<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Small Deployment High Availability in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486045#M528533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you join the PSN to the new deployment everything it had from the old deployment should be overwritten and the data will be sync'd from the new deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Jul 2017 20:10:28 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2017-07-12T20:10:28Z</dc:date>
    <item>
      <title>Cisco ISE Small Deployment High Availability</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486041#M528526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi please can someone help me with the below question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a splatted deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DC1 -&amp;gt; ISE1(2.2): Primary (Administration, Monitoring, Policy Service) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;DC2 -&amp;gt;ISE2(2.2): Secondary (Administration, Monitoring, Policy Service)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;DC3 -&amp;gt; ISE3(old deployment, 1.X)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;My questions are:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;I've done the two new ise2.2 node deployment as per above setup. I know above model does not going to support the automatic failover between the nodes. AS both nodes are used as PSN as well can i use each node (primary and secondary) IPs for each DC endpoints and NAD devices.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;not able to understand the PSN behavior of the Secondary node. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;can we use both PSNs nodes at a time for policy configuration? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;what will happen in case of manual failover? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Any suggestion would be really appreciated.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jul 2017 12:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486041#M528526</guid>
      <dc:creator>khalid.meraj</dc:creator>
      <dc:date>2017-07-12T12:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Small Deployment High Availability</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486042#M528528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Policy config is done on the PAN not the PSN. The PSN is the policy engine that does all the work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PSNs are always active so in a standalone environment both node1 and 2 have PSN running on them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can manually failover PAN and MNT in this environment&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jul 2017 13:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486042#M528528</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-07-12T13:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Small Deployment High Availability</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486043#M528530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PSNs are always active all the time and it is up to the network device (NAD) to utilize the PSNs in a fault tolerant manner.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M&amp;amp;Ts nodes are always active all the time and all nodes in the deployment log to the M&amp;amp;Ts.&amp;nbsp; If one the primary M&amp;amp;Ts fails the admin node will automatically pull logs from other M&amp;amp;T.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only part you won't have failover for is Admin persona.&amp;nbsp; You will just need to manually failover so you can administer the system.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jul 2017 13:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486043#M528530</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-07-12T13:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Small Deployment High Availability</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486044#M528532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for a wonderful explanation. just one question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In regards to my above setup. I'v already a PSN configured and running if i need to include that in the new clustering with the existing config what will happen. does it going to add the existing config to my new PSN config or going to overright it? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can i configure policies on secondary M&amp;amp;T which is also a PSN persona? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jul 2017 14:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486044#M528532</guid>
      <dc:creator>khalid.meraj</dc:creator>
      <dc:date>2017-07-12T14:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Small Deployment High Availability</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486045#M528533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you join the PSN to the new deployment everything it had from the old deployment should be overwritten and the data will be sync'd from the new deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jul 2017 20:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-small-deployment-high-availability/m-p/3486045#M528533</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-07-12T20:10:28Z</dc:date>
    </item>
  </channel>
</rss>

