<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to design 3 Nodes ISE? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3350442#M549681</link>
    <description>&lt;P&gt;We have 3 ISE nodes license, Want to use 2 in Primary DC, with HA. and then use the 3rd one in the DR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IN Primary DC,&amp;nbsp; 1 is Primary for Admin, Policy and Monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2 is Secondary for Admin, Policy and Monitor&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then how to do with the 3rd one in DR?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:49:13 GMT</pubDate>
    <dc:creator>ccie14007</dc:creator>
    <dc:date>2020-02-21T18:49:13Z</dc:date>
    <item>
      <title>How to design 3 Nodes ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3350442#M549681</link>
      <description>&lt;P&gt;We have 3 ISE nodes license, Want to use 2 in Primary DC, with HA. and then use the 3rd one in the DR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IN Primary DC,&amp;nbsp; 1 is Primary for Admin, Policy and Monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2 is Secondary for Admin, Policy and Monitor&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then how to do with the 3rd one in DR?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3350442#M549681</guid>
      <dc:creator>ccie14007</dc:creator>
      <dc:date>2020-02-21T18:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to design 3 Nodes ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3350513#M549683</link>
      <description>Hi,&lt;BR /&gt;How many users/devices will it be supporting? What services - wired, wireless 802.1x? Guest portals? BYOD?.&lt;BR /&gt;&lt;BR /&gt;3 is an awkward number. How about this:&lt;BR /&gt;&lt;BR /&gt;1 - Primary PAN and MNT&lt;BR /&gt;2 - Secondary PAN and MNT + PSN&lt;BR /&gt;3 - PSN&lt;BR /&gt;&lt;BR /&gt;this leaves the first ISE node dedicated mgmt and provides redundancy for all personas.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Sun, 18 Mar 2018 16:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3350513#M549683</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-03-18T16:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to design 3 Nodes ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3350515#M549685</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp; By &lt;FONT color="#FF0000"&gt;not&lt;/FONT&gt; using such a model , use &lt;STRONG&gt;&lt;FONT color="#008000"&gt;standard&lt;/FONT&gt;&lt;/STRONG&gt; deploymens; 2 admin + monitor , +2 PSN =&lt;STRONG&gt; 4!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Mar 2018 17:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3350515#M549685</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2018-03-18T17:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to design 3 Nodes ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3351179#M549686</link>
      <description>&lt;P&gt;My 2 cents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-The ISE radius or tacacs servers&amp;nbsp;for authentication are the ones running PSN persona not PAN/MNT (admin nodes).&lt;/P&gt;
&lt;P&gt;-You should NOT combine multiple personas into the same appliance or VM. But if you have resources constrains then, you should ONLY have 1 primary PAN/MNT, 1 Secondary PAN/MNT and 1 PSN. But still, 1 PSN is&amp;nbsp;not enough because you need redundancy for authentication.&lt;/P&gt;
&lt;P&gt;-Running 3495 servers + 2 personas is NOT a good combination, I have seen performance issues so it is much better to run at least 3595.&lt;/P&gt;
&lt;P&gt;-At the end, you need minimum 4 appliances or VM's.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 20:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3351179#M549686</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-03-19T20:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to design 3 Nodes ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3352901#M549687</link>
      <description>&lt;P&gt;I've made this topology of our new ISE deployment. I'll be happy to receive any comments or suggestions for better planning, since I've properly missed something. The PSN in the top is deployed, IF the redundant links towards the DC's i disconnected.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 07:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3352901#M549687</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2018-03-22T07:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to design 3 Nodes ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3354798#M549689</link>
      <description>&lt;P&gt;Primary PAN+MnT and Secondary PAN+MnT with 3 x PSNs looks good&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would put all three PSNs in a nodegroup to provide redudancy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;happy to receive feedback on my thoughts&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 00:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-design-3-nodes-ise/m-p/3354798#M549689</guid>
      <dc:creator>paul46</dc:creator>
      <dc:date>2018-03-26T00:18:40Z</dc:date>
    </item>
  </channel>
</rss>

