<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about ISE HA Deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281926#M565107</link>
    <description>&lt;P&gt;Thanks, Marcelo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know about scenario:&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, Device Admin Service&lt;/PRE&gt;&lt;P&gt;but can be&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, &lt;STRONG&gt;No&lt;/STRONG&gt; Device Admin Service&lt;/PRE&gt;&lt;P&gt;w/o Device Admin for HA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, Device Admin Service&lt;/PRE&gt;&lt;P&gt;with only one license&amp;nbsp;&lt;STRONG&gt;L-ISE-TACACS-ND= ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 04:43:17 GMT</pubDate>
    <dc:creator>Andrey Ageev</dc:creator>
    <dc:date>2021-01-29T04:43:17Z</dc:date>
    <item>
      <title>Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281272#M565079</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two ISE nodes:&lt;/P&gt;&lt;P&gt;Node 1: Primary PAN, Secondary MnT, PSN, Device Admin (TACACS) +&amp;nbsp;L-ISE-TACACS-ND=&lt;/P&gt;&lt;P&gt;Node 2: Secondary PAN, Primary MnT, (w/o Device Admin and w/o&amp;nbsp;L-ISE-TACACS-ND=)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So&amp;nbsp;&lt;SPAN&gt;am I thinking correctly what's it not HA deployment because 2-nd node doesn't have Device Admin role?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And in case of primary node down - secondary will not working properly for TACACS/RADIUS requests and first it should be promoted to Primary and after that Device Admin role must be set up?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's correct that minimal requirements for HA is two&amp;nbsp;L-ISE-TACACS-ND=&amp;nbsp;licenses? So both nodes will have Device Admin role?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 11:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281272#M565079</guid>
      <dc:creator>Andrey Ageev</dc:creator>
      <dc:date>2021-01-28T11:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281285#M565081</link>
      <description>&lt;P&gt;If you add the license to the deployment and assign the role to the second node, it will perform the device admin functions fine even if the primary node is down.&lt;/P&gt;
&lt;P&gt;You would only need to promote it to primary if the primary node was down for an extended period and you needed to modify configuration or if the primary had to be replaced altogether due to failure.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 11:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281285#M565081</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-01-28T11:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281517#M565091</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/297049"&gt;@Andrey Ageev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;first of all ... you are able to &lt;STRONG&gt;Promote&lt;/STRONG&gt; the &lt;STRONG&gt;Secondary PAN&lt;/STRONG&gt; or &lt;STRONG&gt;Secondary MnT&lt;/STRONG&gt; to &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt; or &lt;STRONG&gt;Primary MnT&lt;/STRONG&gt; (respectively), this is one thing !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Second ... to enable &lt;STRONG&gt;TACACS+&lt;/STRONG&gt;&amp;nbsp;on &lt;STRONG&gt;ISE&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;. you need the &lt;STRONG&gt;L-ISE-TACACS-ND=&lt;/STRONG&gt; license.&lt;/P&gt;&lt;P&gt;. you need to check the&amp;nbsp;&lt;STRONG&gt;Enable Device Admin Service&lt;/STRONG&gt; on &lt;U&gt;each&lt;/U&gt; &lt;STRONG&gt;PSN&lt;/STRONG&gt; in the deployment (for &lt;STRONG&gt;HA&lt;/STRONG&gt; of &lt;STRONG&gt;TACACS+&lt;/STRONG&gt; service)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words:&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, Device Admin Service&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281517#M565091</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-01-28T16:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281803#M565105</link>
      <description>&lt;P&gt;It's important to note that if you were to promote the secondary admin node to primary in a two node deployment, even if both nodes were healthy and online, this is still an outage. Swapping the MNT primary/secondary role is not impacting, it does not require a service reload. If you swap the admin node, both admin nodes need to restart their application services which includes the services providing authentication.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;To Marvin's point, purchase a second device admin node license, enable the device admin on the second node, and you do not have to swap the primary/secondary to maintain TACACS authentication functionality. You would have to delay any configuration changes until you can get the existing primary back online or take an outage to swap the primary role.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 23:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281803#M565105</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-01-28T23:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281924#M565106</link>
      <description>&lt;P&gt;So i need two licenses (L-ISE-TACACS-ND), right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With only one license on Primary and Device Admin checked on both nodes i have this message:&amp;nbsp;fewer device admin licenses installed than device admin nodes deployed.&amp;nbsp;But AAA on second ISE work fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it normal&amp;nbsp;behaviour for ISE and means that i can work with only license?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What&amp;nbsp;are the risks then working with only one?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 04:41:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281924#M565106</guid>
      <dc:creator>Andrey Ageev</dc:creator>
      <dc:date>2021-01-29T04:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281926#M565107</link>
      <description>&lt;P&gt;Thanks, Marcelo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know about scenario:&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, Device Admin Service&lt;/PRE&gt;&lt;P&gt;but can be&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, &lt;STRONG&gt;No&lt;/STRONG&gt; Device Admin Service&lt;/PRE&gt;&lt;P&gt;w/o Device Admin for HA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, Device Admin Service&lt;/PRE&gt;&lt;P&gt;with only one license&amp;nbsp;&lt;STRONG&gt;L-ISE-TACACS-ND= ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 04:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4281926#M565107</guid>
      <dc:creator>Andrey Ageev</dc:creator>
      <dc:date>2021-01-29T04:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4282052#M565111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/297049"&gt;@Andrey Ageev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;the &lt;U&gt;old&lt;/U&gt; &lt;STRONG&gt;Device Admin&lt;/STRONG&gt;&amp;nbsp;license was for the whole deployment, but ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Now, for each &lt;STRONG&gt;PSN&amp;nbsp;&lt;/STRONG&gt; that you check the&amp;nbsp;&lt;STRONG&gt;Enable Device Admin Service&lt;/STRONG&gt;,&amp;nbsp;you need the&amp;nbsp;&lt;STRONG&gt;L-ISE-TACACS-ND=&lt;/STRONG&gt;&amp;nbsp;license, in other words, as soon as you have &lt;U&gt;one box&lt;/U&gt; for &lt;STRONG&gt;TACACS &lt;/STRONG&gt;and&amp;nbsp;&lt;U&gt;another&lt;/U&gt; for &lt;STRONG&gt;HA&lt;/STRONG&gt;, then you would need &lt;U&gt;two licenses&lt;/U&gt;&amp;nbsp;for the deployment.:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service (&lt;SPAN&gt;&lt;STRONG&gt;L-ISE-TACACS-ND=&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, Device Admin Service (&lt;SPAN&gt;&lt;STRONG&gt;L-ISE-TACACS-ND=&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note: you don't have &lt;STRONG&gt;HA&lt;/STRONG&gt; (for &lt;STRONG&gt;TACACS&lt;/STRONG&gt;) on the scenario bellow:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 10:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4282052#M565111</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-01-29T10:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE HA Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4284187#M565179</link>
      <description>&lt;P&gt;Thanks to all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last qustions: should i have&amp;nbsp;L-ISE-BSE-PLIC (Cisco ISE Base License) and&amp;nbsp;L-ISE-BSE-P1 (Cisco ISE Base License - Sessions 100 to 249) for second node for HA for also RADUIS, not only TACACS, in this configuration:&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: Primary PAN  , Secondary MnT, Session Service, Device Admin Service (&lt;SPAN&gt;&lt;STRONG&gt;L-ISE-TACACS-ND=&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: Secondary PAN, Primary MnT  , Session Service, Device Admin Service (&lt;SPAN&gt;&lt;STRONG&gt;L-ISE-TACACS-ND=&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 09:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-ha-deployment/m-p/4284187#M565179</guid>
      <dc:creator>Andrey Ageev</dc:creator>
      <dc:date>2021-02-02T09:52:53Z</dc:date>
    </item>
  </channel>
</rss>

