cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

16282
Views
10
Helpful
6
Replies
gandhi.rifal
Beginner

Synchronizing Cisco ISE and NTP Server

I am currently implementing Cisco ISE in our client.

But having a little problem that Cisco ISE can not synchronize with the NTP Server.

Keep in mind, NTP servers are in AD.

Currently Cisco ISE just synchronize to local.

Cisco ISE implemented on distributed mode, where there are two Cisco ISE installed on VMware (Administration & Monitoring Node Primary & Secondary), and another one is the appliance (Policy Service Node).

As a result of it could not sync NTP Server and the Cisco ISE, Cisco ISE often OUT-OF-SYN.

Is there a solution for this problem?

1 ACCEPTED SOLUTION

Accepted Solutions

Gandhi,

This is a known issue, I was crossed up and didnt read that you are using AD as your NTP server, there have been issues with integrating ISE and ACS with AD as their ntp source, please use another device as the ntp sources, for example a router.

Thanks,

Tarik Admani
*Please rate helpful posts*

View solution in original post

6 REPLIES 6

Do you check the connectivity between ISE and NTP ? Is there any security perimeters like Firewall between both system ?

Thanks,

Pongsatorn M.

Yes, there is no firewall between both system.

I have testing other device (switch) to use that NTP server and work correctly

So the problem not on NTP Server. 

I spent some time troubleshooting this issue before, ISE will try to ping the ntp server before it moves on and tries to synchornize with it. Please allow ICMP if you can so that ISE will connect and sync with the NTP server.

Thanks,

Tarik Admani
*Please rate helpful posts*

No problems with ICMP packet. ISE can ping the NTP server.

Any idea?

Gandhi,

This is a known issue, I was crossed up and didnt read that you are using AD as your NTP server, there have been issues with integrating ISE and ACS with AD as their ntp source, please use another device as the ntp sources, for example a router.

Thanks,

Tarik Admani
*Please rate helpful posts*

Dear Tarik,

I've tried your solution, and the problem is gone.

Thanks for your help. 

Regards,

Gandhi

Create
Recognize Your Peers
Content for Community-Ad

ISE Webinars


Miss a previous ISE webinar?
Never miss one again!

CiscoISE on YouTube