<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE MNT Failover Testing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3707427#M542978</link>
    <description>&lt;P&gt;It will be good to record this as you do a change.&lt;/P&gt;
&lt;P&gt;When you stop the service in Primary PAN and MNT, check out what happens to secondary PAN and MNT.&lt;/P&gt;
&lt;P&gt;Here is the link to ISE 2.2 MNT failover documentation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010.html#ID90" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010.html#ID90&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your case, secondary MNT should get the logs still when Primary MNT goes down. You need to manually promote Secondary MNT/PAN to primary then.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Krishnan&lt;/P&gt;</description>
    <pubDate>Sat, 15 Sep 2018 01:07:29 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2018-09-15T01:07:29Z</dc:date>
    <item>
      <title>ISE MNT Failover Testing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3705760#M542974</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a new distributed ISE deployment PAN, MNT and 2&amp;nbsp;*&amp;nbsp;PSNs that I have to failover test.&lt;/P&gt;
&lt;P&gt;The PAN and MNT act as secondary MNT and PAN to each other.&lt;/P&gt;
&lt;P&gt;When I failover the PAN&amp;nbsp;the MNT is set to be manually promoted to PAN and therefore reboots (restarts its ISE services).&lt;/P&gt;
&lt;P&gt;When I failover the MNT (stop the application via cli)&amp;nbsp;the PAN has to be set as Primary MNT. I presume this does not cause a restart of ISE PAN services, does it?&lt;/P&gt;
&lt;P&gt;What is good evidence that I can record to show that the PAN is also now the current Primary MNT?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks in advance&lt;/P&gt;
&lt;P&gt;Scott&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3705760#M542974</guid>
      <dc:creator>Scott Gillies</dc:creator>
      <dc:date>2019-03-11T08:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MNT Failover Testing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3705853#M542975</link>
      <description>&lt;P&gt;PAN and MNT are two different functional roles in a ISE deployment.&lt;/P&gt;
&lt;P&gt;If you have two nodes, one as primary PAN and primary MNT, second one as secondary PAN and secondary MNT. The Primary PAN is active and Secondary PAN will be standby. ISE supports both automatic and manual failover of Administrative node. For automatic failover you need something called a health check node that checks if the Primary PAN is available or not. You can have a PSN as a health check node if you have PAN and MNT in the same node. Health check node should not be a PAN.&lt;/P&gt;
&lt;P&gt;You can find more information about Admin node failover with the following documentation for ISE 2.4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.html#ID59" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.html#ID59&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try out the failover once you understand how it works and enable the right set of controls.&lt;/P&gt;
&lt;P&gt;Then look at the ISE UI, Administration --&amp;gt; Deployment and check the roles of the individual nodes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Krishnan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 20:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3705853#M542975</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2018-09-12T20:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MNT Failover Testing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3705855#M542976</link>
      <description>I would also look at craig hyps performance and scale presentation from cisco live&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Sep 2018 20:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3705855#M542976</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-12T20:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MNT Failover Testing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3706104#M542977</link>
      <description>&lt;P&gt;Hi Krishnan&lt;/P&gt;
&lt;P&gt;Thank you for your prompt reply.&lt;/P&gt;
&lt;P&gt;Apologies I should have mentioned I am using ISE 2.2 not 2.4. I have a manual PAN failover&amp;nbsp;configuration&amp;nbsp;so the Health Check Node will not be applicable in my current deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When&amp;nbsp;the Secondary Admin node (in my case the MNT is the Secondary Admin) is promoted to Primary Admin (in my case I will do this manually - stop the PAN services then promote the MNT which will reboot the ISE services) it will&amp;nbsp;be obvious/evident when logging onto the MNT that it is now the Primary Admin because the Web Gui should now have all the appropriate Admin configuration options which only the Primary PAN has.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I am trying to understand is if I configure/promote the Secondary MNT (in my case the PAN is Secondary MNT)&amp;nbsp;to be the Primary MNT what evidence do I look for (other than the configuration in the deployment) that the PAN is also performing the Primary MNT&amp;nbsp;role? Is there anything obvious that would indicate this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also does setting the PAN as Primary MNT cause the PAN to reboot the ISE services?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 13:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3706104#M542977</guid>
      <dc:creator>Scott Gillies</dc:creator>
      <dc:date>2018-09-13T13:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MNT Failover Testing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3707427#M542978</link>
      <description>&lt;P&gt;It will be good to record this as you do a change.&lt;/P&gt;
&lt;P&gt;When you stop the service in Primary PAN and MNT, check out what happens to secondary PAN and MNT.&lt;/P&gt;
&lt;P&gt;Here is the link to ISE 2.2 MNT failover documentation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010.html#ID90" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010.html#ID90&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your case, secondary MNT should get the logs still when Primary MNT goes down. You need to manually promote Secondary MNT/PAN to primary then.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Krishnan&lt;/P&gt;</description>
      <pubDate>Sat, 15 Sep 2018 01:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mnt-failover-testing/m-p/3707427#M542978</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2018-09-15T01:07:29Z</dc:date>
    </item>
  </channel>
</rss>

