<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE via CDP concern switch upgrade in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-via-cdp-concern-switch-upgrade/m-p/3854543#M473200</link>
    <description>Understood,&lt;BR /&gt;I will submit on Monday, surely that got me curious cause I want to make less impact as possible on the operations since we run a global solutions with multiple PSNs&lt;BR /&gt;&lt;BR /&gt;Thanks for your support and time,</description>
    <pubDate>Sun, 12 May 2019 05:21:21 GMT</pubDate>
    <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
    <dc:date>2019-05-12T05:21:21Z</dc:date>
    <item>
      <title>ISE via CDP concern switch upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-via-cdp-concern-switch-upgrade/m-p/3854259#M473193</link>
      <description>&lt;P&gt;Hi, please forgive me if this is not the right forum section, but it brought to me a concern.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have to upgrade the WS-C3650-24PD that is connected to "both ISEs"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I do the show interfaces status, I can see both ports are up according to the description&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE2.PNG" style="width: 693px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/36525iA3DB89D7B3ED5916/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE2.PNG" alt="ISE2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have the following PANs set up,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="switchdiagram.PNG" style="width: 356px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/36524iB0DB77859B1499BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="switchdiagram.PNG" alt="switchdiagram.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but when I do the show cdp nei on the switch, I can only see the primary ISE,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cdp.PNG" style="width: 634px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/36526i01AB709645D163A1/image-size/large?v=v2&amp;amp;px=999" role="button" title="cdp.PNG" alt="cdp.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and when I trace the MAC address from each ISE 1 and ISE 2, I can only see it that it says is connected to the port&amp;nbsp; 5 for the primary ISE but not the secondary ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="connection.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/36527i85CDC2C9C38B77A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="connection.PNG" alt="connection.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So, as I stated, Im planning to make the IOS upgrade of this switch connected to both ISEs, but&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How come I can only see one ISE?&lt;/P&gt;&lt;P&gt;Is there any soft of configuration applied on ISE to make it appear as one cluster? perhaps Im missing that?&lt;/P&gt;&lt;P&gt;Assuming that I go for the IOS upgrade, how can I ensure that the primary will take the &lt;STRONG&gt;primary role&lt;/STRONG&gt; and the secondary the &lt;STRONG&gt;secondary role?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Not sure why I see both interfaces up as you saw above, but cannot identify the port as where it should be connected,&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;is this normal?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;has anyone experienced something like this and have you done it in the past?&lt;/P&gt;&lt;P&gt;what should I take into consideration before upgrading the IOS switch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2019 02:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-via-cdp-concern-switch-upgrade/m-p/3854259#M473193</guid>
      <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
      <dc:date>2019-05-11T02:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE via CDP concern switch upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-via-cdp-concern-switch-upgrade/m-p/3854480#M473196</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;How come I can only see one ISE?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The CDP info from ISE is not always shown correctly and can vary by ISE releases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Is there any soft of configuration applied on ISE to make it appear as one cluster? perhaps Im missing that?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;ISE deployment relies on its jGroup replications but not on CDP. See&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_011.html" target="_blank"&gt;Set Up Cisco ISE in a Distributed Environment&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Assuming that I go for the IOS upgrade, how can I ensure that the primary will take the &lt;STRONG&gt;primary role&lt;/STRONG&gt; and the secondary the &lt;STRONG&gt;secondary role?&lt;/STRONG&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Assuming you asking about how Cisco IOS will treat an ISE PSN as the primary RADIUS and another as the secondary RADIUS server, then it depends on the switch configuration on RADIUS. See&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp;or the older&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-731907.html" target="_blank"&gt;Demystifying RADIUS Server Configurations&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Not sure why I see both interfaces up as you saw above, but cannot identify the port as where it should be connected,&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;is this normal?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;has anyone experienced something like this and have you done it in the past?&lt;/P&gt;
&lt;P&gt;what should I take into consideration before upgrading the IOS switch?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;We do not usually rely on CDP to tell how ISE connecting to a switch. If you would like our team to address your issue, please open a Cisco TAC case with info on your ISE release number and patch level.&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2019 23:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-via-cdp-concern-switch-upgrade/m-p/3854480#M473196</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-05-11T23:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE via CDP concern switch upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-via-cdp-concern-switch-upgrade/m-p/3854543#M473200</link>
      <description>Understood,&lt;BR /&gt;I will submit on Monday, surely that got me curious cause I want to make less impact as possible on the operations since we run a global solutions with multiple PSNs&lt;BR /&gt;&lt;BR /&gt;Thanks for your support and time,</description>
      <pubDate>Sun, 12 May 2019 05:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-via-cdp-concern-switch-upgrade/m-p/3854543#M473200</guid>
      <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
      <dc:date>2019-05-12T05:21:21Z</dc:date>
    </item>
  </channel>
</rss>

