<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between enabling Primary/Secondary in ISE and enabling failover in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417249#M547920</link>
    <description>&lt;P&gt;Thanks everyone for your suggestions but I think I have not made myself clear; so i will rephrase. My question was: Whats the difference between enabling failover between 2 devices/personas and&amp;nbsp;configuring primary/secondary between 2 devices/personas.&amp;nbsp; Which method is better?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jul 2018 01:27:55 GMT</pubDate>
    <dc:creator>abhijith891</dc:creator>
    <dc:date>2018-07-18T01:27:55Z</dc:date>
    <item>
      <title>Difference between enabling Primary/Secondary in ISE and enabling failover</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417106#M547915</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have received a distributed environment for Cisco ISE from a client where they have configured an ISE node in one location as Primary in Admin, Sec in Monitoring and another ISE in another location as Secondary&amp;nbsp;&lt;SPAN&gt;in Admin, Primary in Monitoring. So I just wanted to know how different is this scenario if failover was enabled between them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abhijit&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417106#M547915</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2020-02-21T19:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between enabling Primary/Secondary in ISE and enabling failover</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417157#M547916</link>
      <description>&lt;P&gt;I suggest to have a look at one of the cisco Live presentation, and you have more clarity about the setup.&lt;/P&gt;
&lt;P&gt;It all depends on how you choose and deploy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://d2zmdbbm9feqrf.cloudfront.net/2015/eur/pdf/BRKSEC-3699.pdf" target="_blank"&gt;http://d2zmdbbm9feqrf.cloudfront.net/2015/eur/pdf/BRKSEC-3699.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BB&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 20:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417157#M547916</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-07-17T20:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between enabling Primary/Secondary in ISE and enabling failover</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417227#M547918</link>
      <description>&lt;P&gt;I had the same question once because I read about that exact scenario in an ISE book called "&lt;/P&gt;
&lt;H2 class="a-size-medium s-inline  s-access-title  a-text-normal" data-attribute="Practical Deployment of Cisco Identity Services Engine (ISE): Real-World Examples of AAA Deployments" data-max-rows="2"&gt;Practical Deployment of Cisco Identity Services Engine (ISE): Real-World Examples of AAA Deployments"&lt;/H2&gt;
&lt;P&gt;The author talks about this and it appears to make sense for hardware ISE nodes where you want to spread the work load between Active PAN and Active MnT.&amp;nbsp; Why make one node Active PAN and Active MnT, while the other node just sits around in Secondary mode?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when I asked this question to the Cisco TME's on the ISE Community Forum, they told me not to do what you're describing.&amp;nbsp; In other words, keep both the PAN and MnT personas Active on one node, and Standby on the other node.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 00:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417227#M547918</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-07-18T00:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between enabling Primary/Secondary in ISE and enabling failover</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417249#M547920</link>
      <description>&lt;P&gt;Thanks everyone for your suggestions but I think I have not made myself clear; so i will rephrase. My question was: Whats the difference between enabling failover between 2 devices/personas and&amp;nbsp;configuring primary/secondary between 2 devices/personas.&amp;nbsp; Which method is better?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 01:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417249#M547920</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2018-07-18T01:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between enabling Primary/Secondary in ISE and enabling failover</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417250#M547921</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks everyone for your suggestions but I think I have not made myself clear; so i will rephrase. My question was: Whats the difference between enabling failover between 2 devices/personas and&amp;nbsp;configuring primary/secondary between 2 devices/personas.&amp;nbsp; Which method is better?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 01:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417250#M547921</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2018-07-18T01:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between enabling Primary/Secondary in ISE and enabling failover</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417256#M548011</link>
      <description>&lt;P&gt;Just to be clear, I understand you have two nodes that have the Admin and Monitoring personas enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In that case there are two possible combinations&lt;/P&gt;
&lt;P&gt;Combo 1:&lt;/P&gt;
&lt;P&gt;Node 1: Primary Admin, &lt;FONT color="#00ff00"&gt;Primary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;Node 2: Secondary Admin, &lt;FONT color="#00ff00"&gt;Secondary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Combo 2&lt;/P&gt;
&lt;P&gt;Node 1: Primary Admin,&amp;nbsp;&lt;FONT color="#ff9900"&gt;Secondary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;Node 2: Secondary Admin,&lt;FONT color="#ff9900"&gt;&amp;nbsp;Primary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now your question is about failover?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no MnT failover as such, but as you probably know, you can promote the Secondary MnT to Primary and this will not cause any disturbance or changes to the PAN persona.&lt;/P&gt;
&lt;P&gt;The PAN is a bit different.&amp;nbsp; If you promote the Secondary PAN to Primary, then the application services will restart on both nodes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After a PAN promotion the result will be as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Combo 1: (no change to MnT)&lt;/P&gt;
&lt;P&gt;Node 1:&amp;nbsp;Secondary Admin, &lt;FONT color="#00ff00"&gt;Primary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;Node 2:&amp;nbsp;Primary Admin, &lt;FONT color="#00ff00"&gt;Secondary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Combo 2: (no change to MnT)&lt;/P&gt;
&lt;P&gt;Node 1:&amp;nbsp;Secondary Admin,&amp;nbsp;&lt;FONT color="#ff9900"&gt;Secondary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;Node 2:&amp;nbsp;Primary Admin,&lt;FONT color="#ff9900"&gt;&amp;nbsp;Primary&lt;/FONT&gt; MnT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't understand what the question is - there is no design choice (or considerations) as far as I can see. Unless I still haven't understood the question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By the way, what do you mean by "enable failover"?&amp;nbsp; Are you talking about Automatic PAN Failover?&amp;nbsp; As far as I know, it's just the automated way of doing the same thing as I described above.&amp;nbsp; You need an outside PSN (in your case) to be the monitors who decide when to trigger the promotion.&amp;nbsp; Is that what you're trying to achieve?&amp;nbsp; In that case the design question is, WHICH PSN do I designate to monitor which PAN node.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would argue that the PSN closest to the PAN (i.e. in same data centre) is the one to use because it would allow the PAN to be monitored in the event of an inter-data centre WAN failure.&amp;nbsp; If WAN link fails then there will be no PAN promotion since each PSN believes their PAN is alive.&amp;nbsp; If you chose the alternative, using cross-DC PSN monitors, then a WAN failure would cause the Standby PAN to be promoted, and you'll have two active PAN nodes with a split brain network.&amp;nbsp; This is to my knowledge how it would work - but I stand to be corrected.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 01:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-enabling-primary-secondary-in-ise-and/m-p/3417256#M548011</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-07-18T01:57:07Z</dc:date>
    </item>
  </channel>
</rss>

