<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE single PSN node down. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316588#M566535</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- &lt;FONT color="#993366"&gt;Monitoring PSN&lt;/FONT&gt; ? PSN normally denotes Policy Service Node and is critical , for more info :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010.html#typesofpersonas" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010.html#typesofpersonas&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Mar 2021 07:10:15 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2021-03-31T07:10:15Z</dc:date>
    <item>
      <title>ISE single PSN node down.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316565#M566533</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We are planning to deploy Cisco ISE with 3 node deployment (Primary PAN, Secondary PAN and monitoring PSN).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help in understanding, what will be the impact, if single monitoring PSN goes down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ashish Shah&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 06:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316565#M566533</guid>
      <dc:creator>rashish135@yahoo.co.in</dc:creator>
      <dc:date>2021-03-31T06:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE single PSN node down.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316588#M566535</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- &lt;FONT color="#993366"&gt;Monitoring PSN&lt;/FONT&gt; ? PSN normally denotes Policy Service Node and is critical , for more info :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010.html#typesofpersonas" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010.html#typesofpersonas&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316588#M566535</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-31T07:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE single PSN node down.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316592#M566536</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean what will be the impact of health check PSN goes down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3 node deployment&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Primary PAN, Secondary PAN and health check PSN.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316592#M566536</guid>
      <dc:creator>rashish135@yahoo.co.in</dc:creator>
      <dc:date>2021-03-31T07:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE single PSN node down.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316598#M566537</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- In general that kind of deployment type is discouraged, it is always better to have 2 PSN , which can then be configured&lt;/P&gt;
&lt;P&gt;as authenticators on the network devices resulting in &lt;STRONG&gt;fallback&lt;/STRONG&gt; and or &lt;U&gt;&lt;STRONG&gt;redundancy&lt;/STRONG&gt;&lt;/U&gt; when one PSN goes down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316598#M566537</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-31T07:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE single PSN node down.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316724#M566541</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;remember that ...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PAN&lt;/STRONG&gt; is the single pane of glass for &lt;STRONG&gt;ISE Admin&lt;/STRONG&gt; (interface to configure and view &lt;STRONG&gt;Policies&lt;/STRONG&gt;), it is the replication hub for all &lt;EM&gt;database config changes&lt;/EM&gt; (responsible for policy sync across &lt;STRONG&gt;Secondary PAN&lt;/STRONG&gt; and ALL &lt;STRONG&gt;PSNs&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PSN&lt;/STRONG&gt; is the&amp;nbsp;&lt;STRONG&gt;RADIUS/TACACS+ Server&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;in other words, if your &lt;U&gt;only&lt;/U&gt; &lt;STRONG&gt;PSN&lt;/STRONG&gt; goes down, then you loose your &lt;STRONG&gt;RADIUS/TACACS+ Server&lt;/STRONG&gt;, you have the option to use a&amp;nbsp;&lt;STRONG&gt;2x Nodes Deployment&lt;/STRONG&gt;:&lt;/P&gt;&lt;PRE&gt;1st Node: Primary PAN, Primary MnT and PSN 01&lt;BR /&gt;2nd Node: Secondary PAN, Secondary MnT and PSN 02&lt;/PRE&gt;&lt;P&gt;Note: the &lt;STRONG&gt;Health Check PSN&lt;/STRONG&gt; is used to automatically &lt;STRONG&gt;Promote&lt;/STRONG&gt; the &lt;STRONG&gt;Secondary PAN&lt;/STRONG&gt; to &lt;EM&gt;primary&lt;/EM&gt; if the &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt; goes down !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 11:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316724#M566541</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-31T11:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE single PSN node down.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316803#M566544</link>
      <description>&lt;P&gt;As Marce1000 mentioned, a three node deployment such as this is not an official tested/certified deployment methodology, but it can still work. I tend to see it deployed when companies understand the risk and still want automatic PAN failover to function.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;That said, if the third node, PSN in your case, goes down, the primary PAN and secondary PAN will not change. Losing the quorum decider aka health check node. If you were to also lose the primary PAN at the same time as the only health check node you have deployed, then it also won't failover. You wouldn't want this automatic promotion scenario anyways since reloading the only remaining node would result in a complete service outage. So if the primary PAN goes down, and the secondary and health check PSN stay up, then by default the promotion will begin after the p-pan has been down for 10 minutes. The secondary PAN will reload and come up as the primary in 10-15 minutes, the whole process takes 10 min down time + 10-15 for reload = 20-25 minutes.&lt;BR /&gt;&lt;BR /&gt;If you are going to use a three node deployment with PAN failover enabled, then ensure all three nodes are providing the PSN services, and every network device also has the three IP's configured for radius/tacacs. This prevents PAN reloads from causing a complete authentication outage.&amp;nbsp;&lt;BR /&gt;1x Pri-PAN/-Pri-MNT/PSN&lt;BR /&gt;1x Sec-PAN/Sec-MNT/PSN&lt;BR /&gt;1x PSN&lt;BR /&gt;&lt;BR /&gt;You can also read this admin guide section for what is available when the primary admin node is down, they have is broken in to a nice table.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_deployment.html#ID57" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_deployment.html#ID57&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 14:29:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4316803#M566544</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-03-31T14:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE single PSN node down.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4317149#M566560</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your valuable inputs. As you mentioned, we will be enabling PSN and MnT persona on Primary and secondary PAN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 04:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-psn-node-down/m-p/4317149#M566560</guid>
      <dc:creator>rashish135@yahoo.co.in</dc:creator>
      <dc:date>2021-04-01T04:35:57Z</dc:date>
    </item>
  </channel>
</rss>

