<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN Auto-Failover for 2 ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512761#M519178</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arne&lt;/P&gt;&lt;P&gt;I was testing this and observed there is a downtime even for the dot1x radius authentication traffic, while the Secondary PAN is promoting into Primary role. Is that an expected behaviour? As per the below link it is not supposed to impact the radius authentication traffic. Please suggest.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.0 - Set Up Cisco ISE in a Distributed Environment [Cisco …&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;V Vinodh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Dec 2017 13:00:03 GMT</pubDate>
    <dc:creator>junk1</dc:creator>
    <dc:date>2017-12-14T13:00:03Z</dc:date>
    <item>
      <title>PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512753#M519168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am working on the ISE part of my DNA SDA customer. There are 2 ISE boxes and each ISE box running PAN, MnT and PSN personas. I would like to know how to enable Auto Failover between PAN. The below URL says, for enabling PAN Auto Failover, I need 3 nodes - 2 of which are admin nodes and a 3rd secondary node. &lt;/P&gt;&lt;P&gt;Please suggest how to achieve Auto failover between PAN in a standalone deployment.&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59" rel="nofollow" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;If I promote Secondary PAN to Primary will it restart? Is that an expected behaviour? If it restarts, and as PSN is also running in same box there will be a downtime in the network. Please advise. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;V Vinodh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 10:25:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512753#M519168</guid>
      <dc:creator>junk1</dc:creator>
      <dc:date>2017-12-13T10:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512754#M519169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Auto failover is not supported with standalone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need an external psn to be the health monitor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be supported for this in production you will need a non standalone setup where the psns are outside of the pan/mnt for a small medium setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the ISE deployment sizing in the admin guide&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 12:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512754#M519169</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-13T12:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512755#M519170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes when you Promote it will restart and that psn Will be down as it’s running on same system&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 12:23:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512755#M519170</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-13T12:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512756#M519171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;Could you please confirm if Auto Failover also restarts the ISE services? &lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;V Vinodh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 12:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512756#M519171</guid>
      <dc:creator>junk1</dc:creator>
      <dc:date>2017-12-13T12:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512757#M519172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure please read the guide here and I will check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be safe assume yes they are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010.html#reference_58F40B0E4D354B4DBB9940E4DB8DC8ED&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 13:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512757#M519172</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-13T13:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512758#M519173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. It's to automate the action in promoting the secondary PAN to the primary. It restarts the ISE services on the secondary PAN when we do it manually so the auto failover will restart ISE services as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 14:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512758#M519173</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-12-13T14:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512759#M519175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't hear much about PAN failover on these forums but I can happily report that I have been using it since day one and it works as designed.&lt;/P&gt;&lt;P&gt;I had the unfortunate experience the other day where the primary PAN popped its clogs for no reason, and the Secondary took over automatically.&amp;nbsp; It's not quick. And the failure detection &lt;STRONG&gt;should NOT be quick&lt;/STRONG&gt; because failover is not to be taken lightly.&amp;nbsp; Processes take ages to wind down, and then start up again on Secondary.&amp;nbsp; I have left the default timers in place which means that failover is TRIGGERED after 10 minutes.&amp;nbsp; At that point the Secondary stops processes and restarts. In my case that's another 10min down.&amp;nbsp; All in all, from time of PAN Primary failure, until happy eyeballs, you're looking at 20min no Admin.&amp;nbsp; Here are some other caveats to be aware of&lt;/P&gt;&lt;P&gt;1) While Admin(s) are down, Sponsor Portal works on PSN but nobody can log in - Guest accounts managed by PAN!&lt;/P&gt;&lt;P&gt;2) PAN Auto Failover gets in the way of patches and upgrades.&amp;nbsp; Make sure you disable PAN failover prior to patching&lt;/P&gt;&lt;P&gt;3) URT for ISE 2.3 couldn't cope with a system where PAN Auto failover was enabled.&amp;nbsp; Fixed in later release of URT. Just beware that unintentional side effects (weird stuff) can happen with PAN Auto failover.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 23:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512759#M519175</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-12-13T23:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512760#M519177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Thanks everyone, for the responses. Much appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2017 05:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512760#M519177</guid>
      <dc:creator>junk1</dc:creator>
      <dc:date>2017-12-14T05:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512761#M519178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arne&lt;/P&gt;&lt;P&gt;I was testing this and observed there is a downtime even for the dot1x radius authentication traffic, while the Secondary PAN is promoting into Primary role. Is that an expected behaviour? As per the below link it is not supposed to impact the radius authentication traffic. Please suggest.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.0 - Set Up Cisco ISE in a Distributed Environment [Cisco …&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;V Vinodh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2017 13:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512761#M519178</guid>
      <dc:creator>junk1</dc:creator>
      <dc:date>2017-12-14T13:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Auto-Failover for 2 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512762#M519179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vinodh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tested this scenario.&amp;nbsp; I have a full distributed deployment (2 x PAN, 2 x MnT and 4 x PSN).&amp;nbsp; I would suspect that in such a deployment the Radius daemon on my PSN's would be unaffected by the PAN outage. If this is NOT the case then I would be quite alarmed.&amp;nbsp; WHat does your deployment look like?&amp;nbsp; Do use allinone nodes?&amp;nbsp; If so,and if not using some load balancer intelligence, then I would expect the NAS to still send to the Primary AAA (PAN/PSN) and thus impacting traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Dec 2017 01:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pan-auto-failover-for-2-ise/m-p/3512762#M519179</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-12-15T01:02:53Z</dc:date>
    </item>
  </channel>
</rss>

