11-13-2024 08:32 AM
I am unable to join a node to the deployment even though I am able to ping PAN to new node and vice versa? What could be stopping this?
11-13-2024 08:35 AM
@NetworkMonkey101 is DNS setup and working? Can you ping the FQDN?
11-13-2024 08:36 AM
I would check this guide that the ports are open between the nodes for all communication.
11-13-2024 09:11 AM
11-13-2024 10:25 AM
As mentioned check the DNS, can you resolve from node a to node b with the command nslookup nodea.domain.com ? And also from node a to the node b? Finally, I'd highly recommend collecting a packet capture. Use the following documentation, it includes the ports for replication and synchronization:
Replication and Synchronization |
|
11-14-2024 03:48 AM
You seem to have a firewall in between these two ISE nodes. Just make sure please that you have all the required ports opened as mentioned by the others, or you can open up all the ports between these nodes on the firewall if they are in segregated secured segments and then look at the firewall logs to narrow down the policy based on the utilised ports you see on the logs.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide