<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283240#M565137</link>
    <description>&lt;P&gt;The usual reason someone want's to run a three node deployment like this is so they can enable the automatic admin node failover. You have to be very careful when doing this, ensuring that every network device has the three nodes configured. When the PAN failover activates, the remaining admin node will also reload leaving just the third PSN online.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;While there is no official support for a three node deployment, it sits between a standalone (1-2 node) and Hybrid (4+ node), it does in fact work. Nothing will prevent you from doing this, but you do so knowing that "officially" it's not tested or supported. TAC will still provide support, but if you get in to troubleshooting performance or other odd issues, they might ask you to disable the third node as a troubleshooting step.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 05:05:21 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2021-02-01T05:05:21Z</dc:date>
    <item>
      <title>ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283120#M565128</link>
      <description>&lt;P&gt;In&amp;nbsp;ISE deployment I know that we can have two nodes acting as Admin P + Monitor S + PSN and Admin S + Monitor P + PSN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can separate roles by having two nodes run as admin + monitor then we can add up to 5 PSNs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case we have 3 nodes can run as the following ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin P + Monitor S + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin S + Monitor P + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 20:03:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283120#M565128</guid>
      <dc:creator>engahmedsaied</dc:creator>
      <dc:date>2021-01-31T20:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283125#M565129</link>
      <description>&lt;P&gt;You can mix nodes, but what kind of deployment is this and also need to consider the size of deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;some notes for reference :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 20:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283125#M565129</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-31T20:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283240#M565137</link>
      <description>&lt;P&gt;The usual reason someone want's to run a three node deployment like this is so they can enable the automatic admin node failover. You have to be very careful when doing this, ensuring that every network device has the three nodes configured. When the PAN failover activates, the remaining admin node will also reload leaving just the third PSN online.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;While there is no official support for a three node deployment, it sits between a standalone (1-2 node) and Hybrid (4+ node), it does in fact work. Nothing will prevent you from doing this, but you do so knowing that "officially" it's not tested or supported. TAC will still provide support, but if you get in to troubleshooting performance or other odd issues, they might ask you to disable the third node as a troubleshooting step.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 05:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283240#M565137</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-02-01T05:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283351#M565140</link>
      <description>&lt;P&gt;Yeah for automatic admin node failover instead of manual method but this a different scenario here&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the required, 3 nodes run as&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin P + Monitor S + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin S + Monitor P + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did not see this in Cisco documentation all about two nodes deployment or two nodes run as admin + monitor without PSN then you can add up to 5 PSNs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but in this way&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin P + Monitor S + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin S + Monitor P + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will there any issues ? performance, support tickets, ...&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 09:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283351#M565140</guid>
      <dc:creator>engahmedsaied</dc:creator>
      <dc:date>2021-02-01T09:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283444#M565142</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/179442"&gt;@engahmedsaied&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;take a look at the following post: &lt;A href="https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148" target="_blank" rel="noopener"&gt;ISE Performance &amp;amp; Scale&lt;/A&gt;. Check the &lt;STRONG&gt;ISE Architecture and Terminology (Hybrid Deployment).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: every &lt;STRONG&gt;ISE&lt;/STRONG&gt; deployment must have one &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt;, one &lt;STRONG&gt;Primary MnT&lt;/STRONG&gt; and at least one &lt;STRONG&gt;PSN&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 11:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283444#M565142</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-02-01T11:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283472#M565143</link>
      <description>&lt;P&gt;yes this is a nice document but what I am asking about is not listed there&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can this be done and supported ? or there issue will be related to this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case we have 3 nodes can run as the following ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin P + Monitor S + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin S + Monitor P + PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as I always use&amp;nbsp;&lt;STRONG&gt;Standalone / Dedicated Deployment ,&amp;nbsp;Hybrid / Medium Deployment or&amp;nbsp;Fully distributed / Dedicated deployment&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 12:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283472#M565143</guid>
      <dc:creator>engahmedsaied</dc:creator>
      <dc:date>2021-02-01T12:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283567#M565146</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/179442"&gt;@engahmedsaied&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;although it's possible to have &lt;STRONG&gt;3x Nodes&lt;/STRONG&gt; just like this:&lt;/P&gt;&lt;PRE&gt;Admin P + Monitor S + PSN&amp;nbsp;&lt;BR /&gt;Admin S + Monitor P + PSN&amp;nbsp;&lt;BR /&gt;PSN&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;the problem is ... how you will calculate the &lt;STRONG&gt;PSN - Maximum Concurrent Sessions&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;If you take a look at: &lt;A href="https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148" target="_blank" rel="noopener"&gt;ISE Performance &amp;amp; Scale&lt;/A&gt; - &lt;STRONG&gt;ISE PSN Performance&lt;/STRONG&gt; topic, there is a difference between a &lt;STRONG&gt;Standalone&lt;/STRONG&gt; vs &lt;STRONG&gt;Hybrid&lt;/STRONG&gt; deployment (in terms of &lt;STRONG&gt;Maximum Concurrent Sessions&lt;/STRONG&gt;) ... on the &lt;STRONG&gt;3x Nodes&lt;/STRONG&gt; case, you have a &lt;STRONG&gt;PSN&lt;/STRONG&gt; with a different load than the others that have Admin &amp;amp; Monitor service enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/4283567#M565146</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-02-01T14:15:49Z</dc:date>
    </item>
  </channel>
</rss>

