<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MNT nodes failover question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mnt-nodes-failover-question/m-p/4187309#M563935</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I understood logs between MNT nodes are not synchronized. They work as active/active. All nodes in the deployment send logs to MNT nodes simultaneously. When Primary MNT goes down PAN switches to Secondary MNT and reads logs from it. Now only Secondary MNT receives logs and when Primary MNT goes up PAN switches back to Primary MNT automatically and does not see logs that happened when Primary MNT was down. The only solution to keep the log database identical is to backup operational data from Secondary MNT (with full logs) and restores it to Primary MNT. But restoring operational data causes stop services on the Primary MNT node so it will miss logs again during the restore. So what the way to keep the log database identical on the MNT nodes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Nov 2020 09:58:21 GMT</pubDate>
    <dc:creator>alyautdinov</dc:creator>
    <dc:date>2020-11-23T09:58:21Z</dc:date>
    <item>
      <title>MNT nodes failover question</title>
      <link>https://community.cisco.com/t5/network-access-control/mnt-nodes-failover-question/m-p/4187309#M563935</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I understood logs between MNT nodes are not synchronized. They work as active/active. All nodes in the deployment send logs to MNT nodes simultaneously. When Primary MNT goes down PAN switches to Secondary MNT and reads logs from it. Now only Secondary MNT receives logs and when Primary MNT goes up PAN switches back to Primary MNT automatically and does not see logs that happened when Primary MNT was down. The only solution to keep the log database identical is to backup operational data from Secondary MNT (with full logs) and restores it to Primary MNT. But restoring operational data causes stop services on the Primary MNT node so it will miss logs again during the restore. So what the way to keep the log database identical on the MNT nodes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 09:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mnt-nodes-failover-question/m-p/4187309#M563935</guid>
      <dc:creator>alyautdinov</dc:creator>
      <dc:date>2020-11-23T09:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: MNT nodes failover question</title>
      <link>https://community.cisco.com/t5/network-access-control/mnt-nodes-failover-question/m-p/4187333#M563937</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Why do you want to restore MNT logs on other nodes. PAN will have full&lt;BR /&gt;visibility on all MNT nodes and parse their logs. What are you trying to&lt;BR /&gt;achieve with this?&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Mon, 23 Nov 2020 09:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mnt-nodes-failover-question/m-p/4187333#M563937</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-23T09:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: MNT nodes failover question</title>
      <link>https://community.cisco.com/t5/network-access-control/mnt-nodes-failover-question/m-p/4187385#M563939</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I do not want to restore MNT logs on the other nodes only between Primary and Secondary MNT nodes to keep the log database identical.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the book SISE 300-715:&lt;/P&gt;&lt;P class="p1"&gt;"Upon an MnT failure, all nodes continue to send logs to the remaining MnT node so that no logs are lost. The PAN retrieves all logs and reports data from the secondary MnT node, so there is no administrative function loss, either. However, the log database is not synchronized between the primary and secondary MnT nodes; therefore, when the MnT node returns to service, a backup and restore of the monitoring node is required to keep the two MnT nodes in complete synchronization."&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 09:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mnt-nodes-failover-question/m-p/4187385#M563939</guid>
      <dc:creator>alyautdinov</dc:creator>
      <dc:date>2020-11-23T09:56:07Z</dc:date>
    </item>
  </channel>
</rss>

