<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Distributed environment-ISE ports &amp; communication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483023#M521387</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly help with the below queries regarding Distributed environment,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What all ports should be opened between ISE nodes in a Distributed environment. If the Admin node should communicate with the Policy Node, what all ports should be opened between these boxes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the Policy Node directly communicate with the Monitoring Node or does the Policy Node send all the logs to the Admin Node &amp;amp; Admin node pass it on to the Monitoring Node&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Sep 2017 15:52:47 GMT</pubDate>
    <dc:creator>nikhilcherian</dc:creator>
    <dc:date>2017-09-21T15:52:47Z</dc:date>
    <item>
      <title>Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483023#M521387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly help with the below queries regarding Distributed environment,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What all ports should be opened between ISE nodes in a Distributed environment. If the Admin node should communicate with the Policy Node, what all ports should be opened between these boxes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the Policy Node directly communicate with the Monitoring Node or does the Policy Node send all the logs to the Admin Node &amp;amp; Admin node pass it on to the Monitoring Node&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2017 15:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483023#M521387</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-09-21T15:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483024#M521388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The full list of ports used between each node (and for what purpose) are listed here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/install_guide/b_ise_InstallationGuide23/b_ise_InstallationGuide23_chapter_0110.pdf" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/install_guide/b_ise_InstallationGuide23/b_ise_InstallationGuide23_chapter_0110.pdf"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/install_guide/b_ise_InstallationGuide23/b_ise_InstallationGuide23…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2017 15:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483024#M521388</guid>
      <dc:creator>bravojared</dc:creator>
      <dc:date>2017-09-21T15:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483025#M521389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the link, I had gone thru the link before I posted the question. The link mentions about "Replication and Synchronization" &amp;amp; Clustering (Node Group)". In which category the communication between Admin Node &amp;amp; Policy Node falls in . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link also doesn't provide any answer on my second question, as to how does the PSN communicate with MnT. Is it thru PAN or do they communicate directly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2017 19:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483025#M521389</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-09-21T19:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483026#M521390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Current Diagram from same 2.3 guide you had link to...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="iseportsnodes.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/111480_iseportsnodes.jpg" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2017 19:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483026#M521390</guid>
      <dc:creator>bravojared</dc:creator>
      <dc:date>2017-09-21T19:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483027#M521392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for the quick help &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2017 19:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483027#M521392</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-09-21T19:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483028#M521396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the diagram I can see you have configured the NAD to send syslog to the MnT server &amp;amp; not to the PSN server. Can you tell me why the syslogs should be send to the MnT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 03:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483028#M521396</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-09-22T03:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483029#M521398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is for troubleshooting and event correlation only and should only be done when debugging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The monitoring and troubleshooting node is used for logging purposes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no need to send to psn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 04:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483029#M521398</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-09-22T04:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483030#M521401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 04:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483030#M521401</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-09-22T04:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483031#M521404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.cisco.com//u1/147838"&gt;jakunst&lt;/A&gt;, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today when I tried to do a CoA&amp;nbsp; for a client from my admin node, I could see there was a communication on port tcp/1700 between Admin &amp;amp; PSN. I couldn't this port reference in the communication between PAN &amp;amp; PSN anywhere. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you seen any communication in this port between PAN &amp;amp; PSN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nikhil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483031#M521404</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-12-12T17:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed environment-ISE ports &amp; communication</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483032#M521406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please reference the diagram attached to the thread, its mentioned right in the middle. PAN tells PSNs to do the COA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 18:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-environment-ise-ports-communication/m-p/3483032#M521406</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-12T18:13:31Z</dc:date>
    </item>
  </channel>
</rss>

