<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High Availability for AD or LDAP servers in distributed ISE environment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573437#M517058</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig.&lt;/P&gt;&lt;P&gt;Do you know if ACS also supports these failover scenarios for AD and LDAP ?&lt;/P&gt;&lt;P&gt;Customer has ACS 5.8 but I am first trying to understand how its done in ISE and explore the same in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Utkarsh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 May 2018 23:32:47 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2018-05-14T23:32:47Z</dc:date>
    <item>
      <title>High Availability for AD or LDAP servers in distributed ISE environment</title>
      <link>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573433#M517053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is high availability between PSNs and local AD/LDAP maintained ?&lt;/P&gt;&lt;P&gt;In a distributed environment we add the fqdn of the domain on Admin Node and then all PSNs get joined to their local domain controller.&lt;/P&gt;&lt;P&gt;If that local domain controller fails does the PSN automatically joins the next domain controller in the DNS response ?&lt;/P&gt;&lt;P&gt;Do we need to register the PSN again when that failure happens ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if you can comment on various challenges in achieving high availability between ISE and AD/LDAP servers in a distributed environment. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 21:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573433#M517053</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-05-14T21:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability for AD or LDAP servers in distributed ISE environment</title>
      <link>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573434#M517054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Specific to integration with AD join points, yes, ISE will try the next domain controllers as defined by Active Directory Site and Services.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As to LDAP, the HA is achieved by enabling secondary server.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 21:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573434#M517054</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-14T21:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability for AD or LDAP servers in distributed ISE environment</title>
      <link>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573435#M517055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the LDAP is defined by just one FQDN how would we add the secondary server ?&lt;/P&gt;&lt;P&gt;Customer has mentioned that DNS will return more than one IPs (primary and secondary ldap) for that FQDN. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 21:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573435#M517055</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-05-14T21:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability for AD or LDAP servers in distributed ISE environment</title>
      <link>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573436#M517056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LDAP supports secondary server per PSN as well as a "force reconnect" option to periodically update DNS reply.&amp;nbsp; LDAP targets can point to real server or LB VIP.&amp;nbsp; See BRKSEC-3699 posted to ciscolive.com for more info on LDAP HA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 23:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573436#M517056</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-14T23:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability for AD or LDAP servers in distributed ISE environment</title>
      <link>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573437#M517058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig.&lt;/P&gt;&lt;P&gt;Do you know if ACS also supports these failover scenarios for AD and LDAP ?&lt;/P&gt;&lt;P&gt;Customer has ACS 5.8 but I am first trying to understand how its done in ISE and explore the same in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Utkarsh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 23:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573437#M517058</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-05-14T23:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability for AD or LDAP servers in distributed ISE environment</title>
      <link>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573438#M517059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;TABLE border="1" class="E-451F249C table" style="margin: 6px 0; border: 0px; font-family: CiscoSans, Arial, sans-serif; font-size: 14px; font-style: normal; font-weight: normal; color: #58585b; text-align: start; text-indent: 0px;" width="100%"&gt;&lt;TBODY class="tbody" style="font-family: inherit; font-size: inherit; font-style: inherit; font-weight: inherit;"&gt;&lt;TR class="TablerowCSS27 E-451F249CFill row" style="margin: 0 auto; border: 0px solid transparent; font-family: inherit; font-size: inherit; font-style: inherit; font-weight: inherit;"&gt;&lt;TD class="E-451F249CColRuling E-451F249CBoxC1 entry E-451F249CRowRuling B1_Body1-F9CE5028 E-451F249C-Table29-Body-Cell11-1" headers="reference_C49694FC52514E588F5B8774692111D3__ID1145__entry__1 " style="padding: 0 5px; border: 1px solid #c6c7ca; font-family: inherit; font-size: inherit; font-style: inherit; font-weight: inherit;"&gt;&lt;P class="p" style="margin: 6px 0; font-family: inherit; font-size: 1.4rem; font-style: inherit; font-weight: 400; color: #58585b;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Force reconnect every N seconds&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD class="entry E-451F249CRowRuling B1_Body1-F9CE5028 E-451F249CBoxC2 E-451F249C-Table29-Body-Cell11-2" headers="reference_C49694FC52514E588F5B8774692111D3__ID1145__entry__2 " style="padding: 0 5px; border: 1px solid #c6c7ca; font-family: inherit; font-size: inherit; font-style: inherit; font-weight: inherit;"&gt;&lt;P class="p" style="margin: 6px 0; font-family: inherit; font-size: 1.4rem; font-style: inherit; font-weight: 400; color: #58585b;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Check this check box and enter the desired value in the Seconds text box to force the server to renew LDAP connection at the specified time interval. The valid range is from 1 to 60 minutes.&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;available in ISE 2.1+ only, but not in any of ACS 5.x. ACS 5.x does support 2nd LDAP server and the option for "Enable Deployment Configuration", which is equivalent to "Specify server for each ISE node" in ISE 2.2+.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 02:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/high-availability-for-ad-or-ldap-servers-in-distributed-ise/m-p/3573438#M517059</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-15T02:41:14Z</dc:date>
    </item>
  </channel>
</rss>

