09-12-2018 07:46 PM
Hi ISE Expert:
Now,I am deploying two ISE in HA mode,I have set one ISE as the primary,and another ISE as the standalone.
I have config the same DNS server and NTP server on these ISE,the software version is also same.
ISE version:2.3.0.298
When i hit the "Register" button to registing a standalone ISE,it seems normal,and i can see the Secondary role on Secondary ISE.Then,i check the "Administration>Deployment" ,the Secondary ISE always in progress status,and after about 4 hours,it will failed,and have these info:
"Sync Node Registration or Sync failed.Please deregister and register the Status:node again"
I have tried to exchange two ISE role,also have rebooted two ISE several times.But,they're not helpful.
two ISEs connect to a Cisco switch,and i can display two ISEs by "show cdp nei".
So,i don't know that's why.Could you help me to analysis it?
Thanks a lot!
Solved! Go to Solution.
09-12-2018 08:38 PM
Make sure both of the ISE nodes can talk to each other using DNS names. Make sure to use FQDN for DNS name and both forward and reverse DNS lookup works.
Here is an admin guide that talks about multinode deployment.
-Krishnan
09-12-2018 08:39 PM
09-12-2018 09:35 PM
09-12-2018 08:38 PM
Make sure both of the ISE nodes can talk to each other using DNS names. Make sure to use FQDN for DNS name and both forward and reverse DNS lookup works.
Here is an admin guide that talks about multinode deployment.
-Krishnan
09-12-2018 09:14 PM
09-12-2018 08:39 PM
09-12-2018 09:16 PM
09-12-2018 09:35 PM
09-12-2018 10:07 PM
09-12-2018 11:43 PM
09-13-2018 09:16 PM
04-03-2019 02:58 AM
I'm having a similar issue with secondary ISE node. It was registered for some time but has recently lost sync to the primary. I have check NTP, DNS, Reverse DNS and Certificates. i have also tried to reboot, de register/register, reset the m&t database, reset the ise config. All with the same result of no sync after 3 hours. Are there any other options apart from TAC at this stage?
04-03-2019 04:26 AM
Sync works, and then fails after roughly three hours each time? And this is reproducible after rebooting the nodes?
If so, any chance you have a firewall/proxy in the way that is aging out the TCP sessions?
04-03-2019 05:23 AM
Hi Nadav,
No there is no sync. I try to do a manual sync, the process starts and after 3 hours the error message will state Registration or sync has failed. Previously it had stated sync to the PAP had failed, since I have done a deregistration is stating the first error now. There are no firewalls in between.
04-03-2019 06:12 AM
If that's the case then the advice and linked documentation provided in this thread should cover the requirements for registering a node.
Regarding certificates... since you have reinstalled the node then it may have a new certificate (unless you specifically demanded that it keep the old certificate during application reset).
Whilst you did say that you checked certificates, I'd check that under the PAN the old certificates for the same CN don't appear under "Trusted Certificates". If they do, delete the trusted certificates before trying to register the node. Assuming DNS records + FQDN provided in registration + NTP + no older certificates in trust store, the registration should be fine.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide