<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Replication Process in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3689631#M508397</link>
    <description>&lt;P&gt;You may want to take a look at BRKSEC-3699 (reference version) available on ciscolive.com. Look for latest session from Orlando 2018.&amp;nbsp; The session goes into some detail on replication process between PSNs and PAN.&amp;nbsp; If replication queue on Primary PAN exceeds 1M messages, it will disconnect node and that node will require manual sync to restart automatic replication.&amp;nbsp; In the process, a full sync of current config will be pulled down.&amp;nbsp; If WAN/network conditions exist that will lead to this condition often, then consider making it separate deployment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For MnT operational data, you can still send logs from one deployment to another to get central visibility into who is logging into network.&amp;nbsp; PSNs will currently not buffer UDP logs when there is a network outage, but will buffer TCP and Secure Syslog up to the configured value (say 200MB) and will update MnT when connection reestablished.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Craig&lt;/P&gt;</description>
    <pubDate>Thu, 16 Aug 2018 12:12:46 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-08-16T12:12:46Z</dc:date>
    <item>
      <title>ISE Replication Process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3686886#M508388</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a customer asking about Replication details in ISE, some questions:&lt;/P&gt;
&lt;P&gt;- Is there any replication between Active Directory and PAN and PSN ?&lt;/P&gt;
&lt;P&gt;- How is the Replication process between PAN, PSN and Active Directory ?&lt;/P&gt;
&lt;P&gt;- What happen if I have a PSN with limited connections and can´t synchronize in 3 months ?&amp;nbsp; &amp;nbsp;will PSN stop functions without sync ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advanced.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Guillermo.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 07:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3686886#M508388</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-08-13T07:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Replication Process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3686901#M508390</link>
      <description>&lt;P&gt;No.&amp;nbsp; ISE queries AD via a Machine Account that exists in the domain.&amp;nbsp; The ISE may cache previously successful authentications for a short period of time, but that's all.&amp;nbsp; If a PSN isn't able to talk to AD for an extended period of time then it's Machine Account may expire and you may have to re-join it to the domain before it will authenticate Users again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE does replicate its own config amongst the other participating ISE nodes, but I can't say I've ever tried leaving one stranded for three months...&amp;nbsp; I can't imagine this being a strategy to encourage, especially if it's just a PSN and no PAN/MNT functionality to go with it.&amp;nbsp; In this kind of use case you may be better off building it as a standalone box then at least you still have the ability to make changes, look at logs, not worry about using it in a way that it wasn't designed to support, etc.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 08:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3686901#M508390</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2018-08-13T08:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Replication Process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3687280#M508393</link>
      <description>Thanks Richard.&lt;BR /&gt;&lt;BR /&gt;The situation is;  the customer has a movile site with large disconnected periods of time, the possible solution could include a redundant deployment with some PSNs with periods of disconnection.&lt;BR /&gt;The question is;  if I have a PSN connected and synchronized with PAN/MnT, what will happen if this PSN disconnects from PAN/MnT  ?    it will work authentication/authorization ?&lt;BR /&gt;What is going to be the impact every time the PSN reconnect to network ?&lt;BR /&gt;&lt;BR /&gt;Thanks in advanced.&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Aug 2018 16:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3687280#M508393</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-08-13T16:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Replication Process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3689525#M508395</link>
      <description>&lt;P&gt;Hi Again,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any comment or suggestion about my last update ? &amp;nbsp;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- PSN connected and synchronized with PAN/MnT, what will happen if this PSN disconnects from PAN/MnT ? it will work authentication/authorization ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- Any issue if PSN is disconnected (no connection to PAN/MnT) form large period of time ?&lt;BR /&gt;&lt;SPAN&gt;- What is going to be the impact every time the PSN reconnect to network ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 08:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3689525#M508395</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-08-16T08:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Replication Process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3689631#M508397</link>
      <description>&lt;P&gt;You may want to take a look at BRKSEC-3699 (reference version) available on ciscolive.com. Look for latest session from Orlando 2018.&amp;nbsp; The session goes into some detail on replication process between PSNs and PAN.&amp;nbsp; If replication queue on Primary PAN exceeds 1M messages, it will disconnect node and that node will require manual sync to restart automatic replication.&amp;nbsp; In the process, a full sync of current config will be pulled down.&amp;nbsp; If WAN/network conditions exist that will lead to this condition often, then consider making it separate deployment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For MnT operational data, you can still send logs from one deployment to another to get central visibility into who is logging into network.&amp;nbsp; PSNs will currently not buffer UDP logs when there is a network outage, but will buffer TCP and Secure Syslog up to the configured value (say 200MB) and will update MnT when connection reestablished.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Craig&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 12:12:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-replication-process/m-p/3689631#M508397</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-08-16T12:12:46Z</dc:date>
    </item>
  </channel>
</rss>

