<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 High availability questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789476#M542088</link>
    <description>Yes, you would deploy two ISE VM's and they would be registered together in a single deployment.  Both nodes will host everything you need for HA, Admin (primary/secondary), Monitoring (primary/secondary), Policy Service (TACACS and RADIUS).  If one node goes down, the other node can assume the admin and monitoring duties.  The policy service role is active on all nodes, active/active.</description>
    <pubDate>Mon, 28 Jan 2019 15:01:08 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2019-01-28T15:01:08Z</dc:date>
    <item>
      <title>ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732879#M542083</link>
      <description>&lt;P&gt;Dear buddy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I started deploy ISE 2.4 in my lab before go to real deployment. Now i'm setup 2 ISE nodes in stand alone HA deployment. I have some question need you guys help:&lt;/P&gt;
&lt;P&gt;1. I want to deploy two ISE nodes in different DC for redundancy, but i don't know which TCP/IP ports two ones use to communicate with each other for registration and replication data. I need those ports for open firewall rule.&lt;/P&gt;
&lt;P&gt;2. What's extract data replicated between two nodes? Database/configuration/...? How frequency it is synchronized between them?&lt;/P&gt;
&lt;P&gt;3. How can i monitor heath of those nodes? (my company only purchase two VMs license so we can not deploy automatic heath check nodes). Can i monitor those node by network monitor tool using SNMP?&lt;/P&gt;
&lt;P&gt;4. My company want to migrate from ACS 4.2 to ISE 2.4 for device administrator. Can i export username/password/network device group/policy from ACS to ISE?&lt;/P&gt;
&lt;P&gt;5. Which data can i backup from ISE for restoring in the future? Configuration/database/...?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732879#M542083</guid>
      <dc:creator>nguyenlam</dc:creator>
      <dc:date>2019-03-11T08:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732895#M542084</link>
      <description>&lt;P&gt;1. I want to deploy two ISE nodes in different DC for redundancy, but i don't know which TCP/IP ports two ones use to communicate with each other for registration and replication data. I need those ports for open firewall rule.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_0110.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_0110.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. What's extract data replicated between two nodes? Database/configuration/...? How frequency it is synchronized between them?&lt;/P&gt;
&lt;P&gt;There is a significant number of different data streams that will pass between these two nodes.&amp;nbsp; I would look at the link above for ports and communication between node roles.&amp;nbsp; Your configuration replication between the two nodes is essentially real time as will authentication logs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. How can i monitor heath of those nodes? (my company only purchase two VMs license so we can not deploy automatic heath check nodes). Can i monitor those node by network monitor tool using SNMP?&lt;/P&gt;
&lt;P&gt;There are a number of SNMP polls supported, you can also enable smtp email alerts for a long list of issues.&amp;nbsp; Look at my previous post here for more info on SNMP monitoring.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/monitor-ise-process-through-snmp/m-p/3718768/highlight/true#M18685" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/monitor-ise-process-through-snmp/m-p/3718768/highlight/true#M18685&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. My company want to migrate from ACS 4.2 to ISE 2.4 for device administrator. Can i export username/password/network device group/policy from ACS to ISE?&lt;/P&gt;
&lt;P&gt;You will not be able to migrate ACS 4.2 to 2.4 via the migration tool Cisco has built.&amp;nbsp;&lt;SPAN&gt;This would be possible if you were running ACS 5.5 or newer.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;You will not be able to migrate user accounts from ACS to ISE&lt;/P&gt;
&lt;P&gt;You can import ACS NADs to ISE via a CSV file.&amp;nbsp; You will have to manipulate the data.&lt;/P&gt;
&lt;P&gt;You will have to build your ACS policies manually in ISE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5. Which data can i backup from ISE for restoring in the future? Configuration/database/...?&lt;/P&gt;
&lt;P&gt;You can backup the ISE configuration (all GUI and ADE-OS config) based on the backup/restore page.&amp;nbsp; You will create a schedule, and ISE will backup itself and export to a repository of your choosing.&amp;nbsp; This can be restored to a new standalone ISE node if you deployment was to fail.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also backup your radius/tacacs logs via the same backup restore portal, this is called the operation data.&lt;/P&gt;
&lt;P&gt;If you build your ISE deployment in the lab, you can backup the config, restore it on a new node in production, then join the second production node to the deployment.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As an additional note, you need to make sure you stay under 300ms round trip time latency between your two ISE nodes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 16:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732895#M542084</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-10-25T16:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732942#M542085</link>
      <description>&lt;P&gt;Great&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Contributor lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;A id="link_13" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320219" target="_self"&gt;Damien Miller&lt;/A&gt;, your answer help me a lot!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Contributor lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;For backup/restore question. Can i backup/restore local user/user group, certificate, NAD,...?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Contributor lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 17:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732942#M542085</guid>
      <dc:creator>nguyenlam</dc:creator>
      <dc:date>2018-10-25T17:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732947#M542086</link>
      <description>&lt;P&gt;You have to back up the certificates, both trusted and system, from either the gui export or via the CLI export. The BU has provided a very thorough backup and restore documentation guide.&amp;nbsp; The certificate stores are not backed up with the config backup.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01100.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01100.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The local users/groups will be included in the standard ISE config backup you run.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 17:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3732947#M542086</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-10-25T17:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789410#M542087</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does it mean that for production environment, we can setup two standalone virtual ISE in high availability?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 14:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789410#M542087</guid>
      <dc:creator>leolink1</dc:creator>
      <dc:date>2019-01-28T14:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789476#M542088</link>
      <description>Yes, you would deploy two ISE VM's and they would be registered together in a single deployment.  Both nodes will host everything you need for HA, Admin (primary/secondary), Monitoring (primary/secondary), Policy Service (TACACS and RADIUS).  If one node goes down, the other node can assume the admin and monitoring duties.  The policy service role is active on all nodes, active/active.</description>
      <pubDate>Mon, 28 Jan 2019 15:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789476#M542088</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-01-28T15:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789494#M542089</link>
      <description>Hi Damien,&lt;BR /&gt;Many thanks for your reply. Is there a helpful link that can help with this high availability deployment for Virtual ISE.&lt;BR /&gt;&lt;BR /&gt;Please share. Thank you.&lt;BR /&gt;</description>
      <pubDate>Mon, 28 Jan 2019 15:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789494#M542089</guid>
      <dc:creator>leolink1</dc:creator>
      <dc:date>2019-01-28T15:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789502#M542090</link>
      <description>&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.html&lt;/A&gt;</description>
      <pubDate>Mon, 28 Jan 2019 15:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789502#M542090</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-01-28T15:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789637#M542091</link>
      <description>Hi Damien,&lt;BR /&gt;Will the virtual ISE VM require separate licenses or will only one license be sufficient for the two ISE? for one admin license for both.&lt;BR /&gt;</description>
      <pubDate>Mon, 28 Jan 2019 17:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789637#M542091</guid>
      <dc:creator>leolink1</dc:creator>
      <dc:date>2019-01-28T17:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789650#M542092</link>
      <description>You require a VM license per node.  For two nodes you need either 2x R-ISE-VMS-K9= or R-ISE-VMM-K9= depending on the scale you want.  &lt;BR /&gt;&lt;BR /&gt;TACACS will also be licenses per node now.  So if you want to enable TACACS on two nodes, you would need 2x L-ISE-TACACS-ND=.&lt;BR /&gt;&lt;BR /&gt;Technically old licensing can be ordered for another two weeks, but I'm not going to muddy the water going in to something that is effectively gone.</description>
      <pubDate>Mon, 28 Jan 2019 18:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3789650#M542092</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-01-28T18:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 High availability questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3790594#M542093</link>
      <description>Hi Damien,&lt;BR /&gt;&lt;BR /&gt;I found the pieces of information you provided very helpful.&lt;BR /&gt;Thank you.&lt;BR /&gt;</description>
      <pubDate>Tue, 29 Jan 2019 17:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-high-availability-questions/m-p/3790594#M542093</guid>
      <dc:creator>leolink1</dc:creator>
      <dc:date>2019-01-29T17:00:44Z</dc:date>
    </item>
  </channel>
</rss>

