<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling secondary MnT Role and Syncing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294243#M565581</link>
    <description>&lt;P&gt;Hello Marcelo, thanks as usual.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2021 11:23:44 GMT</pubDate>
    <dc:creator>Americo Massotti</dc:creator>
    <dc:date>2021-02-19T11:23:44Z</dc:date>
    <item>
      <title>Enabling secondary MnT Role and Syncing</title>
      <link>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294226#M565578</link>
      <description>&lt;P&gt;Hello everybody.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment I have a cluster with only a MnT Primary role on the secondary Pan.&lt;/P&gt;&lt;P&gt;I would enable it also on the Primary Pan as Secondary MnT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering if after enable it and the Primary Pan restarted the services, it sync automatically with the MnT Primary/Secondary Pan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's true?&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Americo&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 10:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294226#M565578</guid>
      <dc:creator>Americo Massotti</dc:creator>
      <dc:date>2021-02-19T10:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling secondary MnT Role and Syncing</title>
      <link>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294236#M565580</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/491474"&gt;@Americo Massotti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;yes, you are correct, it syncs automatically.&lt;/P&gt;&lt;P&gt;&amp;nbsp;You can use the following command:&lt;/P&gt;&lt;PRE&gt;show application status ise&lt;/PRE&gt;&lt;P&gt;and take a look at the following process when you activate the &lt;STRONG&gt;Sec MnT&lt;/STRONG&gt; .. from &lt;EM&gt;disabled&lt;/EM&gt; to &lt;EM&gt;running&lt;/EM&gt;:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;M&amp;amp;T Session Database&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;M&amp;amp;T Log Processor&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 11:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294236#M565580</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-02-19T11:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling secondary MnT Role and Syncing</title>
      <link>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294243#M565581</link>
      <description>&lt;P&gt;Hello Marcelo, thanks as usual.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 11:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294243#M565581</guid>
      <dc:creator>Americo Massotti</dc:creator>
      <dc:date>2021-02-19T11:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling secondary MnT Role and Syncing</title>
      <link>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294455#M565588</link>
      <description>&lt;P&gt;There is also a method to check if the sync it's over?&lt;/P&gt;&lt;P&gt;From the deployment status I'm not seeing anything about the sync process&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 17:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294455#M565588</guid>
      <dc:creator>Americo Massotti</dc:creator>
      <dc:date>2021-02-19T17:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling secondary MnT Role and Syncing</title>
      <link>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294493#M565589</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/491474"&gt;@Americo Massotti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;yes, on &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Deployment&lt;/STRONG&gt;, take a look at the &lt;STRONG&gt;Node Status&lt;/STRONG&gt; icon and the icon marked bellow:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DEPLOYMENT.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104721i77D3A973E2F16388/image-size/large?v=v2&amp;amp;px=999" role="button" title="DEPLOYMENT.png" alt="DEPLOYMENT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 18:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294493#M565589</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-02-19T18:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling secondary MnT Role and Syncing</title>
      <link>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294572#M565593</link>
      <description>&lt;P&gt;There are two things to consider here.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The primary PAN will coordinate and replicate configuration and endpoint attributes with all of the nodes in the deployment. This is the "Sync" status you see in the deployment view.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The two MNT nodes do not sync or replicate data between each other. Each MNT node maintains a unique copy of the RADIUS and TACACS logs sent to it. PSN nodes send two identical logs to each MNT for storage and reporting, these databases are not synced.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Enabling the MNT role on the other node starts the MNT log collection from zero. While you can backup the operation logs from the existing MNT, and restore them to the new MNT, I do not recommend doing this unless there is some specific need. By default the MNTs store 30 days of logs, after a month, both nodes will have the same 30 days of logs barring some kind of problem with the deployment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 22:56:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enabling-secondary-mnt-role-and-syncing/m-p/4294572#M565593</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-02-19T22:56:17Z</dc:date>
    </item>
  </channel>
</rss>

