cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6928
Views
5
Helpful
12
Replies

Synchronization failed after ISE register

Hi ISE Expert:

Now,I am deploying two ISE in HA mode,I have set one ISE as the primary,and another ISE as the standalone.
I have config the same DNS server and NTP server on these ISE,the software version is also same.
ISE version:2.3.0.298

When i hit the "Register" button to registing a standalone ISE,it seems normal,and i can see the Secondary role on Secondary ISE.Then,i check the "Administration>Deployment" ,the Secondary ISE always in progress status,and after about 4 hours,it will failed,and have these info:
"Sync Node Registration or Sync failed.Please deregister and register the Status:node again"

I have tried to exchange two ISE role,also have rebooted two ISE several times.But,they're not helpful.

two ISEs connect to a Cisco switch,and i can display two ISEs by "show cdp nei".
So,i don't know that's why.Could you help me to analysis it?
Thanks a lot!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !
3 Accepted Solutions

Accepted Solutions

kthiruve
Cisco Employee
Cisco Employee

Make sure both of the ISE nodes can talk to each other using DNS names. Make sure to use FQDN for DNS name and both forward and reverse DNS lookup works.

Here is an admin guide that talks about multinode deployment.

https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010.pdf

 

-Krishnan

View solution in original post

Francesco Molino
VIP Alumni
VIP Alumni
Hi
Do you have the forward and reverse dns entry for both of them in your dns server? Timezone is correct?
On the second one, have you tried reconfiguring it using application reconfigure cli command over ssh and then try again?

Can you share the ADE.log please? On both ise, over ssh, you can run the show logging system command to view this file.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

View solution in original post

12 Replies 12

kthiruve
Cisco Employee
Cisco Employee

Make sure both of the ISE nodes can talk to each other using DNS names. Make sure to use FQDN for DNS name and both forward and reverse DNS lookup works.

Here is an admin guide that talks about multinode deployment.

https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010.pdf

 

-Krishnan

hi kthiruve

thanks for your reply,i can ping each other ,including by ip address and dns address of two ise.whether i have to do a forward and reverse lookup on dns server?

BR
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

Francesco Molino
VIP Alumni
VIP Alumni
Hi
Do you have the forward and reverse dns entry for both of them in your dns server? Timezone is correct?
On the second one, have you tried reconfiguring it using application reconfigure cli command over ssh and then try again?

Can you share the ADE.log please? On both ise, over ssh, you can run the show logging system command to view this file.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Hi Francesco:

i will collect the info,and do i need do the forward and reverse dns lookup on dns server?but the timezone what i should set?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

Hi Jason;

Whether i should config the reverse dns lookup on DNS server for two ISE device?
Is ther any config example?

Thanks a lot!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

Hello Everyone,

After i config reverse dns lookup on DNS Server,and retry to register,the Secondary will work well,and display "connected" status.thank you very much.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

You're welcome

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

I'm having a similar issue with secondary ISE node. It was registered for some time but has recently lost sync to the primary. I have check NTP, DNS, Reverse DNS and Certificates. i have also tried to reboot, de register/register, reset the m&t database, reset the ise config. All with the same result of no sync after 3 hours. Are there any other options apart from TAC at this stage?

Sync works, and then fails after roughly three hours each time? And this is reproducible after rebooting the nodes? 

 

If so, any chance you have a firewall/proxy in the way that is aging out the TCP sessions?

 

Hi Nadav,

 

No there is no sync. I try to do a manual sync, the process starts and after 3 hours the error message will state Registration or sync has failed. Previously it had stated sync to the PAP had failed, since I have done a deregistration is stating the first error now. There are no firewalls in between.

If that's the case then the advice and linked documentation provided in this thread should cover the requirements for registering a node.

 

Regarding certificates... since you have reinstalled the node then it may have a new certificate (unless you specifically demanded that it keep the old certificate during application reset).

 

Whilst you did say that you checked certificates, I'd check that under the PAN the old certificates for the same CN don't appear under "Trusted Certificates". If they do, delete the trusted certificates before trying to register the node. Assuming DNS records + FQDN provided in registration + NTP + no older certificates in trust store, the registration should be fine.