cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1816
Views
20
Helpful
10
Replies

Cisco Prime and ISE intergration

ittechk4u1
Level 4
Level 4

Hello Experts,

 

Earlier (Before SSL certificate installation) CPI and ISE was working together but now...I am struggling to get integrate CPI and ISE.

 

ISE version: 2.1.0.474

CPI: 3.5.0.0.55.0

 

Error(s): You must correct the following error(s) before proceeding:

Error: The connection to ISE with IP address "xx.xx.xx.xx" has timed out. Please check the network connectivity and the user account status on the ISE.

 

Thanks

2 Accepted Solutions

Accepted Solutions

Sandeep Choudhary
VIP Alumni
VIP Alumni

Hi,

 

Did you installed the new certificates on both ? if yes then you need to delete the old certificate of ISE from Cisco prime CLI.

 

Regards

Dont forget to rate helpful posts

View solution in original post

check under tofu-certs or trusted certs:

 

check the old certs: ncs certvalidation tofu-certs listcerts

Delete using the command: ncs certvalidation tofu-certs deletecert host IP_PORT

 

Regards

Dont forget to rate helpful posts

View solution in original post

10 Replies 10

Hi

 Considering you actually have connectivity OK,  this probably a Bug. 

 

 

-If I helped you somehow, please, rate it as useful.-

Even i guess so. I will check if i can raise a TAC case ..

pieterh
VIP
VIP

at first check if time-sync and time-zone match.

if this is both self signed certificate  then both need to "know" and trust each others certificate

if it is public certificate, then both bust know and trust the root and intermediate certificate in the chain.

 

Time is correct on both.

 

I installed wildcard CA signed cert on ISE and SSL cert signed by CA on cisoc prime but prime showing error "Mismatched address" as certificate error.

 

I suspect its the issue with TLSV1 handshake.

 

Thanks

Sandeep Choudhary
VIP Alumni
VIP Alumni

Hi,

 

Did you installed the new certificates on both ? if yes then you need to delete the old certificate of ISE from Cisco prime CLI.

 

Regards

Dont forget to rate helpful posts

Let me try it. Thank for suggestion.

can you please tell me how can i do it ? I tried but didn't find a way...

 

Thanks

 

 

check under tofu-certs or trusted certs:

 

check the old certs: ncs certvalidation tofu-certs listcerts

Delete using the command: ncs certvalidation tofu-certs deletecert host IP_PORT

 

Regards

Dont forget to rate helpful posts

Excellent. It worked now after deletion of trusted old certs.

 

Thank a lot. you guys are awesome.

Glad it helped. Thanks for rating.

Review Cisco Networking products for a $25 gift card