cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6903
Views
13
Helpful
7
Replies

ISE 3.0 No live logs on install in cluster

JonathanC1
Level 1
Level 1

Hello all, I've setup a new distributed deployment with dedicated PAN, maintenance and policy nodes today. I've got radius & tacacs auth and authorisation working but there are no logs - live logs also in operations menu nothing is appearing. The deployment is all green, and the logging locations look OK. Is there any further troubleshooting anyone can recommend. Or something maybe missed?

Warm Regards J

 

 

 

 

 

7 Replies 7

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @JonathanC1,

I would assume that you are facing issue with ISE Messaging Service. Do you see alarms "Queue Link Error" on initial dashboard?

Also, try deactivating ISE Messaging Service under Administration / System / Logging, and see if your logs are there after this action. If your logs are appearing after this action, then you are indeed hitting an issue with ISE Messaging Service, and see this post in order to resolve it.

BR,

Milos

Hi Milos,

 

Yes we are getting queue link error on the dashboard & have tried to add more ports from FW documentation. This looks like it is thank you will check it out.

 

Thank you

J

Mike.Cifelli
VIP Alumni
VIP Alumni

I have seen this bug in 2.7 versions and most recently with ISE 3.0p5:

Queue Link Bug
---------
The workaround is:
1.- Regenerate ISE Root CA
2.- Regenerate ISE Messaging service Certificate.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr40715

ChuckMcF
Level 1
Level 1

Minor update: This issue still exists in ISE 3.1P5. The solution suggested by @Mike.Cifelli worked perfectly to resolve the issue.

Thanks,

ChuckMcF

kdurai12
Level 1
Level 1

I have the same issue, I have regenerated the ISE messaging certificate for that PSN, but still the issue remains.. 

Question:

If I regenerate the ISE Root CA certificate, will there be any service affected with PSN authentication and Sync between PAN and PSN  ?

Any help ?

ChuckMcF
Level 1
Level 1

It's been well over a year and a few revisions since I did this, so the details are a bit foggy. I don't remember there being any issues, though. Best suggestion would be to set up a call with TAC.