<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE distributed deploy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931887#M584326</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Guys, I am a bit puzzled about this. I have implemented 2 ISE nodes in&amp;nbsp; Simple Two Node Deployment. Each node holds all personas. If I split it up, Ise03 holds, Admin and MnT, and Ise02 holds PSN personas, It still works, and clients gets AuthZ. NAD tacacs+ also works,&amp;nbsp; however the live logs are empty? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Both servers has certifcate from MS AD, NTP are in sync, and DNS records are in place.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards Kasper&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 30 Sep 2023 08:43:18 GMT</pubDate>
    <dc:creator>Kasper Elsborg</dc:creator>
    <dc:date>2023-09-30T08:43:18Z</dc:date>
    <item>
      <title>ISE distributed deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931887#M584326</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Guys, I am a bit puzzled about this. I have implemented 2 ISE nodes in&amp;nbsp; Simple Two Node Deployment. Each node holds all personas. If I split it up, Ise03 holds, Admin and MnT, and Ise02 holds PSN personas, It still works, and clients gets AuthZ. NAD tacacs+ also works,&amp;nbsp; however the live logs are empty? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Both servers has certifcate from MS AD, NTP are in sync, and DNS records are in place.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards Kasper&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 08:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931887#M584326</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2023-09-30T08:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931892#M584327</link>
      <description>&lt;P&gt;what version of ISE - I am bit confused here, you mentioned 2 Node deployment, do you have 3rd node admin and Mnt ?&lt;/P&gt;
&lt;P&gt;The Live Logs you looking hope&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;Operations &amp;gt; TACACS &amp;gt; Live Logs&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;what switch model ? (may be run some debug and check is the logs shipping to ISE)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 09:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931892#M584327</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-09-30T09:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931938#M584330</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt; First it's a test lab that I have running. The deployment was as described ISE02, and ISE03, holding all personas, PSN, MnT and Admin. Everythin works, Radius, and Tacacs, and there are logs in both Operation-&amp;gt;live logs, and operations-&amp;gt;tacacs-&amp;gt;livelogs. and ofcause my policy sets get hits. Then I split deployment up, and ISE03 now only has admin and MnT, and ISE02 now only has PSN. Everything works like before. Clients get dot1x authZ and there are hits in the policies, Tacacs works, however now there are no logs in any of the live logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE &lt;SPAN&gt;3.1.0.518&lt;/SPAN&gt; patch 7&lt;/P&gt;
&lt;P&gt;Switch is a WS-C3650-48PD&lt;/P&gt;
&lt;P&gt;Br. Kasper&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 13:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931938#M584330</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2023-09-30T13:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931971#M584331</link>
      <description>&lt;P&gt;Hi, So I've disabled the "&lt;SPAN&gt;Use "ISE Messaging Service" for UDP Syslogs delivery to MnT" and then I have livelogs again. Then I reissued certificates for&amp;nbsp;ISE Messaging Service on both node, but using the pxgrid template(it has both server and client). Reenabled the&amp;nbsp;ISE Messaging Service" for UDP Syslogs delivery to MnT, and now it works.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KasperElsborg_0-1696093732331.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/198508i36B7ECE2461C5E42/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KasperElsborg_0-1696093732331.png" alt="KasperElsborg_0-1696093732331.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 17:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931971#M584331</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2023-09-30T17:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deploy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931986#M584332</link>
      <description>&lt;P&gt;glad to know all working, cheers for sharing your solution.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 18:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deploy/m-p/4931986#M584332</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-09-30T18:02:21Z</dc:date>
    </item>
  </channel>
</rss>

