<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can deploy Cisco ISE 2 Cluster  for VPN GW in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571467#M573489</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/207331"&gt;@jewfcb001&lt;/a&gt; I'm not really sure of the question here, but you can configure the VPN GW (either ASA or FTD) to use ISE cluster for aaa. If you have different ASA/FTD connection profiles/tunnels groups you could point these to different ISE clusters.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2022 10:35:21 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-03-16T10:35:21Z</dc:date>
    <item>
      <title>Can deploy Cisco ISE 2 Cluster  for VPN GW</title>
      <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571450#M573488</link>
      <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have plan to deploy Cisco ISE 2 Cluster and 2 Cluster&amp;nbsp; but configuration and internal user&amp;nbsp; it's same .&lt;/P&gt;&lt;P&gt;In Case Cisco ISE Clustuer-1 or Cluster 2&amp;nbsp; Fail All&amp;nbsp; , I'm not sure I facing issue about session struck or accounting stuck or not ?&amp;nbsp;The customer need to separate Group of Cisco ISE&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise-3.JPG" style="width: 402px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/146273i9C2410798FD50D46/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise-3.JPG" alt="ise-3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571450#M573488</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-03-16T10:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can deploy Cisco ISE 2 Cluster  for VPN GW</title>
      <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571467#M573489</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/207331"&gt;@jewfcb001&lt;/a&gt; I'm not really sure of the question here, but you can configure the VPN GW (either ASA or FTD) to use ISE cluster for aaa. If you have different ASA/FTD connection profiles/tunnels groups you could point these to different ISE clusters.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571467#M573489</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-16T10:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can deploy Cisco ISE 2 Cluster  for VPN GW</title>
      <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571478#M573490</link>
      <description>&lt;P&gt;as mentioned other post we are not clear what is the issue or what you trying to achive here :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;look some deployment guide can help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571478#M573490</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-16T10:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can deploy Cisco ISE 2 Cluster  for VPN GW</title>
      <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571480#M573491</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Rob . I mean&amp;nbsp; if I have tunnel-group and point to 4 ISE&amp;nbsp; (ISE 1.1.1.1 and 1.1.1.2 same cluster) and (ISE 2.1.1.1 and 2.1.1.2 same cluster) Incase ISE 1.1.1.1 and ISE 1.1.1.2 down . Can VPN gateway authentication to ise cluster-2 and do you have concern with my scenario ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;example&lt;/P&gt;&lt;P&gt;aaa-server ISE protocol radius&lt;BR /&gt;aaa-server ISE (inside) host 1.1.1.1&lt;BR /&gt;aaa-server ISE (inside) host 1.1.1.2&lt;/P&gt;&lt;P&gt;aaa-server ISE (inside) host 2.1.1.1&lt;/P&gt;&lt;P&gt;aaa-server ISE (inside) host 2.1.1.2&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571480#M573491</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-03-16T10:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can deploy Cisco ISE 2 Cluster  for VPN GW</title>
      <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571483#M573492</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi balaji ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as i explain Rob above .&amp;nbsp;&lt;SPAN&gt;Can VPN gateway authentication to ise cluster-2&amp;nbsp; incase ise 1.1.1.1 and ise 1.1.1.2 down. ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;example&lt;/P&gt;&lt;P&gt;aaa-server ISE protocol radius&lt;BR /&gt;aaa-server ISE (inside) host 1.1.1.1&lt;BR /&gt;aaa-server ISE (inside) host 1.1.1.2&lt;/P&gt;&lt;P&gt;aaa-server ISE (inside) host 2.1.1.1&lt;/P&gt;&lt;P&gt;aaa-server ISE (inside) host 2.1.1.2&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571483#M573492</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-03-16T10:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can deploy Cisco ISE 2 Cluster  for VPN GW</title>
      <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571486#M573493</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/207331"&gt;@jewfcb001&lt;/a&gt; 1 tunnel group pointing to 2 separate ISE clusters, that's not really a great idea in my opinion. You'd have to configure both ISE clusters independantly and there are chances of misconfiguration on one ISE cluster but not the other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could do what you suggested, but configuring the VPN gateway to authentication to 1 ISE cluster with 2 (or more) PSN nodes should be sufficient.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571486#M573493</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-16T10:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can deploy Cisco ISE 2 Cluster  for VPN GW</title>
      <link>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571493#M573494</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your information . I accept with you recommend but I get requirement from the customer . I don't understand this scenario from the customer. About&amp;nbsp;&lt;SPAN&gt;misconfiguration on one ISE cluster i try to tell the customer . He understand for this .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But if this scenario I can do but have any concern i will let him know. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 11:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-deploy-cisco-ise-2-cluster-for-vpn-gw/m-p/4571493#M573494</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-03-16T11:03:05Z</dc:date>
    </item>
  </channel>
</rss>

