<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Removing last PSN from cluster in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3884773#M471717</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;In my lab I had setup and entire dsitributed cluter with one each of the nodes (Primary and secondary PAN, primary and secondary Motioning,&amp;nbsp;and a PSN)&lt;BR /&gt;Now when I tried to remove the primary monitoring node (after removing the secondary monitoring), an error was thrown, stating that there needs to be at least one monitoring node in the cluster.&lt;BR /&gt;But, when I removed the the only PSN from the cluster, there was no such error or warning given?!&lt;BR /&gt;Is this something by design? Or am I doing something wrong?&lt;BR /&gt;It all stems to the lab that I have setup and noticed this, not sure if this by design or if missing out on something?&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2019 13:05:16 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2019-07-04T13:05:16Z</dc:date>
    <item>
      <title>Removing last PSN from cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3884773#M471717</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;In my lab I had setup and entire dsitributed cluter with one each of the nodes (Primary and secondary PAN, primary and secondary Motioning,&amp;nbsp;and a PSN)&lt;BR /&gt;Now when I tried to remove the primary monitoring node (after removing the secondary monitoring), an error was thrown, stating that there needs to be at least one monitoring node in the cluster.&lt;BR /&gt;But, when I removed the the only PSN from the cluster, there was no such error or warning given?!&lt;BR /&gt;Is this something by design? Or am I doing something wrong?&lt;BR /&gt;It all stems to the lab that I have setup and noticed this, not sure if this by design or if missing out on something?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 13:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3884773#M471717</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-07-04T13:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Removing last PSN from cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3884811#M471718</link>
      <description>This is by design. Since PAN/PSNs do not have a logging capability of their own, there needs to be a Monitoring node in the deployment as it is completely off loaded to the MnT Persona and that there can be only 2 monitoring nodes in a deployment. Even if you do not have a PSN, you can use PxGrid services of a node just subscribing and publishing data. I know that this is not a perfect answer but partially explains the need not do so.&lt;BR /&gt;</description>
      <pubDate>Thu, 04 Jul 2019 14:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3884811#M471718</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-04T14:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Removing last PSN from cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3884959#M471719</link>
      <description>Keep in mind that you can run all ISE roles/personas on a single node if you want to do so.  I wouldn't recommend a single node deployment in production, but I regularly use a single node for lab purposes.</description>
      <pubDate>Thu, 04 Jul 2019 20:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3884959#M471719</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-04T20:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Removing last PSN from cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3885054#M471720</link>
      <description>&lt;P&gt;Hi mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason for this is that ISE doesn't have a concept of Primary or Secondary PSN.&lt;/P&gt;&lt;P&gt;It is the NAD that dictates which ISE to go to first as primary or secondary.&lt;/P&gt;&lt;P&gt;If you check on the ISE Deployment, The "Roles" of PRI - primary or SEC - secondary is for (A) - admin or (M) - monitoring.&lt;BR /&gt;You will never see that on PSN Role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Raffy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 04:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3885054#M471720</guid>
      <dc:creator>RaffyLindogan</dc:creator>
      <dc:date>2019-07-05T04:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: Removing last PSN from cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3886064#M471721</link>
      <description>&lt;P&gt;If there are no other PSN in the cluster, then in that scenario, it is possible for the PAN to process the authentication requests?&lt;/P&gt;&lt;P&gt;If the NAD is pointed to the PAN in the cluster?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 08:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3886064#M471721</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-07-08T08:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Removing last PSN from cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3887859#M471722</link>
      <description>&lt;P&gt;Yes, if the admin node(s) enabled with session services.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 16:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3887859#M471722</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-10T16:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Removing last PSN from cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3890864#M471724</link>
      <description>&lt;P&gt;Thank you guys! I think this has resolved my query...&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 08:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/removing-last-psn-from-cluster/m-p/3890864#M471724</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-07-16T08:39:50Z</dc:date>
    </item>
  </channel>
</rss>

