<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic pxGrid Implementation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578754#M540949</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When enabling pxGrid in a new ISE 2.0 deployment, should the distributed deployment be built out before enabling pxGrid on the desired nodes, or is it ok to enable it on the first node before joining the other nodes to the deployment and assigning roles?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Feb 2016 18:33:51 GMT</pubDate>
    <dc:creator>andrew333</dc:creator>
    <dc:date>2016-02-09T18:33:51Z</dc:date>
    <item>
      <title>pxGrid Implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578754#M540949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When enabling pxGrid in a new ISE 2.0 deployment, should the distributed deployment be built out before enabling pxGrid on the desired nodes, or is it ok to enable it on the first node before joining the other nodes to the deployment and assigning roles?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 18:33:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578754#M540949</guid>
      <dc:creator>andrew333</dc:creator>
      <dc:date>2016-02-09T18:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: pxGrid Implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578755#M540954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can really do it in any order..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, keep in mind, for pxGrid there are three roles:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Controller&lt;/LI&gt;&lt;LI&gt;Publisher&lt;/LI&gt;&lt;LI&gt;Subscriber&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;So what makes the most sense from an order of operations perspective would be to build out your entire ISE cube (deployment).&amp;nbsp; Once all the nodes are joined &amp;amp; assigned their normal persona (aka: role); then you can do the pxGrid certificates for each of the nodes that will participate.&amp;nbsp; Once they're ready, enable the services on the respective nodes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a certificate perspective, it is usually best to use all pxGrid certificates from the same CA Root.&amp;nbsp; It could be a company specific CA (like the one from MS) or even public roots.&amp;nbsp; That way all pxGrid components (publishers, subscribers &amp;amp; controller) are using certs that are signed &amp;amp; trusted as part of the same PKI hierarchy.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will also be part of my Cisco Live - Berlin session next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 19:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578755#M540954</guid>
      <dc:creator>Aaron Woland</dc:creator>
      <dc:date>2016-02-09T19:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: pxGrid Implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578756#M540959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aaron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick response. My deployment will be three nodes for a geographically dispersed cube:&lt;/P&gt;&lt;P&gt;Node 1: PAN/Primary MnT/PSN/Primary pxGrid &lt;/P&gt;&lt;P&gt;Node 2: Secondary Admin &amp;amp; MnT/PSN/Secondary pxGrid&lt;/P&gt;&lt;P&gt;Node 3: PSN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nodes 2 &amp;amp; 3 are still in their boxes so I was wondering if it would be best to bring them up before enabling pxGrid. There is a strong desire for immediate StealthWatch integration. Thanks for your guidance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I look forward to your Live Session (presuming it's available on ciscolive.com). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 19:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578756#M540959</guid>
      <dc:creator>andrew333</dc:creator>
      <dc:date>2016-02-09T19:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: pxGrid Implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578757#M540964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please be advised that pxgrid requires its own psn to run by itself on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you use deployment size of medium to support up to 5 standalone PSNs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Small deployment doesn't support splitting out psn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/installation_guide/b_ise_InstallationGuide20/Network_Deployments_in_Cisco_ISE.html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are docs here about pxgrid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-implementation-design-guides-list.html&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 20:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-implementation/m-p/3578757#M540964</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-02-09T20:41:40Z</dc:date>
    </item>
  </channel>
</rss>

