<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [ISE2.2] Originating Policy Services Node behavior in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432261#M535366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm testing "Originating Policy Services Node" setting with ISE2.2 distributed topology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With some best practice guidance, I changed the setting from "Auto" to nearest PSN on the setting.&amp;nbsp; &lt;/P&gt;&lt;P&gt;It works as expected first. But it the PSN goes offline, SNMP query node will not fallback to other PSNs. &lt;/P&gt;&lt;P&gt;Is it expected behavior? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer's expectation is as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Configured PSN always sends SNMP Query to the NAD if the PSN is active&lt;/P&gt;&lt;P&gt;- If the PSN becomes offline, next PSN is randomly selected. Then the next PSN sends SNMP Query instead till original PSN is recovered. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Sep 2017 08:10:21 GMT</pubDate>
    <dc:creator>masyamad</dc:creator>
    <dc:date>2017-09-06T08:10:21Z</dc:date>
    <item>
      <title>[ISE2.2] Originating Policy Services Node behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432261#M535366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm testing "Originating Policy Services Node" setting with ISE2.2 distributed topology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With some best practice guidance, I changed the setting from "Auto" to nearest PSN on the setting.&amp;nbsp; &lt;/P&gt;&lt;P&gt;It works as expected first. But it the PSN goes offline, SNMP query node will not fallback to other PSNs. &lt;/P&gt;&lt;P&gt;Is it expected behavior? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer's expectation is as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Configured PSN always sends SNMP Query to the NAD if the PSN is active&lt;/P&gt;&lt;P&gt;- If the PSN becomes offline, next PSN is randomly selected. Then the next PSN sends SNMP Query instead till original PSN is recovered. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 08:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432261#M535366</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2017-09-06T08:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE2.2] Originating Policy Services Node behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432262#M535367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;2nd try. Could someone take a look on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 23:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432262#M535367</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2017-09-07T23:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE2.2] Originating Policy Services Node behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432263#M535368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That might be expected. I am checking on it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 00:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432263#M535368</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-08T00:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE2.2] Originating Policy Services Node behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432264#M535369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. This is expected behavior.&amp;nbsp; Once a specific PSN is selected for polling, the only way to force an association with another PSN is to de-register the original PSN.&amp;nbsp; I believe the behavior is same for Auto, but would be interested to hear if seeing different behavior with Auto selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend filing a defect to help address the caveat.&amp;nbsp; I thought there may have already been one opened, but not finding it.&amp;nbsp; In past I requested enhancements to provide fallback, to allow source PSN value to be set in bulk via UI, as well as to auto-select PSN based on location.&amp;nbsp; Today the only option is to use ERS API to script such changes.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 01:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432264#M535369</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-09-08T01:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE2.2] Originating Policy Services Node behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432265#M535370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks hslai, chyps, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Once a specific PSN is selected for polling, the only way to force an association with another PSN is to de-register the original PSN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK. But re-configuring originating parameter on NAD setting (from a certain PSN to another, or back to auto) doesn't effect? &lt;BR /&gt;The de-registering PSN from PAN is an impact for existing deployment. So I'd like to make sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; I believe the behavior is same for Auto, but would be interested to hear if seeing different behavior with Auto selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK. I'll ask my customer to test the "Auto" behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; I recommend filing a defect to help address the caveat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK. But I'd like to confirm what the current caveat is. Does it mean "need de-registering for PSN change"? &lt;/P&gt;&lt;P&gt;Could you let me know about 1) what the current caveat, and 2) what the desired produce behavior is?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 04:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432265#M535370</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2017-09-08T04:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE2.2] Originating Policy Services Node behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432266#M535371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue is that we do not auto-assign a different PSN upon failure of current designated poller.&amp;nbsp; This coincides with your initial report.&amp;nbsp; The desired behavior is for ISE to more gracefully handle the PSN failure.&amp;nbsp;&amp;nbsp; There are many possible scenarios and solutions, but they do not currently exist so that is why I propose open TAC case and have bug filed.&amp;nbsp;&amp;nbsp; Yes, de-registering the failed PSN should resolve, but I will admit this is not a desirable solution and only a workaround.&amp;nbsp;&amp;nbsp; If temporary failure of PSN, then this generally should not have a major impact as the SNMP poller is primarily used as a catch all mechanism whereas RADIUS Accounting should trigger active endpoints entering and leaving network.&amp;nbsp; If expect PSN to be down for extended period, then you could de-register.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 04:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432266#M535371</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-09-08T04:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE2.2] Originating Policy Services Node behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432267#M535372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see. I'll try to open with account team's help. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise2-2-originating-policy-services-node-behavior/m-p/3432267#M535372</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2017-09-08T07:00:54Z</dc:date>
    </item>
  </channel>
</rss>

