<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trustsec + ISE Down? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3737898#M488686</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What happens to a TrustSec environment when all ISE servers are down?&lt;/P&gt;
&lt;P&gt;Will traffic still be forwarded? When will it stop working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Nov 2018 13:08:59 GMT</pubDate>
    <dc:creator>Ricardo T Duarte</dc:creator>
    <dc:date>2018-11-02T13:08:59Z</dc:date>
    <item>
      <title>Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3737898#M488686</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What happens to a TrustSec environment when all ISE servers are down?&lt;/P&gt;
&lt;P&gt;Will traffic still be forwarded? When will it stop working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 13:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3737898#M488686</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-11-02T13:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3737991#M488693</link>
      <description>&lt;P&gt;The environment data is cached on the NAD so the enforcement should work still.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3737991#M488693</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-02T14:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3737994#M488697</link>
      <description>&lt;P&gt;Hi Hslay,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I remember that cache has a lifetime of typically 24 hours.&lt;/P&gt;
&lt;P&gt;Will traffic stop flowing after the cache expires and ISE is down?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3737994#M488697</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-11-02T14:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738004#M488705</link>
      <description>If you have a whole ise outage aren’t there other things to worry about? AAA not working? They would go into critical auth on wired and wireless dot1x wouldn’t work. &lt;BR /&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738004#M488705</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-02T14:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738007#M488709</link>
      <description>&lt;P&gt;I'm not using ISE for AAA. Another software is classifying the devices and sending the tag info to the NADs.&lt;/P&gt;
&lt;P&gt;I'm just using ISE to manage the TrustSec infrastructure (SGACLs, Matrix, etc), and only have one ISE (Express Bundle) per site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738007#M488709</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-11-02T14:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738016#M488713</link>
      <description>&lt;P&gt;Ricardo, As Hsing pointed out we could increase the timers to weeks/years so that the network devices wont request the new policy though ISE is down.&lt;/P&gt;
&lt;P&gt;Also one more thing is to configure Static SGACLs on the switches. But that would require lot of manual effort. When ISE is unavailable Static SGACLs would be used by the NADs for enforcement. As soon as ISE is up then dynamic SGACL policies from ISE would take the precedence.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738016#M488713</guid>
      <dc:creator>kthumula</dc:creator>
      <dc:date>2018-11-02T14:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738019#M488716</link>
      <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I have a huge cache lifetime, can ISE push new configurations on demand, or will I have to wait for the cache to expire and/or do a manual download at the switch?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738019#M488716</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-11-02T14:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738023#M488718</link>
      <description>&lt;P&gt;It can always push new configuration on demand. That has nothing to do with timers/cache.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3738023#M488718</guid>
      <dc:creator>kthumula</dc:creator>
      <dc:date>2018-11-02T14:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec + ISE Down?</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3821734#M488719</link>
      <description>&lt;P&gt;Is that possible to keep the downloaded SGACL and TrsutSec environment data after ISE down or the policy expire?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because I still want to keep the SGACL enforcement function working, even though there is no new user can be authentication, after the Cisco ISE down or the policy expires.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 03:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ise-down/m-p/3821734#M488719</guid>
      <dc:creator>JackHsu</dc:creator>
      <dc:date>2019-03-19T03:30:13Z</dc:date>
    </item>
  </channel>
</rss>

