<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/2-node-ise-deployment-best-practices/m-p/2944789#M38582</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can have a cluster where Primary admin node can act as secondary Mnt and PSN.&lt;/P&gt;
&lt;P&gt;However, load balancing on NAD devices set on the basis of PSN configured first in the list. It is always recommended to have authentication for some devices on one PSN and&amp;nbsp;rest to another PSN as first&amp;nbsp;radius server.&lt;/P&gt;
&lt;P&gt;Make sure ISE should have suppression enabled just to suppress anomalous clients for best practices.&lt;/P&gt;
&lt;P&gt;Under Administration &amp;gt; System &amp;gt; setting &amp;gt; Protocols &amp;gt; radius.&lt;/P&gt;
&lt;P&gt;Let me know if you have any concerns.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2016 22:11:56 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2016-08-26T22:11:56Z</dc:date>
    <item>
      <title>2-Node ISE Deployment - Best Practices?</title>
      <link>https://community.cisco.com/t5/network-access-control/2-node-ise-deployment-best-practices/m-p/2944788#M38581</link>
      <description>&lt;P&gt;We're deploying a 2-node ISE cluster.&lt;BR /&gt;&lt;BR /&gt;In the past we've always done:&lt;BR /&gt;Node1: PAN-Primary, MnTSecondary, PSN&lt;BR /&gt;Node2: PAN-Secondary, MnT-Primary, PSN&lt;BR /&gt;&lt;BR /&gt;In a recent best practice slide deck, it shows using the same node1 for both primary PAN &amp;amp; MnT.&lt;BR /&gt;&lt;BR /&gt;I wonder if that was a typo, or not a typo, but instead a new recommendation, or have I just been doing it the wrong way?&lt;BR /&gt;=======&lt;BR /&gt;&lt;BR /&gt;Also, in a 2-node cluster, which node would you use as the "Primary" RADIUS server for the WLC &amp;amp; switches?&lt;BR /&gt;In the past I've always used whatever's NOT the primary MnT node, because it's busy doing a lot of logging and disk I/O.&lt;BR /&gt;&lt;BR /&gt;However, doesn't the secondary MnT node also do the same logging as well, so it's just as busy?&lt;BR /&gt;So is the answer pretty much: doesn't matter, either node can provide equal amount of AAA service?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2-node-ise-deployment-best-practices/m-p/2944788#M38581</guid>
      <dc:creator>CSCO10662744_2</dc:creator>
      <dc:date>2019-03-11T07:01:30Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/2-node-ise-deployment-best-practices/m-p/2944789#M38582</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can have a cluster where Primary admin node can act as secondary Mnt and PSN.&lt;/P&gt;
&lt;P&gt;However, load balancing on NAD devices set on the basis of PSN configured first in the list. It is always recommended to have authentication for some devices on one PSN and&amp;nbsp;rest to another PSN as first&amp;nbsp;radius server.&lt;/P&gt;
&lt;P&gt;Make sure ISE should have suppression enabled just to suppress anomalous clients for best practices.&lt;/P&gt;
&lt;P&gt;Under Administration &amp;gt; System &amp;gt; setting &amp;gt; Protocols &amp;gt; radius.&lt;/P&gt;
&lt;P&gt;Let me know if you have any concerns.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 22:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2-node-ise-deployment-best-practices/m-p/2944789#M38582</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-08-26T22:11:56Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/2-node-ise-deployment-best-practices/m-p/2944790#M38583</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Let me know if you still have any further concerns.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS: Please rate as correct if it helps!!!!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2016 10:31:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2-node-ise-deployment-best-practices/m-p/2944790#M38583</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-09-02T10:31:39Z</dc:date>
    </item>
  </channel>
</rss>

