<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Health Check Node within Base licenses? Roadmap question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545232#M523330</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't discuss roadmap question in the public forum. I understand the original ask is to include automatic failover in a base deployment. Please don't confuse this with base licensing. The automatic failover is included in the base licensing. The confusion is a small (base) deployment you can only have 2 nodes max, its a standalone with high availability. No you cannot deploy automatic failover and understand its a cost to have another node and since its external PSN it requires more resources on the PAN/MNT per the deployment guidelines &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to see this functionality in this type of deployment please reach out through your sales channel to our ISE product management team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/install_guide/b_ise_InstallationGuide22/b_ise_InstallationGuide22_chapter_00.html" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/install_guide/b_ise_InstallationGuide22/b_ise_InstallationGuide22_chapter_00.html"&gt;Cisco Identity Services Engine Installation Guide, Release 2.2 - Network Deployments in Cisco ISE [Cisco Identity Servi…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Aug 2017 14:17:21 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-08-01T14:17:21Z</dc:date>
    <item>
      <title>Health Check Node within Base licenses? Roadmap question</title>
      <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545227#M523320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ISE experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Health Check Node functionality (providing automatic promotion of Secondary ISE to Primary in failure circumstance) will at some stage be integrated into the base ISE functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; In a 2 node environment where all the processes are on these 2 in A/S configuration, it’s a relatively large cost to go for HCN… and if you want resilient HCN nodes, then its double the cost of the manual approach. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Flavio Costa&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 14:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545227#M523320</guid>
      <dc:creator>Flavio Costa</dc:creator>
      <dc:date>2017-07-31T14:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Node within Base licenses? Roadmap question</title>
      <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545228#M523321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would love to see an engineering document from the BU that explains (with some diagrams) how this concept is designed to work, taking into account the various failure components (PAN node failure, inter-PAN link failure, etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my view, health checking with a two node setup (both of whom are candidates) can get tricky, because when there is a split brain scenario, then either node can promote itself to be the primary (imagine that Node A doesn't hear from Node B - then it thinks, I am the master&amp;nbsp; - and vice versa). This would arise if both nodes were actually perfectly healthy, but the network link between them gets cut - then they run blind. &lt;/P&gt;&lt;P&gt;A third node provides a concept where we can observe the situation from an outsider's view to determine who is alive or not.&amp;nbsp; This is why we would nominate a MnT node to be a health checker. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One might argue that failover can and does work with two nodes (e.g. HSRP/VRRP etc) and if one were to place priority values then one doesn't need an external health checker.&amp;nbsp; Would be good to hear from the BU &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 23:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545228#M523321</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-07-31T23:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Node within Base licenses? Roadmap question</title>
      <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545229#M523323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arne, thanks for your input, +1 for a doc that explains this concept. I couldn't find anything in our data base, like Cisco Live presentations for instance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 12:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545229#M523323</guid>
      <dc:creator>Flavio Costa</dc:creator>
      <dc:date>2017-08-01T12:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Node within Base licenses? Roadmap question</title>
      <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545230#M523325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A 2 node deployment with automatic PAN failover is not supported&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need at least 3 nodes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59" rel="nofollow" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html#ID59&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig hyps cisco live for scalability and high availability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=89293&amp;amp;tclass=popup" rel="nofollow" target="_blank"&gt;https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=89293&amp;amp;tclass=popup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Slide 225&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 13:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545230#M523325</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-01T13:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Node within Base licenses? Roadmap question</title>
      <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545231#M523328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Slide 225 to be exact! &lt;A href="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=89293&amp;amp;tclass=popup" title="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=89293&amp;amp;tclass=popup"&gt;Advanced - Designing ISE for Scale &amp;amp; High Availability (2016 Berlin)&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 14:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545231#M523328</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-01T14:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Node within Base licenses? Roadmap question</title>
      <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545232#M523330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't discuss roadmap question in the public forum. I understand the original ask is to include automatic failover in a base deployment. Please don't confuse this with base licensing. The automatic failover is included in the base licensing. The confusion is a small (base) deployment you can only have 2 nodes max, its a standalone with high availability. No you cannot deploy automatic failover and understand its a cost to have another node and since its external PSN it requires more resources on the PAN/MNT per the deployment guidelines &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to see this functionality in this type of deployment please reach out through your sales channel to our ISE product management team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/install_guide/b_ise_InstallationGuide22/b_ise_InstallationGuide22_chapter_00.html" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/install_guide/b_ise_InstallationGuide22/b_ise_InstallationGuide22_chapter_00.html"&gt;Cisco Identity Services Engine Installation Guide, Release 2.2 - Network Deployments in Cisco ISE [Cisco Identity Servi…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 14:17:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545232#M523330</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-01T14:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Node within Base licenses? Roadmap question</title>
      <link>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545233#M523332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason, thank you very much for your inputs! Very helpful!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 16:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/health-check-node-within-base-licenses-roadmap-question/m-p/3545233#M523332</guid>
      <dc:creator>Flavio Costa</dc:creator>
      <dc:date>2017-08-01T16:10:50Z</dc:date>
    </item>
  </channel>
</rss>

