<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/4611234#M574823</link>
    <description>&lt;P&gt;We have two ISE primary and Secondary. Want to create a HA between them. if primary ISE goes down does secondary ISE run all services that were running on Primary ISE?&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2022 04:58:27 GMT</pubDate>
    <dc:creator>bilal.atif</dc:creator>
    <dc:date>2022-05-17T04:58:27Z</dc:date>
    <item>
      <title>Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/4611234#M574823</link>
      <description>&lt;P&gt;We have two ISE primary and Secondary. Want to create a HA between them. if primary ISE goes down does secondary ISE run all services that were running on Primary ISE?&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 04:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/4611234#M574823</guid>
      <dc:creator>bilal.atif</dc:creator>
      <dc:date>2022-05-17T04:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/4611258#M574824</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1346193"&gt;@bilal.atif&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes this is a classic 2-node deployment where each ISE Node will run Admin, Monitoring and Services.&lt;/P&gt;
&lt;P&gt;The ISE HA ensures that the primary admin node (the one you log into the GUI) synchronises its config database with the other node. If Primary ISE node fails, then Secondary is a hot-standby. You have to manually promote the Standby node to log into the GUI to configure/view things - but the RADIUS/TACACS+/Web services will already be running same as the other node.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="inherit"&gt;The NAD's (Switch/WLC/VPN) needs to have both ISE nodes configured as AAA servers and they &lt;/FONT&gt;will&lt;FONT face="inherit"&gt;&amp;nbsp;decide which server to use (based on things like health probes, dead timers etc.)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 06:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise/m-p/4611258#M574824</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-05-17T06:10:12Z</dc:date>
    </item>
  </channel>
</rss>

