<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rebooting multiple ISE nodes - what's the quickest yet safe sequen in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4445768#M568909</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1230989"&gt;@SanahGrat&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;just to add one piece of information beyond what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;said ...&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;About &lt;STRONG&gt;Posture&lt;/STRONG&gt; ... take a look at:&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu62938" target="_blank" rel="noopener"&gt;CSCvu62938 Posture fails when primary PSN/PAN are unreachable&lt;/A&gt;. (solved on &lt;STRONG&gt;ISE 3.0 P3&lt;/STRONG&gt;, &lt;STRONG&gt;ISE 2.7 P4&lt;/STRONG&gt; and &lt;STRONG&gt;ISE 2.6 P9&lt;/STRONG&gt;).&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Sat, 07 Aug 2021 05:09:54 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-08-07T05:09:54Z</dc:date>
    <item>
      <title>Rebooting multiple ISE nodes - what's the quickest yet safe sequence?</title>
      <link>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4444359#M568872</link>
      <description>&lt;DIV class="_3xX726aBn29LDbsDtzr_6E _1Ap4F5maDtT1E1YuCiaO0r D3IL3FD0RFy_mkKLPwL4"&gt;&lt;DIV class="_292iotee39Lmt0MkQZ2hPV RichTextJSON-root"&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I had to reboot our 2 ISE VMs recently. TAC has said to just be sure I leave one node up so there are still services available. They always say this. I never get a really clear answer to my question.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have been rebooting the secondary node, making sure there are no pending sync operations, then promoting secondary to primary, then rebooting the now secondary node. This way I am always rebooting the secondary node. This takes a LONG time but seems like the safest way to go. My question is, is this really necessary? Is it safe to reboot the primary without doing the promotion routine? Do the nodes sort out the details/sync if I reboot the primary leaving only the secondary up?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 04 Aug 2021 17:19:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4444359#M568872</guid>
      <dc:creator>SanahGrat</dc:creator>
      <dc:date>2021-08-04T17:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Rebooting multiple ISE nodes - what's the quickest yet safe sequen</title>
      <link>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4444450#M568873</link>
      <description>&lt;P&gt;May something miss understood here :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what TAC saying, when you reboot Secondary - the Primary still service and Active. when the Secondary come back - promote that as Primary that means (secondary become active here)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is promote example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bluenetsec.com/promote-ise-secondary-pan-to-become-the-primary/" target="_blank"&gt;https://bluenetsec.com/promote-ise-secondary-pan-to-become-the-primary/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when the Secondary become primary,&amp;nbsp; (primary become secondary, so you rebooting secondary for safe )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this will have no impact on services. Once Secondary (original Primary back only) you can promote this as Primary to leave as it is all up to the business decision.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(in other way what you said correct, you reboot secondary all time - but you rebooting both ISE- with out any service impact)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;not sure what reason you rebooting by TAC suggestion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 19:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4444450#M568873</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-04T19:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Rebooting multiple ISE nodes - what's the quickest yet safe sequen</title>
      <link>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4445732#M568900</link>
      <description>&lt;P&gt;With only 2 ISE nodes, you only want to reboot only 1 at a time because otherwise you will lose &lt;EM&gt;&lt;STRONG&gt;all&lt;/STRONG&gt;&lt;/EM&gt; ISE services (network access outage!) for 15-20 minutes while both nodes reboot simultaneously. This is why TAC &lt;EM&gt;always&lt;/EM&gt; says this. It is Good Advice.&lt;/P&gt;
&lt;P&gt;To answer your question, you need to think about the multiple personas that each node performs: PAN+MNT+PSN. When you reboot the Primary, you are losing half of your PSN (RADIUS/TACACS) capacity but you are also losing your Primary PAN which performs some critical functions beside configuration. Read the &lt;STRONG&gt;ISE Administration Guide&lt;/STRONG&gt; section &lt;STRONG&gt;High Availability for the Administrative Node&lt;/STRONG&gt; to understand what functions are down while the Primary PAN reboots:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-08-06 at 3.57.09 PM.png" style="width: 635px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/127365i33FA839596D46DB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-08-06 at 3.57.09 PM.png" alt="Screen Shot 2021-08-06 at 3.57.09 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you cannot live without these services for the 15-20 minutes that the Primary PAN reboots, you will want to take the necessary steps and time to perform the Primary node election! This is the &lt;EM&gt;recommended&lt;/EM&gt; and "safest way to go" as you said. &lt;/P&gt;
&lt;P&gt;That leaves the MNT persona. Read the &lt;STRONG&gt;ISE Administration Guide&lt;/STRONG&gt; section&amp;nbsp;&lt;STRONG&gt;Automatic Failover in MnT Nodes&lt;/STRONG&gt; . You will effectively lose the logging data from the PSNs while the MNT was down/rebooting - which is also a PSN in your small deployment. To get that period of logging data back, do a backup from the secondary:&lt;/P&gt;
&lt;DIV class="page" title="Page 113"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'TimesNewRomanPSMT';"&gt;When the primary node comes back up after a failover, obtain a backup of the secondary and restore the data to update the primary node. &lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Aug 2021 23:21:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4445732#M568900</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-08-06T23:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Rebooting multiple ISE nodes - what's the quickest yet safe sequen</title>
      <link>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4445768#M568909</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1230989"&gt;@SanahGrat&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;just to add one piece of information beyond what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;said ...&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;About &lt;STRONG&gt;Posture&lt;/STRONG&gt; ... take a look at:&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu62938" target="_blank" rel="noopener"&gt;CSCvu62938 Posture fails when primary PSN/PAN are unreachable&lt;/A&gt;. (solved on &lt;STRONG&gt;ISE 3.0 P3&lt;/STRONG&gt;, &lt;STRONG&gt;ISE 2.7 P4&lt;/STRONG&gt; and &lt;STRONG&gt;ISE 2.6 P9&lt;/STRONG&gt;).&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 05:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rebooting-multiple-ise-nodes-what-s-the-quickest-yet-safe/m-p/4445768#M568909</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-08-07T05:09:54Z</dc:date>
    </item>
  </channel>
</rss>

