<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE deployment in two data centers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544221#M496227</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is hard to say whether you need to dedicate nodes or not since no data provided on size of network.&amp;nbsp; In general, PSNs that are in the same LAN campus would be part of same Node Group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no longer an entity referred to as an Inline Posture node.&amp;nbsp; This was removed many releases ago and the ASA can support Posture for VPN users without it.&amp;nbsp; Traffic does not flow "through" PSNs.&amp;nbsp;&amp;nbsp; PSNs terminate RADIUS and Posture Assessment conversations with NAD and endpoint, respectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE supports L3 separation of PAN and MNT nodes (or PAN+MNT nodes) for geographic redundancy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jul 2018 15:28:34 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-07-12T15:28:34Z</dc:date>
    <item>
      <title>ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544220#M496226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are looking for ISE deployment across two data centers for wired &amp;amp; wireless 802.1x authentication and posture assessment for corporate and VPN users. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Option 1 : &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Data center 1: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1. PAN - Primary&lt;/P&gt;&lt;P&gt;2. MnT - Primary&lt;/P&gt;&lt;P&gt;3. PSN - Primary for DC1&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Data center 2: &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;1. PAN - Secondary&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;2. MnT - Secondary&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;3. PSN - Primary for DC2&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 13.3333px;"&gt;Option 2: &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Data center 1: &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;1. PAN/MnT - Primary&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;2. PSN - Primary for DC1&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Data center 2: &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;1. PAN/MnT - Secondary&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;2.&lt;SPAN style="font-size: 13.3333px;"&gt; PSN - Primary for DC2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you help clarify the below queries?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Can we put two PSNs in a device group(or we need more than two)?&lt;/P&gt;&lt;P&gt;2. Do we need to have dedicated "in-line posture" node for VPN users? Or can we use the PSN nodes itself?&lt;/P&gt;&lt;P&gt;3. In Option2, can we keep the PAN/MnT nodes across data centers or they have to be in the data centers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 14:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544220#M496226</guid>
      <dc:creator>mgr</dc:creator>
      <dc:date>2018-07-12T14:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544221#M496227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is hard to say whether you need to dedicate nodes or not since no data provided on size of network.&amp;nbsp; In general, PSNs that are in the same LAN campus would be part of same Node Group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no longer an entity referred to as an Inline Posture node.&amp;nbsp; This was removed many releases ago and the ASA can support Posture for VPN users without it.&amp;nbsp; Traffic does not flow "through" PSNs.&amp;nbsp;&amp;nbsp; PSNs terminate RADIUS and Posture Assessment conversations with NAD and endpoint, respectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE supports L3 separation of PAN and MNT nodes (or PAN+MNT nodes) for geographic redundancy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 15:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544221#M496227</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-07-12T15:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544222#M496228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chyps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response. If i require posture assessment and remediation for Corporate LAN users in addition to VPN users, should i go with Anyconnect agent? Is there any other agent available for this purpose?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 16:21:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544222#M496228</guid>
      <dc:creator>mgr</dc:creator>
      <dc:date>2018-07-12T16:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544223#M496229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Posture services with ISE require AnyConnect--either persistent or temporal agent.&amp;nbsp; ISE can also integrate with other systems which report compliance.&amp;nbsp; For example, ISE can query SCCM or Intune or MDM products regarding an endpoints compliance/posture status that do not entail the use of AnyConnect.&amp;nbsp; However, if require ISE solution to perform the endpoint interrogation and remediation, then AC required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 16:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544223#M496229</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-07-12T16:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544224#M496230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chyps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a&amp;nbsp; ton for your clear explanation. This answers my query completely. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 06:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544224#M496230</guid>
      <dc:creator>mgr</dc:creator>
      <dc:date>2018-07-13T06:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544225#M496231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make myself very sure, Is the below mentioned diagram a valid design for positioning the ISE components? I am planning to position two PSNs one in each data cener. In case, the local PSN fails, the endpoints need to authenticate with the other DC's PSN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ISE query.jpg" class="image-1 jive-image" src="/legacyfs/online/fusion/119145_ISE query.jpg" style="width: 620px; height: 287px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 10:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/3544225#M496231</guid>
      <dc:creator>mgr</dc:creator>
      <dc:date>2018-07-16T10:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/4286629#M565300</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/479386"&gt;@mgr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you test your design? Can u please share more information about the outcome of the design in regards the L3 different center deployment of two PSNs, PAN and MnT nodes?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have almost the same setup and I would like to understand best practices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/4286629#M565300</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-02-05T09:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/4286873#M565313</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081844"&gt;@laurathaqi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;this is an old post (Jul, 2018) ... so please take a look at the following links:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;A href="https://community.cisco.com/docs/DOC-68347" target="_blank" rel="noopener"&gt;ISE Performance &amp;amp; Scale&lt;/A&gt; ... &amp;nbsp;search for &lt;STRONG&gt;Maximum Network Latency Between Nodes&lt;/STRONG&gt; (&lt;STRONG&gt;300 ms&lt;/STRONG&gt; - &lt;STRONG&gt;ISE 2.1+&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;2. &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_deployment.html#ID513" target="_blank" rel="noopener"&gt;ISE Admin Guide 2.7&lt;/A&gt; ... search for &lt;STRONG&gt;Create a Policy Service Node Group&lt;/STRONG&gt; (".&lt;EM&gt;.. make all PSNs in the same local network part of the same Node Group ...&lt;/EM&gt;")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 17:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/4286873#M565313</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-02-05T17:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment in two data centers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/4286979#M565318</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for sharing the information. Highly helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best wishes,&lt;/P&gt;&lt;P&gt;Laura&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 19:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-in-two-data-centers/m-p/4286979#M565318</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-02-05T19:54:12Z</dc:date>
    </item>
  </channel>
</rss>

