<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Cluster in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240829#M593952</link>
    <description>&lt;P&gt;As far as I know you cannot sync two differnt ISE deployments.&lt;/P&gt;
&lt;P&gt;Is this setup the result of a M&amp;amp;A? If so you should be looking into adapting the 2nd deployment policies in your primary one and merge all the PSN's at the end. If this is something you want to have on a fresh deployment, the best way to go is to have a distributes ISE deployment with PPAN and PMNT at DC#1, and SPAN and SMNT at DC#2 and then enable Automatic Failover on the deployment (If you also have a DNS' load balance technology enble it for the ISE admin portal resolution to point to the good one under the failover scenario)&lt;/P&gt;</description>
    <pubDate>Thu, 26 Dec 2024 07:35:51 GMT</pubDate>
    <dc:creator>JPavonM</dc:creator>
    <dc:date>2024-12-26T07:35:51Z</dc:date>
    <item>
      <title>ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240814#M593951</link>
      <description>&lt;P&gt;Can four ISE nodes be deployed across two clusters to ensure high availability between two data-centers with the following criteria :&lt;/P&gt;&lt;P&gt;- An active cluster of 2 nodes in Datacenter 01.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://www.smart-squarehmh.com" target="_self"&gt;&lt;FONT size="1 2 3 4 5 6 7" color="#FFFFFF"&gt;Click Here&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- A standby cluster of 2 nodes in Datacenter 02&lt;/P&gt;&lt;P&gt;- Configuration synchronization between the two platforms.&lt;/P&gt;&lt;P&gt;- Automatic failover in case of an issue with one of the datacenters.&lt;/P&gt;&lt;P&gt;As far as I know, the four nodes will be deployed within a single ISE distributed deployment, all configured with the active PSN role, and we will select two nodes to handle the PAN and MNT roles&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2024 06:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240814#M593951</guid>
      <dc:creator>bella964hadid</dc:creator>
      <dc:date>2024-12-26T06:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240829#M593952</link>
      <description>&lt;P&gt;As far as I know you cannot sync two differnt ISE deployments.&lt;/P&gt;
&lt;P&gt;Is this setup the result of a M&amp;amp;A? If so you should be looking into adapting the 2nd deployment policies in your primary one and merge all the PSN's at the end. If this is something you want to have on a fresh deployment, the best way to go is to have a distributes ISE deployment with PPAN and PMNT at DC#1, and SPAN and SMNT at DC#2 and then enable Automatic Failover on the deployment (If you also have a DNS' load balance technology enble it for the ISE admin portal resolution to point to the good one under the failover scenario)&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2024 07:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240829#M593952</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-12-26T07:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240870#M593953</link>
      <description>&lt;P&gt;I would assume that this requirement came from a misunderstanding of the way an ISE deployment works. I you want the redunduncy that this requirement implies, you can build one deployment with two servers each in DC1 and DC2. The servers in DC1 would run primary PAN and MNT, the two servers in DC2 would run secondary PAN and MNT. Depending on the load all four could run PSN or the PSNs are separated to other nodes.&lt;/P&gt;
&lt;P&gt;For the automatic failover, I just assume that you are mainly interested in RADIUS/TACACS failover. But that is a NAD functionality firsthand.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2024 10:32:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240870#M593953</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2024-12-26T10:32:21Z</dc:date>
    </item>
  </channel>
</rss>

