<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE failover Questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3761541#M487769</link>
    <description>So when you add the secondary IP address to the AAA server group within the ASA there is no way to test the secondary node because its not responding to requests until its promoted to primary?</description>
    <pubDate>Tue, 11 Dec 2018 20:04:57 GMT</pubDate>
    <dc:creator>Steven Williams</dc:creator>
    <dc:date>2018-12-11T20:04:57Z</dc:date>
    <item>
      <title>ISE failover Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3753022#M487761</link>
      <description>&lt;P&gt;When I have two ISE nodes and they are set to primary and secondary on Admin, Monitoring, and Policy how does failover work with this? do I need to create a PAN failover group and add each one to it and enable failover?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I start adding ISE servers to radius servers do I have to list both IP addresses of the ISE Servers?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 19:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3753022#M487761</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2018-11-26T19:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failover Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3753034#M487764</link>
      <description>&lt;P&gt;It is different for each persona:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Admin- in a two node deployment this is active/passive.&amp;nbsp; If the primary admin fails you would need to go to the GUI of the secondary to promote it to be the primary.&amp;nbsp; At that point the services will restart and authentication would be disrupted.&amp;nbsp; If you have more than two nodes you can configure automatic failover.&lt;/LI&gt;
&lt;LI&gt;Monitoring- always active/active.&amp;nbsp; All ISE nodes log to both monitoring nodes simultaneously. If the primary monitoring node goes down the Admin persona will automatically start pulling data from the other monitoring node.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;PSN- always active and you decide how you use them by how you point your network devices at them.&amp;nbsp; You might say wired will be PSN #1 first then PSN #2 and wireless PSN #2 first then PSN #1.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 26 Nov 2018 20:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3753034#M487764</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-11-26T20:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failover Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3753047#M487766</link>
      <description>&lt;P&gt;Good answer,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll just add that for Admin failover the primary doesn't automatically become the active node once it's up. You'll need to promote the primary node yourself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For MnT persona the primary preempts back to working with the active PAN, so no need to promote anything.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 20:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3753047#M487766</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2018-11-26T20:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failover Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3761541#M487769</link>
      <description>So when you add the secondary IP address to the AAA server group within the ASA there is no way to test the secondary node because its not responding to requests until its promoted to primary?</description>
      <pubDate>Tue, 11 Dec 2018 20:04:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3761541#M487769</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2018-12-11T20:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failover Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3761698#M487770</link>
      <description>&lt;P&gt;Requests are handled by PSN nodes, not PAN or MnT. PSN nodes are always active, so you should be getting a reply from any of the PSN nodes assuming the right persona, protocols and policy&amp;nbsp;are in place.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 05:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failover-questions/m-p/3761698#M487770</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2018-12-12T05:53:20Z</dc:date>
    </item>
  </channel>
</rss>

