<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE distributed deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754119#M487693</link>
    <description>Answer to your first question, Yes, you can have two ISE nodes in different subnets and locations as long as you allow the ports mentioned here between the nodes &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_0110.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_0110.html&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;Answer to your second question, Yes, certificates are mandatory as the registration happens over secure HTTP tunnel. &lt;BR /&gt;&lt;BR /&gt;For the third question,&lt;BR /&gt;Recommend you to follow this &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.pdf&lt;/A&gt;</description>
    <pubDate>Wed, 28 Nov 2018 07:32:45 GMT</pubDate>
    <dc:creator>Surendra</dc:creator>
    <dc:date>2018-11-28T07:32:45Z</dc:date>
    <item>
      <title>Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754059#M487692</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have two ISE in different subnet and location.Can we make it as single cluster?&lt;/P&gt;
&lt;P&gt;Is it certificate mandatory ?&lt;/P&gt;
&lt;P&gt;What are the prequation needs to be taken care?&lt;/P&gt;
&lt;P&gt;Can any one help me&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Debu&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 04:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754059#M487692</guid>
      <dc:creator>Debabrata Majhi</dc:creator>
      <dc:date>2018-11-28T04:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754119#M487693</link>
      <description>Answer to your first question, Yes, you can have two ISE nodes in different subnets and locations as long as you allow the ports mentioned here between the nodes &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_0110.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_0110.html&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;Answer to your second question, Yes, certificates are mandatory as the registration happens over secure HTTP tunnel. &lt;BR /&gt;&lt;BR /&gt;For the third question,&lt;BR /&gt;Recommend you to follow this &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.pdf&lt;/A&gt;</description>
      <pubDate>Wed, 28 Nov 2018 07:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754119#M487693</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-11-28T07:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754292#M487695</link>
      <description>&lt;P&gt;Hi Surendra&lt;/P&gt;
&lt;P&gt;Thanks for your prompt response.&lt;/P&gt;
&lt;P&gt;Apricate your help&lt;/P&gt;
&lt;P&gt;Hi Surendra&lt;/P&gt;
&lt;P&gt;Thanks for your prompt response.&lt;/P&gt;
&lt;P&gt;Appreciate your help. Just to understand&lt;/P&gt;
&lt;P&gt;If there is any existing ISE cluster already running, can we move one node from existing ISE cluster for new location, is it possible?&lt;/P&gt;
&lt;P&gt;Is there any licensing issue ? If I change the IP address&lt;/P&gt;
&lt;P&gt;If possible What Shall we do&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Unregister the server from existing cluster&lt;/LI&gt;
&lt;LI&gt;Change the ISE IP according to new location&lt;/LI&gt;
&lt;LI&gt;Again join the node in cluster&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Am I right? Or please guide me proper steps&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 12:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754292#M487695</guid>
      <dc:creator>Debabrata Majhi</dc:creator>
      <dc:date>2018-11-28T12:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754301#M487697</link>
      <description>You can do that as long as you have connectivity. No additional licenses are required.&lt;BR /&gt;</description>
      <pubDate>Wed, 28 Nov 2018 12:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754301#M487697</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-11-28T12:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754321#M487699</link>
      <description>&lt;P&gt;Hi Surendra&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In that case ,I have to follow the following steps right?&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Unregister the&amp;nbsp;Node from existing cluster&lt;/LI&gt;
&lt;LI&gt;Change the ISE IP according to new location&lt;/LI&gt;
&lt;LI&gt;Again join the node in cluster&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 12:51:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3754321#M487699</guid>
      <dc:creator>Debabrata Majhi</dc:creator>
      <dc:date>2018-11-28T12:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757486#M487701</link>
      <description>&lt;P&gt;Hello Surenda&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any Delay which needs to be match ,If the server is defferent location/Subnet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Debu&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 13:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757486#M487701</guid>
      <dc:creator>Debabrata Majhi</dc:creator>
      <dc:date>2018-12-04T13:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757494#M487703</link>
      <description>200ms is the tolerance.&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Dec 2018 13:41:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757494#M487703</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-12-04T13:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757520#M487705</link>
      <description>please see &lt;A href="https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148#toc-hId-798633198" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148#toc-hId-798633198&lt;/A&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:28:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757520#M487705</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-04T14:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757737#M487706</link>
      <description>&lt;P&gt;200 ms was the old guidance. In 2.1 and later it was change and to 300 ms.&amp;nbsp; Of course there are other factors other than latency.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 19:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3757737#M487706</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-12-04T19:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3758052#M487707</link>
      <description>&lt;P&gt;Thanks Paul and all for make it sence ,&lt;/P&gt;
&lt;P&gt;Paul,Can your please let me know some example of "other factors" which needs to be consider.Which will help us to design the cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 08:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3758052#M487707</guid>
      <dc:creator>Debabrata Majhi</dc:creator>
      <dc:date>2018-12-05T08:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3758211#M487708</link>
      <description>Have you reviewed scale and high availability or ise tips tricks&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944#toc-hId-1281981443" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944#toc-hId-1281981443&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Dec 2018 13:09:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-distributed-deployment/m-p/3758211#M487708</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-05T13:09:31Z</dc:date>
    </item>
  </channel>
</rss>

