<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 1.4 - Inline Posture Nodes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461678#M539311</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its best to try and stay away from deployments using IPN where possible. On the VPN side the ASA support COA natively. As we increase 3rd party support there will be less of a need for the IPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html" title="http://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html"&gt;ASA Version 9.2.1 VPN Posture with ISE Configuration Example - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice in ISE 2.0 that its no longer supported&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/release_notes/ise20_rn.html#pgfId-587660" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/release_notes/ise20_rn.html#pgfId-587660"&gt;Release Notes for Cisco Identity Services Engine, Release 2.0 - Cisco&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Mar 2016 14:57:46 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2016-03-29T14:57:46Z</dc:date>
    <item>
      <title>ISE 1.4 - Inline Posture Nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461674#M539305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;how many standalone IPN nodes can work simultaneously in ISE deployment? My customer adds one IPN and do not switch on HA settings. After that he adds a second one and it already do not have Standalone options (Deployment Modes, Filters, Radius Config, Managed Subnets etc.). Is it expected that second node added is treated by ISE as secondary? Thank you for answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2016 10:51:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461674#M539305</guid>
      <dc:creator>janwegrz</dc:creator>
      <dc:date>2016-03-29T10:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.4 - Inline Posture Nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461675#M539306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the ISE 1.4 Admin Guide:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;Unlike other personas, Inline Posture is unable to share a node with other services. This inability to share a&lt;/P&gt;
&lt;P&gt;node means that Inline Posture must be a dedicated node that is registered to the PAN on your network.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cisco ISE allows you to have up to two Inline Posture nodes configured as an active-standby pair for high &lt;/STRONG&gt;&lt;STRONG&gt;availability.&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A maximum of 2 IPN are allowed in an ISE deployment.&amp;nbsp; One acting as an HA standby.&amp;nbsp; I have linked the specific section below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_0100.html#ID61" title="http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_0100.html#ID61"&gt;Cisco Identity Services Engine Administrator Guide, Release 1.4 - Set Up Inline Posture [Cisco Identity Services Engine…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2016 14:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461675#M539306</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2016-03-29T14:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.4 - Inline Posture Nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461676#M539307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPNs are considered Network Access Devices on the network so it will support many of them &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the document it actually says &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;At any network entry point, like VPN headend using ASA or group of ASAs in an HA cluster, a maximum of 2 Inline Posture nodes can be deployed as active-standby pair for high-availability. You can have several HA pairs in a deployment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this guide it also explains it a little differently&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_deploy.html#29252" title="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_deploy.html#29252"&gt;Cisco Identity Services Engine Hardware Installation Guide, Release 1.2 - Network Deployments in Cisco ISE [Cisco Identi…&lt;/A&gt;&lt;/P&gt;&lt;H2 class="p_H_Head1" style="font-size: 14px; color: #336666; font-family: Arial, Helvetica, sans-serif; margin: 14px 0 7px -0.1in;"&gt;Inline Posture Planning Considerations&lt;/H2&gt;&lt;P class="pB1_Body1" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0 6px;"&gt;&lt;A name="pgfId-1153230"&gt;&lt;/A&gt;A network or system architect is responsible for researching the issues involved in Inline Posture deployment to determine what best suits network requirements.&lt;/P&gt;&lt;P class="pB1_Body1" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0 6px;"&gt;&lt;A name="pgfId-1153770"&gt;&lt;/A&gt;A network or system architect must address the following basic questions when planning to deploy Inline Posture nodes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A name="pgfId-1153231"&gt;&lt;/A&gt;Will deployment plans include an Inline Posture primary-secondary pair configuration? Cisco ISE networks support up to two Inline Posture nodes configured on a network at any one time.&lt;/LI&gt;&lt;LI&gt;&lt;A name="pgfId-1153790"&gt;&lt;/A&gt;What type of Inline Posture operating modes will you choose?&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2016 14:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461676#M539307</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-03-29T14:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.4 - Inline Posture Nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461677#M539309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting.&amp;nbsp; Though I do not see where it states that you can have multiple IPN HA Pairs.&amp;nbsp; All I see is this statement:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ISE allows you to have two Inline Posture nodes, and they can take on primary or secondary roles for high availability.&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;Cisco ISE networks support up to two Inline Posture nodes configured on a network at any one time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would certainly make sense to allow for multiple instances, but the documentation seems lacking.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe different network segments or entry points on separate networks...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2016 14:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461677#M539309</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2016-03-29T14:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.4 - Inline Posture Nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461678#M539311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its best to try and stay away from deployments using IPN where possible. On the VPN side the ASA support COA natively. As we increase 3rd party support there will be less of a need for the IPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html" title="http://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html"&gt;ASA Version 9.2.1 VPN Posture with ISE Configuration Example - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice in ISE 2.0 that its no longer supported&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/release_notes/ise20_rn.html#pgfId-587660" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/release_notes/ise20_rn.html#pgfId-587660"&gt;Release Notes for Cisco Identity Services Engine, Release 2.0 - Cisco&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2016 14:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-inline-posture-nodes/m-p/3461678#M539311</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-03-29T14:57:46Z</dc:date>
    </item>
  </channel>
</rss>

