<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - HA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047981#M558977</link>
    <description>&lt;P&gt;You can delete the node.&amp;nbsp; its like same sitatuation think as if one of the node fails, ISE Group shiftover traffic to other available nodes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is some referenec guide :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html#wp1134272" target="_blank"&gt;https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html#wp1134272&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2020 12:11:12 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-03-18T12:11:12Z</dc:date>
    <item>
      <title>ISE - HA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047942#M558974</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some advice if possible, we're licensed for 4 small ISE servers and someone ages ago installed a 5th and didn't get it licensed properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I need to turn one off until we get funds to pay for a 5th and I cant decide which one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup is as follows:&lt;/P&gt;&lt;P&gt;x2 PAN servers in HA&lt;/P&gt;&lt;P&gt;x2 PSN servers in HA&lt;/P&gt;&lt;P&gt;x1 PSN server in DMZ for guest portal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE is just used for Radius for wifi (so clients can connect) and guest portal for visitors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm thinking I turn off and deregister (?) one of the PSN servers but is that the safest one to do??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 10:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047942#M558974</guid>
      <dc:creator>KingTech1</dc:creator>
      <dc:date>2020-03-18T10:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - HA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047951#M558975</link>
      <description>&lt;P&gt;If the system isn't heavily loaded then you could add the PSN role to one of the PAN/MnT nodes and decommission one dedicated PSN (the one that's listed second in your network access devices). It's not strictly a best practices design but will work functionally and make your licensing compliant.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 11:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047951#M558975</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-18T11:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - HA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047954#M558976</link>
      <description>&lt;P&gt;Thanks for this, great idea.&amp;nbsp; None of the servers are heavily used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You dont by chance know what steps do I need to follow to get rid a of a PSN server from ISE?&amp;nbsp; I dont think just turning it off will cut it.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 11:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047954#M558976</guid>
      <dc:creator>KingTech1</dc:creator>
      <dc:date>2020-03-18T11:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - HA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047981#M558977</link>
      <description>&lt;P&gt;You can delete the node.&amp;nbsp; its like same sitatuation think as if one of the node fails, ISE Group shiftover traffic to other available nodes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is some referenec guide :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html#wp1134272" target="_blank"&gt;https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html#wp1134272&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 12:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047981#M558977</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-03-18T12:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - HA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047985#M558978</link>
      <description>&lt;P&gt;Deregister the node from the deployment first - then you can safely shut it down. Here is the section of the Admin Guide telling you the detailed steps:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_011.html#ID665" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_011.html#ID665&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 12:23:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha/m-p/4047985#M558978</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-18T12:23:35Z</dc:date>
    </item>
  </channel>
</rss>

