<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic One thing to keep in mind in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977690#M24502</link>
    <description>&lt;P&gt;One thing to keep in mind here is that the maximum round trip delay between the nodes has to be &amp;lt; 300 ms. Anything over that will not be supported by Cisco TAC and you might encounter database replication issues. If the delay is &amp;gt; 300 ms then you will need to deploy two separate instances of ISE that are not replicating to each other.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2017 18:16:43 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2017-01-11T18:16:43Z</dc:date>
    <item>
      <title>ISE redundancy/failover over distributed environment at different geographically locations.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977687#M24495</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
&lt;SCRIPT src="https://dpm.demdex.net/id?d_visid_ver=1.5.6&amp;amp;d_rtbd=json&amp;amp;d_ver=2&amp;amp;d_orgid=B8D07FF4520E94C10A490D4C%40AdobeOrg&amp;amp;d_nsid=0&amp;amp;d_mid=59422263365916656242409819833846430863&amp;amp;d_blob=NRX38WO0n5BH8Th-nqAG_A&amp;amp;d_cb=s_c_il%5B2%5D._setMarketingCloudFields" type="text/javascript" async="async"&gt;&lt;/SCRIPT&gt;
&lt;/P&gt;
&lt;SECTION class="clearfix" id="j-main"&gt;
&lt;DIV class="clearfix" id="jive-body"&gt;
&lt;DIV class="j-layout j-layout-ls clearfix"&gt;
&lt;DIV class="j-column-wrap-l"&gt;
&lt;DIV class="j-column j-column-l lg-margin"&gt;
&lt;DIV class="jive-thread-messages" id="jive-thread-messages-container" role="main"&gt;
&lt;DIV class="jive-content j-op j-rc4 " role="article"&gt;
&lt;DIV class="j-thread-post j-rc4 "&gt;
&lt;SECTION class="j-original-message"&gt;
&lt;DIV class="jive-rendered-content"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a use case where i need to configure ISE at two different geographical locations: &amp;nbsp;HO (India) and BO (USA).&lt;/P&gt;
&lt;P&gt;Requirement is, if the ISE server fails at US Branch, all the endpoints must automatically fail-over to HO (India) and the endpoints in US must be 802.1x authenticated and the authorization policy to be given by HO ISE server. However, to achieve this i don't see secondary ISE point configuration is Switch.&lt;/P&gt;
&lt;P&gt;ISE configuration(Standalone deployment), Integration with NAD and AD, dot1x etc, is much familiar to me. But, internet documents are not helping much in this requirement.&lt;/P&gt;
&lt;P&gt;Can someone give much clarity to achieve the fail-over part for this use case pls?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Sagar&lt;/P&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977687#M24495</guid>
      <dc:creator>prado1985</dc:creator>
      <dc:date>2019-03-11T07:20:51Z</dc:date>
    </item>
    <item>
      <title>If both nodes are acting as</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977688#M24498</link>
      <description>&lt;P&gt;If both nodes are acting as Policy Nodes (PSN), you can have both as Radius servers in a aaa server group. The second radius server in the group acts as backup in case first one is not reachable. Example to configure that on a switch is here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_rad/configuration/xe-3se/5700/sec-usr-rad-xe-3se-5700-book/sec-rad-aaa-server-groups.html#GUID-5B656046-CF52-4B95-8292-71EC081FD041&lt;/P&gt;
&lt;P&gt;As seen in the example above, you would then call your AAA group in the "aaa authentication" and "aaa authorization" commands.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 17:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977688#M24498</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-01-10T17:03:56Z</dc:date>
    </item>
    <item>
      <title>Hi Rahul,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977689#M24499</link>
      <description>&lt;P&gt;Hi Rahul,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your valuable response. I'll implement as per the reference example and revert with the result.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks again,&lt;/P&gt;
&lt;P&gt;Pradeep&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 12:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977689#M24499</guid>
      <dc:creator>prado1985</dc:creator>
      <dc:date>2017-01-11T12:33:27Z</dc:date>
    </item>
    <item>
      <title>One thing to keep in mind</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977690#M24502</link>
      <description>&lt;P&gt;One thing to keep in mind here is that the maximum round trip delay between the nodes has to be &amp;lt; 300 ms. Anything over that will not be supported by Cisco TAC and you might encounter database replication issues. If the delay is &amp;gt; 300 ms then you will need to deploy two separate instances of ISE that are not replicating to each other.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 18:16:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redundancy-failover-over-distributed-environment-at/m-p/2977690#M24502</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2017-01-11T18:16:43Z</dc:date>
    </item>
  </channel>
</rss>

