<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Just so we are clear, ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/utilizing-psn-node-groups-in-multiple-datacenters/m-p/2730319#M57520</link>
    <description>&lt;P&gt;Just so we are clear, ISE node groups does not do load-balancing, you need an external load-balancer for this. If you are in fact using a load-balancer for each DC, then you could just manually have half of your switches use one vip for primary and one for secondary, and the other half reversed. Also, if you use aaa server groups in your switch, you can also do local switch "load-balancing", based on how many active session are on each radius server in the group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_rad/configuration/15-sy/sec-usr-rad-15-sy-book/sec-rad-load-bal.html#GUID-EAADC56D-9634-49B9-A3DF-06932A3DCA1E&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2015 16:46:55 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2015-09-18T16:46:55Z</dc:date>
    <item>
      <title>Utilizing PSN node groups in multiple datacenters</title>
      <link>https://community.cisco.com/t5/network-access-control/utilizing-psn-node-groups-in-multiple-datacenters/m-p/2730318#M57519</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I was looking for some information, I am setting up a Distributed Deployment of ISE.&amp;nbsp;&amp;nbsp; We have two data center each will have its own PSN Node group (load balanced), I need a strategy where we can make sure that all NADs are not pointing to one PSN node group.&amp;nbsp; In the switch config I only see the option of listing the radius server where the first one listed is referenced and secondary IP is only used if the primary Radius server is not available.&amp;nbsp; We have many branch sites that we would like deploy ISE, we would like to distribute the Radius AuthC/AuthZ evenly between the two DC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;-Amin&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/utilizing-psn-node-groups-in-multiple-datacenters/m-p/2730318#M57519</guid>
      <dc:creator>amohammed01</dc:creator>
      <dc:date>2019-03-11T06:04:09Z</dc:date>
    </item>
    <item>
      <title>Just so we are clear, ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/utilizing-psn-node-groups-in-multiple-datacenters/m-p/2730319#M57520</link>
      <description>&lt;P&gt;Just so we are clear, ISE node groups does not do load-balancing, you need an external load-balancer for this. If you are in fact using a load-balancer for each DC, then you could just manually have half of your switches use one vip for primary and one for secondary, and the other half reversed. Also, if you use aaa server groups in your switch, you can also do local switch "load-balancing", based on how many active session are on each radius server in the group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_rad/configuration/15-sy/sec-usr-rad-15-sy-book/sec-rad-load-bal.html#GUID-EAADC56D-9634-49B9-A3DF-06932A3DCA1E&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 16:46:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/utilizing-psn-node-groups-in-multiple-datacenters/m-p/2730319#M57520</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-09-18T16:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Just so we are clear, ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/utilizing-psn-node-groups-in-multiple-datacenters/m-p/4018668#M57521</link>
      <description>&lt;P&gt;For Correction the statment :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you use aaa server groups in your switch, you can also do local switch "load-balancing", based on how many active session are on each radius server in the group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;aaa server groups in your switch,&amp;nbsp; it does&amp;nbsp; not do a function of Load balancer- the function is that all the session will hit first PSN&amp;nbsp; &amp;nbsp;and Second PSN will work as Backup for&amp;nbsp; radius Requests&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 10:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/utilizing-psn-node-groups-in-multiple-datacenters/m-p/4018668#M57521</guid>
      <dc:creator>aasaadsavola</dc:creator>
      <dc:date>2020-01-27T10:25:39Z</dc:date>
    </item>
  </channel>
</rss>

