Helpful
8
Replies
Highlighted
Beginner

Secondary ISE cannot join the primary node with error message

Hi,

I have just installed the secondary ISE and did the followings, but when I try to join the primary node, I received the Cannot authenticate the primary ISE, please check the server or certificate and try again.

- promote the secondary from standalone to primary

- export self cert from the seconary

- import the cert to the primary

- try to add not on the secondary used both IP and host name with super admin user

One thing I have noticed that the instruction on the ISE 1.1.1 import cert on primary section mentioned:

  1. Choose Administration > System > Certificates.
  2. From the Certificate Operations navigation pane on the left, click Certificate Authority Certificates.

but the Certificat Authority Certificates does not exist on the left pane. I choosed Certificate store instead

ise.png

any suggestions?

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted

Hi,

Did you set the secondary node to primary? You may have tried to register the node in the wrong direction. For a node to register with the primary node, the registration request must be initiated from the primary node.

Thanks,

Tarik Admani
*Please rate helpful posts*

View solution in original post

8 REPLIES 8
Highlighted
Enthusiast

I've seen that order to be different on the cert guide aswell.

Make sure that the admin password matches

Highlighted

Yes. Admin password is match. I have also tested to using a different super admin user created on both system. none of them working

Highlighted

do you have both certs on the primary node as of right now?

if you go to

Administration > System > Certificates

choose Certificate Store

what do you see there?

.

Highlighted

Yes. I have two certs there, one is local/primary the other one is imported from the secondary

Highlighted

I'm sorry, you do or don't see two certs there?

Highlighted

I tried to add the cert from primary and imported it into the secondary. Run add note again, get different error:

Unable to register primary_host. Node is not a Standalone node.

Highlighted

Hi,

Did you set the secondary node to primary? You may have tried to register the node in the wrong direction. For a node to register with the primary node, the registration request must be initiated from the primary node.

Thanks,

Tarik Admani
*Please rate helpful posts*

View solution in original post

Highlighted

Thanks,  Tarik:  that's It.

Content for Community-Ad