<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Policy Node deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039791#M23835</link>
    <description>&lt;P&gt;We are building a new site in a test lab in one of our current buildings.&lt;BR /&gt;The test lab is able to access most of the rest of the network (some remote sites are not accessible).&lt;/P&gt;
&lt;P&gt;I want to configure an ISE policy node in this site I don't think this will cause an issue but I wanted to check first so...&lt;/P&gt;
&lt;P&gt;1st question&lt;BR /&gt;If I join this unit to the&amp;nbsp;ISE deployment &amp;nbsp;it will be able to see the admin and monitoring nodes but not some of the remote policy nodes- would this cause a problem for it?&lt;/P&gt;
&lt;P&gt;2nd question&lt;BR /&gt;The bigger problem might be with the AD integration does the policy node talk to the DCs or is that all handled via the Admin nodes&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Giles Cooper&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:29:03 GMT</pubDate>
    <dc:creator>bgl-group</dc:creator>
    <dc:date>2019-03-11T07:29:03Z</dc:date>
    <item>
      <title>ISE Policy Node deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039791#M23835</link>
      <description>&lt;P&gt;We are building a new site in a test lab in one of our current buildings.&lt;BR /&gt;The test lab is able to access most of the rest of the network (some remote sites are not accessible).&lt;/P&gt;
&lt;P&gt;I want to configure an ISE policy node in this site I don't think this will cause an issue but I wanted to check first so...&lt;/P&gt;
&lt;P&gt;1st question&lt;BR /&gt;If I join this unit to the&amp;nbsp;ISE deployment &amp;nbsp;it will be able to see the admin and monitoring nodes but not some of the remote policy nodes- would this cause a problem for it?&lt;/P&gt;
&lt;P&gt;2nd question&lt;BR /&gt;The bigger problem might be with the AD integration does the policy node talk to the DCs or is that all handled via the Admin nodes&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Giles Cooper&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039791#M23835</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2019-03-11T07:29:03Z</dc:date>
    </item>
    <item>
      <title>1) PSN's talk to each other</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039792#M23838</link>
      <description>&lt;P&gt;1) PSN's talk to each other when they are part of a node group. If they are not, they do not need to communicate with each other as far as I can remember.&lt;/P&gt;
&lt;P&gt;2) PSN's do talk to the AD, so this communication needs to be there:&lt;/P&gt;
&lt;P&gt;The entire port and communication reference for all nodes is available here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/installation_guide/b_ise_InstallationGuide20/Cisco_SNS_3400_Series_Appliance_Ports_Reference.html&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 13:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039792#M23838</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-22T13:11:46Z</dc:date>
    </item>
    <item>
      <title>Thanks for that.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039793#M23840</link>
      <description>&lt;P&gt;Thanks for that.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So if a PSN can see all of the DCs apart from two if it doesn't get a response then will it try another one?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If it is a bit slower then I don't really mind as it will be a temporary fix.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 13:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039793#M23840</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2017-02-22T13:56:33Z</dc:date>
    </item>
    <item>
      <title>Yes, it will failover to</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039794#M23842</link>
      <description>&lt;P&gt;Yes, it will failover to another DC if it is not able to talk to its assigned one. I believe when you set up AD integration, it automatically assigns a DC from the domain based on the initial response, so the new PSN should talk to the DC it can reach (and closest to) only.&lt;/P&gt;
&lt;P&gt;More info on that here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_20.pdf&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 14:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039794#M23842</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-22T14:36:21Z</dc:date>
    </item>
    <item>
      <title>Thanks very much for your</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039795#M23843</link>
      <description>&lt;P&gt;Thanks very much for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Giles&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 14:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-node-deployment/m-p/3039795#M23843</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2017-02-22T14:39:38Z</dc:date>
    </item>
  </channel>
</rss>

