ISE PSN node will not be joining the cluster

Hi all

Has anyone seen a problem where an NHP cannot join the cluster?

We join node of PSN

-Node is saved successfully (current synchronization)

-1 hour later - node replication failure.

-Replication synchronization failed because the secondary database is down

I have a client where admin node and PSN are separated by the firewall.

We let in two directions

Admin <-->PSN

ICMP

HTTPS

1521

Firewall not showing drops.

DNS and NTP are ok.

Current topology is 1 NHP, 1 Admin node.

Works very well in our test lab, but not clients environmnet.

See you soon

Peter.

Thank you for the update we and good work on the search for the solution! You should probably mark it as resolved now

In addition, it is quite rare (at least for me) for nodes of ISE to be separated by firewalls. There are a lot of ports/protocols that must be opened between them is usually more of a pain to manage. In addition, sometimes ports will change too. For example, the fueling port agent has been changed not too long ago...

Thanks for the note!

Tags: Cisco Security

Similar Questions

  • 2602AP will not register with the 5508 controller

    Hello all-

    We have a 5508 controller that manages the HA to about 20 branches - each branch has its own subnet. We have a single branch (subnet) with new 2602 AP who will not register with the controller. All communications to that subnet appear normal and there is no ACL in place between the AP and the controller. The AP is able to resolve the IP address of the controller via DNS and start the registration process, but then timeout. We have installed 2602 AP successfully to other areas of the branch and they fit without any problems - it is a problem only in one branch. I have attached a few debug messages below for a single point of access (it's a production environment, so I analyzed useless info) and also included messages from the console to a different access point (the console AP messages are the same). There are currently 9 AP here and none of them will record this. Any ideas?

    Capwap debug events:

    * spamApTask0: 11 Dec 14:39:32.904: 44:2 b: 03:9 has: Discovery d1:10 request 10.29.9.190:44306

    * spamApTask0: 11 Dec 14:39:32.904: 44:2 b: 03:9 has: d1:10 join priority Processing status = 0, priority 1 of incoming Ap, MaxLrads = 300, joined Aps = 272

    * spamApTask0: 11 Dec 14:39:32.904: 44:2 b: 03:9's: Discovery d1:10 response to 10.29.9.190:44306

    * spamApTask0: 11 Dec 14:39:32.904: 44:2 b: 03:9's: Discovery d1:10 response to 10.29.9.190:44306

    * spamApTask0: 11 Dec 14:39:32.992: 44:2 b: 03:9 has: d1:10 DISCOVERY LWAPP APPLICATION received at 68:ef:bd:8e:48:6f on port "13"

    * spamApTask0: 14:39:32.992 Dec 11: Discovery 44:2 b request: 03:9 has: d1:10 elements in LWAPP of AP supporting CAPWAP

    * spamApTask0: 14:39:42.903 Dec 11: connection of DTLS 44:2 b: 03:9 has: d1:10 not found, creating new connection for 10:29:9:190 (44306) 10:5:13:4 (5246)

    * spamApTask0: 14:57:52.301 Dec 11: DTLS closed connection events receivedserver e8:ba:70:dc:d1:c0 (10:5:13:4 / 5246) client (10:29:9:190 / 44306)

    * spamApTask0: 11 Dec 14:57:52.301: e8:ba:70:dc:d1:c0 no entry there for AP (10:29:9:190 / 44306)

    * spamApTask0: 11 Dec 14:57:52.301: e8:ba:70:dc:d1:c0 entry no. AP exist in the temporary database for 10.29.9.190:44306

    * spamApTask0: 11 Dec 14:57:53.828: 44:2 b: 03:9 has: Discovery d1:10 request 10.29.9.190:44306

    * spamApTask0: 11 Dec 14:57:53.828: 44:2 b: 03:9 has: d1:10 join priority Processing status = 0, priority 1 of incoming Ap, MaxLrads = 300, joined Aps = 272

    * spamApTask0: 11 Dec 14:57:53.828: 44:2 b: 03:9's: Discovery d1:10 response to 10.29.9.190:44306

    * spamApTask0: 11 Dec 14:57:53.828: 44:2 b: 03:9's: Discovery d1:10 response to 10.29.9.190:44306

    * spamApTask0: 11 Dec 14:57:53.916: 44:2 b: 03:9 has: d1:10 DISCOVERY LWAPP APPLICATION received at 68:ef:bd:8e:48:6f on port "13"

    * spamApTask0: 14:57:53.916 Dec 11: Discovery 44:2 b request: 03:9 has: d1:10 elements in LWAPP of AP supporting CAPWAP

    * spamApTask0: 14:58:03.824 Dec 11: connection of DTLS 44:2 b: 03:9 has: d1:10 not found, creating new connection for 10:29:9:190 (44306) 10:5:13:4 (5246)

    Debug Capwap errors:

    * spamApTask0: 11 Dec 15:17:33.715: e8:ba:70:dc:d1:c0 abolition PT 10.29.9.190 which has not been surveyed

    * spamApTask0: 11 Dec 15:17:33.716: e8:ba:70:dc:d1:c0 DTLS connection has been closed

    Debug Capwap Details:

    * spamApTask0: 11 Dec 15:24:29.419: 44:2 b: 03:9 has: d1:10 CAPWAP control received Msg to 10.29.9.190:44306

    * spamApTask0: 11 Dec 15:24:35.542: 44:2 b: 03:9 has: d1:10 CAPWAP control received Msg to 10.29.9.190:44306

    * spamApTask0: 11 Dec 15:24:41.555: 44:2 b: 03:9 has: d1:10 CAPWAP control received Msg to 10.29.9.190:44306

    * spamApTask0: 11 Dec 15:24:49.555: 44:2 b: 03:9 has: d1:10 CAPWAP control received Msg to 10.29.9.190:44306

    * spamApTask0: 11 Dec 15:25:29.420: 44:2 b: 03:9 has: d1:10 CAPWAP control received Msg to 10.29.9.190:44306

    * spamApTask0: 15:25:29.420 Dec 11: connection of DTLS 44:2 b: 03:9's: d1:10 0x1a1703c8 closed by controller

    * spamApTask0: 15:25:29.421 Dec 11: msg closed connection CAPWAP DTLS

    Journal of the Console from the AP:

    Translate "CISCO-CAPWAP - CONTROLLER.ad.pps.k12.va.us"... the domain server (10.29.8.3)

    * 00:00:57.511 Mar 1: % 3-CAPWAP-ERRORLOG: did not get the server DHCP server log settings. [OK]

    * 00:01:10.511 Mar 1: % 3-CAPWAP-ERRORLOG: go join a capwap controller

    * 16:05:56.000 11 dec: % CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.5.13.4 peer_port: 5246

    * 16:06:17.495 11 dec: % CDP_PD-2-POWER_LOW: all disabled radios - NEGOTIATED WS-C3560E-24PD (68bc.0c03.8015)

    * 11 Dec 16:06:28.231: DTLS_CLIENT_ERROR:... /CAPWAP/base_capwap/DTLS/base_capwap_dtls_connection_db.c:2051 retransmission count Max reached!

    Kern of logging mechanism

    ^

    Invalid entry % detected at ' ^' marker.

    emergency logging trap

    ^

    Invalid entry % detected at ' ^' marker.

    Kern of logging mechanism

    ^

    Invalid entry % detected at ' ^' marker.

    emergency logging trap

    ^

    Invalid entry % detected at ' ^' marker.

    * 16:06:55.999 11 dec: % DTLS-5-SEND_ALERT: send FATAL: close notify alert at 10.5.13.4:5246

    * 16:06:55.999 3 dec: % CLIENTERRORLOG-3-LWAPP: LWAPP LED Init: incorrect led State 255

    * 16:07:06.367 11 dec: % 3-CAPWAP-ERRORLOG: go join a capwap controller

    * 16:07:07.000 11 dec: % CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.5.13.4 peer_port: 5246

    * 11 Dec 16:07:39.151: DTLS_CLIENT_ERROR:... /CAPWAP/base_capwap/DTLS/base_capwap_dtls_connection_db.c:2051 retransmission count Max reached!

    Kern of logging mechanism

    ^

    Invalid entry % detected at ' ^' marker.

    emergency logging trap

    ^

    Invalid entry % detected at ' ^' marker.

    Kern of logging mechanism

    ^

    Invalid entry % detected at ' ^' marker.

    emergency logging trap

    ^

    Invalid entry % detected at ' ^' marker.

    * 16:08:06.999 11 dec: % DTLS-5-SEND_ALERT: send FATAL: close notify alert at 10.5.13.4:5246

    * 16:08:06.999 11 dec: % CLIENTERRORLOG-3-LWAPP: LWAPP LED Init: incorrect led State 255

    * 16:08:17.367 11 dec: % 3-CAPWAP-ERRORLOG: go join a capwap controller

    * 16:08:17.000 11 dec: % CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.5.13.4 peer_port: 5246

    *Dec 17 15:53:47.463: %CAPWAP-3-ERRORLOG: Selected MWAR 'IRC-WLC-5508'(index 0).

    *Dec 17 15:53:47.463: %CAPWAP-3-ERRORLOG: Go join a capwap controller

    *Dec 17 15:53:47.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.5.13.4 peer_port: 5246

    *Dec 17 15:54:23.131: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_connection_db.c:2051 Max retransmission count reached!

    Get much better.

    WAP has selected the 5508 with good firmware.  WAP sends a JOIN request to 10.5.13.4 but cannot recover anything.

    Firewall?  Routing loop?

    What so-called "remote site", how is it connected to your office?  Dark fiber?  INTERNET SERVICE PROVIDER?

    You know what?  Can you post the output in the following commands:

    1 WAP: sh of stocks;

    2 WLC: sh sysinfo

    Nuts, I should already posed for these info before.

  • Tree nodes will not collapse.

    I have a tree that shows what to expect, but will not collapse the subnodes.

    The root is a customer number.
    Below that is the lines of products that the customer has purchased.
    The product lines here are the items in these product lines. These are the nodes.

    The node root, customer number will be very well expand/collapse.
    Product line nodes will not collapse. When the root node is expanded product line nodes appear expanded, but they will not collapse.

    The maximum levels is equal to 3. When I set the Max levels to 2 then the prod line nodes are reduced, but they don't develop.

    I see the tree at the http://htmldb.oracle.com/pls/otn/f?p=33642:12 factory where I expect mine to work.

    Any ideas on how to get my nodes collapse?

    Thank you
    Gregory

    Hi Gregory,

    I discovered the reason for the problem. It's the + symbols in your credentials. When adding in a URL, they are dealt with, in many cases, as spaces (the same that if you put a + between the two words in a search engine). So when you click the collapse icon, the used value ends in a space rather than a + and, as it does not match any ID on your table, no collapse does actually take place.

    I created a second page: http://htmldb.oracle.com/pls/otn/f?p=55041:4

    This includes SQL according to the definition of the tree:

    select REPLACE(ID, '+', '_') id,
           REPLACE(PID, '+', '_') pid,
           NAME name,
           null link,
           null a1,
           null a2
    from "#OWNER#"."GREGORY"
    

    Collapse now works because all the +'s were converted to of _

    Andy

  • Webutation extentsion will not appear in the toolbar

    installed webutation extentsion... will not appear in the toolbar...

    I checked the Webutation extension and this extension is broken because it uses a function (quote() to quote a string) that is no longer supported in Firefox.

    This is not a bug in Firefox, but a bug in the extension and thus must be fixed by the creator of the extension.
    You can point the creator of expansion on the subject if you wish.

    I don't know for other extensions, but they can be broken as well and you will need to check the Console browser (Firefox/tools > Web Developer) for the error messages.

  • Why the clip will not play in the window of the observer?

    Hello world. It's me again. So, I just started working on a project, and the clip will not play in the window of the observer. In the timeline panel, I see that there are images to play, but the Viewer is black when I try to play. I have temporary can solve it by leaving FCPX and opening it again, but after a few minutes, the display window stops again, and it's a pain to have to do every time so I can watch a few minutes of film. Just so you guys know, do it mode multi-cam, incase that has an effect on it. Thank you very much!

    You have the options of display Angles show the value? You are in the editor of the Angle or the project timeline?

    Russ

  • iPhone 6 + will not except that the load rope nor any what lightning male. Impossible to recharge the iPhone.

    iPhone 6 + will not except that the load rope nor any what lightning male. Impossible to recharge the iPhone. Male/female connection not relieve tight. Advice\help would be appreciated.

    Try a different cable - preferably a certified one MFI

    If this does not work

    Please take a genius appointment at an Apple Store, or select another authorized service provider.

  • CRNT FF: 1 of 5 emails lost all my messages on viewing but shows the amount of mails are there. Search can find them all, just will not appear in the Inbox

    1 of 5 email ACCOUNTS receive mail OK, but as soon as you leave this account and that you come back, nothing appears in the Inbox. The status bar shows however, that there are 32 emails it even if the Inbox is devoid of any text.

      Using Search, I can find ALL 32 emails by searching for a word in the subject field or the body fields. The mails ARE there!  They just do not display in the Inbox.
    

    Then... How the hell can I get the Inbox to display its content again?

    It worked until the day before yesterday when I read an e-mail from a reliable source and it automatically disappeared, along with all others in the Inbox. All other accounts are working very well.

       I tried creating a new email account but it wouldn't let me, giving me an error that the "incoming already exists".  No number or anything; it come when I click DONE in the creation process.  The new account will not write to the disk.
    

    I ran NOrton, AVG, MalWare Bytes, Windows Defender, Spybot AV and the other that I forgot the name of that time. ALL showed nothing found after each live scan success. I'm reasonable sure, I have no malicious software.

    Emails from this account are quite important, and I don't want to lose them if possible; they are for a Committee planning the 50th high-school reunion.

    Windows 7 HP, Dell XPS L702, 6 Gig of RAM, Intel i7 processor and lots of disk space. I've also compacted without change. The messages are all still there, but nothing shows in my Inbox; It is empty. I only see them using Find Messages from words I know are in them.

      Happy to provide any other info needed to evaluate this.  Oh, the account Sends OK too; it's a POP3 account setup.
    

    Any help would be most appreciated!

    Twayne'

    In main menu, make sure that you have seen (Alt - V) - topics - all.

  • Firefox will not start after the upgrade to 27. Seen an error message during the upgrade process.

    Firefox will not start after the upgrade to 27. Seen an error message during the upgrade process, but do not remember.
    Tried running firefox.exe Pei but error message:

    XML parsing error: the undefined entity
    Location: chrome://mozapps/content/profile/profileSelection.xul
    Line 18, column 1:
    "< dialog < =" "^ =" "p =" "> < / dialogue >

    Running on Windows XP SP3. No problem whatsoever before moving to 27. Sending of Chrome that I can't open Firefox at all.

    Thank you, jschaer2000. In the meantime, he works. How long, we'll see ;-)

  • IPhoto on the external hard drive will not launch despite the force quit and relaunch several times. Can someone help me?

    I have a MacBook from 2008. 4 years ago I moved my iPhoto on an external hard drive. I have thousands if photos on it. IPhoto on the external hard drive will not launch despite the force quit and relaunch several times. Can someone help me?

    < re-titled by host >

    I moved my iPhoto on an external hard drive.

    Did you move the iPhoto library for the external hard drive or the iPhoto application, or both?

    How is formatted the external hard drive? Is the file system on the drive Mac OS extended (journaled) or other system files?  Is the drive directly connected by USB or similar, or is it a SIN?

    IPhoto on the external hard drive will not launch despite the force quit and relaunch several times.

    I don't understand - if you force quit smoking, launches the application, or you can not force it quit?

    IPhoto is suspended without doing anything, when you launch?

    What version of iPhoto does? And what version of Mac OS X?

  • Firefox will not display on the screen even though with Process Explorer, I see active Firefox.exe but no CPU usage

    I use Firefox as default browser v10.0.2 on Dell XPS8300 Intel Core i5 and Windows 7 Ultimate and Compaq Presario CQ57 IO IO Intel Core i3 and Windows 7 Home. More frequently on the (approximately 90% of attempts) that Dell (50% of attempts) Firefox will not display on the screen when I click the icon. Cannot display other programs when it happens. I expressly say display because I believe that Firefox has started. To work around the problem, I installed Process Explorer on both machines and launch this program first, then click on the Firefox icon. When the problem occurs I see process Firefox.exe in the list of processes; some CPU consumed but, then, no CPU activity. If I click on the Firefox icon, yet another process opens in the list of processes, but with the same answer - some consumed CPU and then no CPU activity. If I have 2 processes running and kill the process from the 1st, the 2nd poster and then everything is normal. If I do not open it treat a 2nd, but kill the 1st process then click the Firefox Firefox is displayed and all then is normal. This problem has occurred since the original on the two new machines installation. I have updated the video drivers on both computers.

    OK, let's see if we can solve this problem and make it work for you!

    First of all, if you start Firefox in safe mode (restart your computer first, then when you open Firefox, hold down the SHIFT key) it starts more reliable? This is usually caused by a defective module. If this does not help, then restart Firefox, go to the Firefox, then add-ons button and disable your extensions one by one until you find the troublemaker.

    Also, try to update to Firefox 11, it has several bug fixes that might make life easier here.

    Just as a few troubleshooting steps base to ensure that we have all the bases covered,
    Run all Windows updates, install all required service packs, etc.

    Update all of your plugins (Flash, Java, etc.): http://www.mozilla.org/plugincheck/.

    Download and install MalwareBytes Anti-Malware, run a full scan. http://www.malwarebytes.org/. This check allows that there is no virus on your computer, causing problems. You can uninstall this program after having cleaned the infections.

  • Try to load version 9. Currently on 8. MacBookPro. Doesn't install not and symbol of installer of firefox will not install on the list of Applications?

    Don't know if I'm using the right conditions, but...
    -Firefox 8.0.1 is now on my list of Mac Applications.
    -When I tried to upgrade to version 9, it wouldn't hang out in my applications folder.
    -The symbol of the installer is "stuck" on the desktop and will not transfer into the application folder.
    -Whenever I turned on the computer, I now restart firefox and also get a warning that "this has been downloaded on the internet.
    -L' entire system seems to have slowed

    If he has problems with the update or the permissions then simpler is to download the full version and trash the version currently installed to do a clean install of the new version.

    Download a new copy of the Firefox program and save the file on the desktop disk image (dmg)

    • Trash the present application Firefox to do a clean (re-) install
    • Install the new version you downloaded

    Your profile data is stored in the Firefox profile folder, so you will not lose your bookmarks and other personal data if you uninstall and (re) install Firefox.

  • My Apple Watch will not charge on the charger.  I cleaned the back of the watch and the charger.  Any ideas?

    My Apple Watch will not charge on the charger.  I tried to clean the back of the watch and the charger more used several points of sale, but in vain.  Any ideas?

    Hello

    When you reload your watch, check that:

    • All the plastic film was removed from both ends and both sides of the cable support (consult closely on the head of the charger).

    • On the back of your watch and the head of the charge cable are clean and dry (clean with an abrasive, lint cloth).
    • The head of the load is properly aligned with the back of the watch, with the concave side / curve touch fully:
      • Some docks of watch, brackets, cases or protectors might hinder it.
    • You use a real Apple magnetic Charging Cable or a certified Apple module magnetic charge.
    • If you reload your watch by plugging into a power outlet:
      • Check that the magnetic charge cable Apple USB connector is fully engaged in the USB power adapter.
      • Try to use different maps of the following:
        • The real Apple USB Power Adapter that came with the watch, or;
        • A true 5W Apple (iPhone) or 12W (iPad) USB power adapter, or;
        • A third-party certified 5W (MFi) Apple USB power adapter.
      • Try to charge via a USB port (see following).
    • If loading via a USB port on a computer, make sure that you use a USB 2.0 or 3.0 port, the computer remains turned on and awake, and the cable is plugged directly into the computer (not on, for example, an external keyboard).
    • If your battery is very low, you may need to wait a few minutes for the green lightning appear (confirming that the charge has started).

    Once the load has started, you can tap on the screen at any time to check the progress (leave a few minutes at the beginning, where the watch is in charge of a very low battery level). A green lightning bolt symbol indicates that your watch is being loaded. It is normal the screen back to sleep while continuous load.

    More information:

    Check your battery and load your Apple Watch - Apple Support

  • MY iphone6 will not return from the icloud, HELP?

    I had to replace my phone.  The new phone will not render from the icloud.  I tried several times and I even took it in the Apple store without success.

    Weezy616 wrote:

    I had to replace my phone.  The new phone will not render from the icloud.  I tried several times and I even took it in the Apple store without success.

    Thanks a lot for sharing that you cannot restore icloud.

    Maybe include some details as to what happens when your restore IE. error message?

    Or that said Apple store has been without success...

  • iPad will not restart after the update iOS9.3. Should force us the reboot?

    iPad will not restart after the update iOS9.3. Should force us the reboot?

    By restart do you average will not turn on?

    There seems to be a bit of a problem past, especially with older models of iPad 2. Some people have reported success after that restore their device via iTunes, for others that it has not worked and all they get is a message "bring it in an apple store.

    Since it affects a lot of people, I think it's safe to say that the problem lies in the range of Apple. But I don't think it is recognized or no matter what put forward fix.

    You can try to restore your device, or you may just be stuck waiting to see if a fix comes out.

    http://support.Apple.com/kb/HT1414

  • When I updated my iPhone 6 more iOS 9.3 my camera will not be to the point and seems blurred by far. I already reset my iPhone and my mother worked... Anything other ideas, might be a bug in the iOS update?

    When I updated my iPhone 6 more iOS 9.3 my camera will not be to the point and seems blurred by far. I already reset my iPhone and my mother worked... Anything other ideas, might be a bug in the iOS update?

    I would say "try and do a restore as new iPhone" like everyone else but I'm having a similar problem and nothing works! I've restored all the possible ways and nothing. I got my screen replaced and I still have the same home button but my phone updated with error 53 (makes the phone unusable) but the camera did work before the update. and Apple has released iOS 9.1.2 (13D 20) to correct the error 53 (mainly for other reasons) but when I go to use the camera, it is only black! If someone could help 'discovered' and I would be great!

Maybe you are looking for