<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - Deployment question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682846#M577139</link>
    <description>&lt;P&gt;For any additional PSN you deploy (if virtual) you need to get a VM License (either VMS or VMC - see ordering guide).&lt;BR /&gt;It it not supported to go with 2x PSN, and 2x PSN,PAN,MNT. You need a medium deployment with separate PSN nodes from your PAN/MNT nodes. &lt;BR /&gt;See here: &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;BG&lt;BR /&gt;Rick&lt;/P&gt;</description>
    <pubDate>Wed, 07 Sep 2022 13:25:23 GMT</pubDate>
    <dc:creator>rschlayer</dc:creator>
    <dc:date>2022-09-07T13:25:23Z</dc:date>
    <item>
      <title>Cisco ISE - Deployment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682758#M577136</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a small question about the deployment of Cisco ISE.&lt;/P&gt;&lt;P&gt;Actually we are running a cluster of 2 members, each hosting PAN-MnT-PSN.&lt;/P&gt;&lt;P&gt;We want to extend the ISE functions to our "industrial network" separated by a DMZ.&lt;/P&gt;&lt;P&gt;To limit the trafic between the 2 zones, I would like to add one (or 2 for redundancy) server running only PSN server.&lt;/P&gt;&lt;P&gt;Is this kind of deployment allowed and supported by TAC ? If yes do I need a full ISE license or there are licenses to only run specific services of ISE ?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;Herve&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 10:45:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682758#M577136</guid>
      <dc:creator>hervej</dc:creator>
      <dc:date>2022-09-07T10:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Deployment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682818#M577138</link>
      <description>&lt;P&gt;You will need to move to the Medium deployment as mentioned here:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#Cisco_Concept.dita_67b428f0-2240-4383-bd49-5eb7a7b98a35" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#Cisco_Concept.dita_67b428f0-2240-4383-bd49-5eb7a7b98a35&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You will need the following to remain in a supported Topology:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;PAN + MnT&lt;/LI&gt;
&lt;LI&gt;PAN + MnT&lt;/LI&gt;
&lt;LI&gt;PSN&lt;/LI&gt;
&lt;LI&gt;PSN&lt;/LI&gt;
&lt;LI&gt;DMZ
&lt;UL&gt;
&lt;LI&gt;PSN&lt;/LI&gt;
&lt;LI&gt;PSN&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 07 Sep 2022 12:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682818#M577138</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-09-07T12:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Deployment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682846#M577139</link>
      <description>&lt;P&gt;For any additional PSN you deploy (if virtual) you need to get a VM License (either VMS or VMC - see ordering guide).&lt;BR /&gt;It it not supported to go with 2x PSN, and 2x PSN,PAN,MNT. You need a medium deployment with separate PSN nodes from your PAN/MNT nodes. &lt;BR /&gt;See here: &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;BG&lt;BR /&gt;Rick&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 13:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682846#M577139</guid>
      <dc:creator>rschlayer</dc:creator>
      <dc:date>2022-09-07T13:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Deployment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682868#M577142</link>
      <description>&lt;P&gt;Other question, does ISE support this:&lt;/P&gt;&lt;P&gt;OT network&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DMZ OT/IT&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IT Network&lt;/P&gt;&lt;P&gt;LDAP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2x PSN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2x PAN/MNT&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2x PSN&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; LDAP&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;OT network&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DMZ OT/IT&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IT Network&lt;/P&gt;&lt;P&gt;LDAP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2x PAN/MNT&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2x PSN&lt;BR /&gt;2x PSN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;LDAP&lt;/P&gt;&lt;P&gt;Does the PAN server need to contact LDAP in both zones (OT/IT) or just the PSE need to contact it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 14:13:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682868#M577142</guid>
      <dc:creator>hervej</dc:creator>
      <dc:date>2022-09-07T14:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Deployment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682877#M577143</link>
      <description>&lt;P&gt;Assuming LDAP means AD?&amp;nbsp; Then its best practice to have all ISE nodes joined to the domain so you can do RBAC login to ISE using AD.&amp;nbsp; If LDAP will strictly be for network authentication only (not AD or used for ISE admin login) then only the PSNs will need to talk to the LDAP server.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 14:37:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4682877#M577143</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-09-07T14:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Deployment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4683996#M577165</link>
      <description>&lt;P&gt;Indeed I mean AD and it's a different domain in IT and OT.&lt;/P&gt;&lt;P&gt;What would be the best practice in this case as we are using RBAC in the IT side ?&lt;/P&gt;&lt;P&gt;PAN/MnT server installed in DMZ (able to reach AD at both side), PSN in OT and IT zone reaching their "local" AD ?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 07:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4683996#M577165</guid>
      <dc:creator>hervej</dc:creator>
      <dc:date>2022-09-09T07:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Deployment question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4684266#M577174</link>
      <description>&lt;P&gt;You should integrate all ISE nodes with both ADs.&amp;nbsp; A properly configured AD sites and services would allow the ISE nodes to contact their local domain controllers.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 14:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment-question/m-p/4684266#M577174</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-09-09T14:35:09Z</dc:date>
    </item>
  </channel>
</rss>

