<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Distributed ISE nodes and communication between PSNs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582155#M573752</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the following distributed ISE deployment:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A: 2x ADM, 2x MNT, 2x PSN&lt;/P&gt;&lt;P&gt;Site B: 2x PSN&lt;/P&gt;&lt;P&gt;Site C: 2x PSN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We opened the ports in the firewalls between Site A and Site B and between Site A and Site C so the PSN can reach the ADM and MNT nodes.&lt;/P&gt;&lt;P&gt;We have some errors in the ISE stating communication failure between the PSN of Site B and PSN of Site C.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do the PSN of Site B need to communicate with the PSN of Site C ?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 17:48:03 GMT</pubDate>
    <dc:creator>hervetram</dc:creator>
    <dc:date>2022-03-30T17:48:03Z</dc:date>
    <item>
      <title>Distributed ISE nodes and communication between PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582155#M573752</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the following distributed ISE deployment:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A: 2x ADM, 2x MNT, 2x PSN&lt;/P&gt;&lt;P&gt;Site B: 2x PSN&lt;/P&gt;&lt;P&gt;Site C: 2x PSN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We opened the ports in the firewalls between Site A and Site B and between Site A and Site C so the PSN can reach the ADM and MNT nodes.&lt;/P&gt;&lt;P&gt;We have some errors in the ISE stating communication failure between the PSN of Site B and PSN of Site C.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do the PSN of Site B need to communicate with the PSN of Site C ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582155#M573752</guid>
      <dc:creator>hervetram</dc:creator>
      <dc:date>2022-03-30T17:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed ISE nodes and communication between PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582174#M573753</link>
      <description>&lt;P&gt;Did you create a single "node group", with all PSNs assigned to it?&lt;/P&gt;&lt;P&gt;Such a scenario would explain the behaviour you see: PSNs share their active sessions with all members of the "node group"&lt;/P&gt;&lt;P&gt;If you have a single "node group", please consider creating a "node group" per site and only assign the PSNs for that site.&lt;/P&gt;&lt;P&gt;Please keep in mind that RADIUS session are shared within a "node group", PSNs of site A will have no knowledge about active sessions within site B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Hans&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 18:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582174#M573753</guid>
      <dc:creator>HansK_NL</dc:creator>
      <dc:date>2022-03-30T18:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed ISE nodes and communication between PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582186#M573755</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/502850"&gt;@hervetram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use this document as a guide of the ports and compare with your logs on firewall to check what traffic is the PSNs trying to establish: &lt;STRONG&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/InstallGuide27/b_ise_InstallationGuide27/b_ise_InstallationGuide27_chapter_0110.html" target="_self"&gt;Cisco ISE Ports Reference&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/916617"&gt;@HansK_NL&lt;/a&gt;&amp;nbsp;said, probably you have just one cluster configured and all PSN personas are trying to sync sessions.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jezer&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 18:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582186#M573755</guid>
      <dc:creator>tjezer</dc:creator>
      <dc:date>2022-03-30T18:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed ISE nodes and communication between PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582189#M573757</link>
      <description>&lt;P&gt;I did create a node group for each site when I added the nodes, so each node group contains only the 2 PSN of its site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 19:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-ise-nodes-and-communication-between-psns/m-p/4582189#M573757</guid>
      <dc:creator>hervetram</dc:creator>
      <dc:date>2022-03-30T19:04:23Z</dc:date>
    </item>
  </channel>
</rss>

