<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE HA behavior if both nodes lost connection to each other? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ha-behavior-if-both-nodes-lost-connection-to-each/m-p/4477265#M570035</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/804751"&gt;@jj2048&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;1st&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;PSN&lt;/STRONG&gt; will work even if &lt;STRONG&gt;PAN&lt;/STRONG&gt; (&lt;STRONG&gt;Primary&lt;/STRONG&gt; and/or&amp;nbsp;&lt;STRONG&gt;Secondary&lt;/STRONG&gt;) is down !!!&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Note: special attention for the following bug: &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvu62938" target="_blank" rel="noopener"&gt;CSCvu62938 Posture fails when primary PSN/PAN are unreachable&lt;/A&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;2nd&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;All &lt;STRONG&gt;PSNs&lt;/STRONG&gt; will send their logging data to the &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; as &lt;STRONG&gt;Syslog Messages&lt;/STRONG&gt; (&lt;STRONG&gt;UDP port 20514&lt;/STRONG&gt;).&lt;/P&gt;&lt;P class="lia-align-justify"&gt;When there are two &lt;STRONG&gt;MnT Nodes&lt;/STRONG&gt;, all &lt;STRONG&gt;ISE Nodes&lt;/STRONG&gt; send their &lt;U&gt;audit data&lt;/U&gt; to both &lt;STRONG&gt;MnT Nodes&lt;/STRONG&gt; at the same time.&lt;BR /&gt;Upon an &lt;STRONG&gt;MnT&lt;/STRONG&gt; &lt;U&gt;failure&lt;/U&gt;, all &lt;STRONG&gt;Nodes&lt;/STRONG&gt; continue to send logs to the &lt;U&gt;remaining&lt;/U&gt; &lt;STRONG&gt;MnT Node&lt;/STRONG&gt;. Therefore, &lt;U&gt;no logs are lost&lt;/U&gt;. The &lt;STRONG&gt;PAN&lt;/STRONG&gt; retrieves &lt;U&gt;ALL log and report data from the remaining&lt;/U&gt; &lt;STRONG&gt;MnT Node&lt;/STRONG&gt;, so there is no administrative function loss, either. However, the &lt;U&gt;log database is not synchronized&lt;/U&gt; between the &lt;STRONG&gt;Primary&lt;/STRONG&gt; and &lt;STRONG&gt;Secondary MnT Nodes&lt;/STRONG&gt;. Therefore, when the &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; returns to service, a &lt;U&gt;backup and restore&lt;/U&gt; of the &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; is &lt;U&gt;required&lt;/U&gt; to keep the two &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; in complete sync.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;3rd&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Automatic Failover&lt;/STRONG&gt; (to &lt;U&gt;promote&lt;/U&gt; the &lt;STRONG&gt;Secondary PAN&lt;/STRONG&gt; to &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt;) requires a &lt;STRONG&gt;Non-Administration Secondary Node&lt;/STRONG&gt;, called a &lt;STRONG&gt;Health Check Node&lt;/STRONG&gt;. This &lt;STRONG&gt;Node&lt;/STRONG&gt; checks the health of &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt;. If the health detects that the &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt; is &lt;U&gt;down or unreachable&lt;/U&gt;, the &lt;STRONG&gt;Health Check Node&lt;/STRONG&gt; initiates the &lt;U&gt;promotion&lt;/U&gt; of the &lt;STRONG&gt;Secondary PAN&lt;/STRONG&gt; to take over the &lt;U&gt;primary role&lt;/U&gt;. To deploy the &lt;STRONG&gt;Automatic Failover&lt;/STRONG&gt; feature, you &lt;U&gt;&lt;STRONG&gt;MUST&lt;/STRONG&gt;&lt;/U&gt; have &lt;U&gt;at least three&lt;/U&gt; &lt;STRONG&gt;Nodes&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Wed, 29 Sep 2021 22:39:38 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-09-29T22:39:38Z</dc:date>
    <item>
      <title>Cisco ISE HA behavior if both nodes lost connection to each other?</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ha-behavior-if-both-nodes-lost-connection-to-each/m-p/4477247#M570033</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Full Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;What is the behavior of Cisco ISE in HA when both nodes lost connectivity with each other but both nodes are still up?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Scenario:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Let's say that Cisco ISE standalone are both installed on two sites A and B. Suddenly the connection between A (ISE-A) and B (ISE-B) are cut off, but both Nodes are still up.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;1. What is the expected behavior when this occurs?&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;-Will ISE services such as tacacs/radius both work with respect to each site?&lt;/P&gt;&lt;P&gt;-Will we be unable to monitor (radius/tacacs live logs) the authentications on Site B (ISE-B) only or both sites? (Refer to Assumption 1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Assumptions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1. ISE-A (Primary Admin, Secondary MnT, PSN Active)&lt;/P&gt;&lt;P&gt;2. ISE-B (Secondary Admin, Primary MnT, PSN Active)&lt;/P&gt;&lt;P&gt;3. Site A Network Devices are radius/tacacs pointed to ISE-A as primary and ISE-B as secondary&lt;/P&gt;&lt;P&gt;4. Site B Network Devices&amp;nbsp;are radius/tacacs pointed to ISE-B as primary and ISE-A as secondary&lt;/P&gt;&lt;P&gt;5. Site A and B both have dedicated AD/DNS servers, and are still reachable on both ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate any feedback or additional comments.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 21:39:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ha-behavior-if-both-nodes-lost-connection-to-each/m-p/4477247#M570033</guid>
      <dc:creator>jj2048</dc:creator>
      <dc:date>2021-09-29T21:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE HA behavior if both nodes lost connection to each other?</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ha-behavior-if-both-nodes-lost-connection-to-each/m-p/4477265#M570035</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/804751"&gt;@jj2048&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;1st&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;PSN&lt;/STRONG&gt; will work even if &lt;STRONG&gt;PAN&lt;/STRONG&gt; (&lt;STRONG&gt;Primary&lt;/STRONG&gt; and/or&amp;nbsp;&lt;STRONG&gt;Secondary&lt;/STRONG&gt;) is down !!!&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Note: special attention for the following bug: &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvu62938" target="_blank" rel="noopener"&gt;CSCvu62938 Posture fails when primary PSN/PAN are unreachable&lt;/A&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;2nd&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;All &lt;STRONG&gt;PSNs&lt;/STRONG&gt; will send their logging data to the &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; as &lt;STRONG&gt;Syslog Messages&lt;/STRONG&gt; (&lt;STRONG&gt;UDP port 20514&lt;/STRONG&gt;).&lt;/P&gt;&lt;P class="lia-align-justify"&gt;When there are two &lt;STRONG&gt;MnT Nodes&lt;/STRONG&gt;, all &lt;STRONG&gt;ISE Nodes&lt;/STRONG&gt; send their &lt;U&gt;audit data&lt;/U&gt; to both &lt;STRONG&gt;MnT Nodes&lt;/STRONG&gt; at the same time.&lt;BR /&gt;Upon an &lt;STRONG&gt;MnT&lt;/STRONG&gt; &lt;U&gt;failure&lt;/U&gt;, all &lt;STRONG&gt;Nodes&lt;/STRONG&gt; continue to send logs to the &lt;U&gt;remaining&lt;/U&gt; &lt;STRONG&gt;MnT Node&lt;/STRONG&gt;. Therefore, &lt;U&gt;no logs are lost&lt;/U&gt;. The &lt;STRONG&gt;PAN&lt;/STRONG&gt; retrieves &lt;U&gt;ALL log and report data from the remaining&lt;/U&gt; &lt;STRONG&gt;MnT Node&lt;/STRONG&gt;, so there is no administrative function loss, either. However, the &lt;U&gt;log database is not synchronized&lt;/U&gt; between the &lt;STRONG&gt;Primary&lt;/STRONG&gt; and &lt;STRONG&gt;Secondary MnT Nodes&lt;/STRONG&gt;. Therefore, when the &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; returns to service, a &lt;U&gt;backup and restore&lt;/U&gt; of the &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; is &lt;U&gt;required&lt;/U&gt; to keep the two &lt;STRONG&gt;MnT Node&lt;/STRONG&gt; in complete sync.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;3rd&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Automatic Failover&lt;/STRONG&gt; (to &lt;U&gt;promote&lt;/U&gt; the &lt;STRONG&gt;Secondary PAN&lt;/STRONG&gt; to &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt;) requires a &lt;STRONG&gt;Non-Administration Secondary Node&lt;/STRONG&gt;, called a &lt;STRONG&gt;Health Check Node&lt;/STRONG&gt;. This &lt;STRONG&gt;Node&lt;/STRONG&gt; checks the health of &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt;. If the health detects that the &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt; is &lt;U&gt;down or unreachable&lt;/U&gt;, the &lt;STRONG&gt;Health Check Node&lt;/STRONG&gt; initiates the &lt;U&gt;promotion&lt;/U&gt; of the &lt;STRONG&gt;Secondary PAN&lt;/STRONG&gt; to take over the &lt;U&gt;primary role&lt;/U&gt;. To deploy the &lt;STRONG&gt;Automatic Failover&lt;/STRONG&gt; feature, you &lt;U&gt;&lt;STRONG&gt;MUST&lt;/STRONG&gt;&lt;/U&gt; have &lt;U&gt;at least three&lt;/U&gt; &lt;STRONG&gt;Nodes&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 22:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ha-behavior-if-both-nodes-lost-connection-to-each/m-p/4477265#M570035</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-09-29T22:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE HA behavior if both nodes lost connection to each other?</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ha-behavior-if-both-nodes-lost-connection-to-each/m-p/4477300#M570041</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This helps a lot! Very informative and made me understand it better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 00:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ha-behavior-if-both-nodes-lost-connection-to-each/m-p/4477300#M570041</guid>
      <dc:creator>jj2048</dc:creator>
      <dc:date>2021-09-30T00:26:02Z</dc:date>
    </item>
  </channel>
</rss>

