<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Cluster in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250492#M594381</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699"&gt;@GHOZLANE Haroun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-align-justify"&gt;Deployment&lt;/H2&gt;
&lt;P class="lia-align-justify"&gt;Please take a look at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_blank" rel="noopener"&gt;Performance and Scalability Guide for Cisco Identity Services Engine&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&lt;/STRONG&gt;, you can create a &lt;STRONG&gt;Medium Deployment&lt;/STRONG&gt;&amp;nbsp;- &lt;STRONG&gt;ISE Cluster&lt;/STRONG&gt; (search for&amp;nbsp;&lt;STRONG&gt;Different Types of Cisco ISE Deployment&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Datacenter01&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="lia-align-justify"&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: PPAN + SMnT&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: PSN (always active)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Datacenter02&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="lia-align-justify"&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 3&lt;/STRONG&gt;: SPAN + PMnT&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 4&lt;/STRONG&gt;: PSN (always active)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd&lt;/STRONG&gt;, for &lt;STRONG&gt;ISE Deployment Sizing&lt;/STRONG&gt; (search for &lt;STRONG&gt;Sizing Guidelines for ISE Deployment&lt;/STRONG&gt;),&amp;nbsp;you &lt;STRONG&gt;MUST&lt;/STRONG&gt; know the &lt;STRONG&gt;Maximum Concurrent Active Sessions&lt;/STRONG&gt; of your &lt;STRONG&gt;Deployment&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;This is an important number to create the correct &lt;STRONG&gt;SNS/VM&lt;/STRONG&gt; (search for&amp;nbsp;&lt;STRONG&gt;Cisco ISE Hardware Appliances&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-align-justify"&gt;Software&lt;/H2&gt;
&lt;P class="lia-align-justify"&gt;Please take a look at &lt;A href="https://cs.co/ise-software" target="_blank" rel="noopener"&gt;Cisco ISE Software Download&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&lt;/STRONG&gt;, today &lt;STRONG&gt;Cisco ISE Suggested Release&lt;/STRONG&gt; is &lt;STRONG&gt;ISE 3.3 Patch 4&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-align-justify"&gt;Load Balancer / NAD&lt;/H2&gt;
&lt;P class="lia-align-justify"&gt;If you have a &lt;STRONG&gt;Load Balancer&lt;/STRONG&gt;,&lt;/P&gt;
&lt;OL class="lia-align-justify"&gt;
&lt;LI class="lia-align-justify"&gt;then load balance your &lt;STRONG&gt;RADIUS Request&lt;/STRONG&gt; between &lt;STRONG&gt;Node 2&lt;/STRONG&gt; and &lt;STRONG&gt;Node 4&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;else manually point&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px lia-align-justify"&gt;&lt;U&gt; half of your &lt;STRONG&gt;NADs&lt;/STRONG&gt;&lt;/U&gt; to &lt;STRONG&gt;Node 2&lt;/STRONG&gt; as a &lt;STRONG&gt;Primary PSN&lt;/STRONG&gt; &amp;amp; &lt;STRONG&gt;Node 4&lt;/STRONG&gt; as a &lt;STRONG&gt;Secondary PSN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px lia-align-justify"&gt;&lt;U&gt;the other half&lt;/U&gt; to &lt;STRONG&gt;Node 4&lt;/STRONG&gt; as a &lt;STRONG&gt;Primary PSN&lt;/STRONG&gt; &amp;amp; &lt;STRONG&gt;Node 2&lt;/STRONG&gt; as a &lt;STRONG&gt;Secondary PSN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2025 22:13:44 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2025-01-21T22:13:44Z</dc:date>
    <item>
      <title>ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240738#M593948</link>
      <description>&lt;DIV class="flex max-w-full flex-col flex-grow"&gt;
&lt;DIV class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="663c72d2-8100-491c-a3a7-66ad42f5bd19" data-message-model-slug="gpt-4o"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;Can four ISE nodes be deployed across two clusters to ensure high availability between two data-centers with the following criteria :&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;-&amp;nbsp; An active cluster of 2 nodes in Datacenter 01.&lt;/P&gt;
&lt;P&gt;- A standby cluster of 2 nodes in Datacenter 02&lt;/P&gt;
&lt;P&gt;- Configuration synchronization between the two platforms.&lt;/P&gt;
&lt;P&gt;- Automatic failover in case of an issue with one of the datacenters.&lt;/P&gt;
&lt;DIV class="flex max-w-full flex-col flex-grow"&gt;
&lt;DIV class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="07473dc7-4ab6-4f07-abe1-479700df8590" data-message-model-slug="gpt-4o"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;As far as I know, the four nodes will be deployed within a single ISE distributed deployment, all configured with the active PSN role, and we will select two nodes to handle the PAN and MNT roles&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 25 Dec 2024 19:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240738#M593948</guid>
      <dc:creator>GHOZLANE Haroun</dc:creator>
      <dc:date>2024-12-25T19:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240741#M593949</link>
      <description>&lt;P&gt;Yes all these 4 nodes can be deployed in a single distributed deployment, make sure roundtrip latency between sites is under 300 ms, you can have few variations of deployment depending on how you want to distribute and scale,&amp;nbsp;&lt;SPAN&gt;table 4 has more details when deployed shared Vs standalone persona in the&amp;nbsp;&lt;/SPAN&gt;scalability &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_self"&gt;guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2024/pdf/BRKSEC-2091.pdf" target="_self"&gt;Here&lt;/A&gt; are some additional best practices to keep in mind&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2024 20:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5240741#M593949</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2024-12-25T20:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250258#M594357</link>
      <description>&lt;P&gt;Dear Ammahend,&lt;/P&gt;
&lt;P&gt;I would like to confirm the following setup for distributed deployment , 2 Nodes in each DC as bellow&amp;nbsp; :&lt;/P&gt;
&lt;P&gt;In Each DC, we will have two Nodes&amp;nbsp; as bellow:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - One Node with the PAN, MNT, and PSN roles.&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; A second Node dedicated to the PSN role.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;is this configuration good or it is mandatory to have pan &amp;amp; mnt nodes in one DC ?&lt;/P&gt;
&lt;P&gt;Additionally, could you clarify how the failover mechanism would work in case the link between two data centers goes down?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 15:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250258#M594357</guid>
      <dc:creator>GHOZLANE Haroun</dc:creator>
      <dc:date>2025-01-21T15:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250269#M594358</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699"&gt;@GHOZLANE Haroun&lt;/a&gt; What hardware have you purhcased or VM specs? How many concurrent sessions does the cluster need to support? &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#Cisco_Reference.dita_59d6eb45-48a9-422f-9369-d9e8c2dacb76" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#Cisco_Reference.dita_59d6eb45-48a9-422f-9369-d9e8c2dacb76&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Having the PAN/MNT roles in different DCs ensures you have resilency if one DC is unavailable.&lt;/P&gt;
&lt;P&gt;Automatic failover can be achieved using one of the PSNs as a health check node.&amp;nbsp;The health check node checks the health of the primary PAN at configured intervals. If the health check response received for the primary PAN is unreachable, the health check node initiates the promotion of the secondary PAN to take over the primary role &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3/b_ISE_admin_33_deployment.html#concept_6C3FA27523BC44FC8B7C56731997B71C" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3/b_ISE_admin_33_deployment.html#concept_6C3FA27523BC44FC8B7C56731997B71C&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You should also ensure that AD, DNS, NTP etc is also available in both DCs, as ISE relies on these for authentication.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 15:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250269#M594358</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-21T15:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250276#M594361</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex max-w-full flex-col flex-grow"&gt;
&lt;DIV class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="2cd9680c-7b9b-49fd-9dfb-1b971bcbf91d" data-message-model-slug="gpt-4o"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;Does it work as follows&amp;nbsp; ? :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I am planning to deploy 4 VM nodes across two data centers as follows:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;DC01&lt;/STRONG&gt;: Primary PAN (PPAN), Primary MNT (PMNT), PSN, and an additional PSN.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;DC02&lt;/STRONG&gt;: Secondary PAN (SPAN), Secondary MNT (SMNT), PSN, and an additional PSN.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If the link between the data centers goes down, each DC will operate independently with its own admin node. Once the link is restored, the system will revert to a single PAN managing both DCs.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Jan 2025 15:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250276#M594361</guid>
      <dc:creator>GHOZLANE Haroun</dc:creator>
      <dc:date>2025-01-21T15:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250287#M594362</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699"&gt;@GHOZLANE Haroun&lt;/a&gt; the health check node should be in the same DC as the node it's monitoring. The WAN must be up for health check to function correctly and failover, to avoid split brain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 16:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250287#M594362</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-21T16:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250492#M594381</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699"&gt;@GHOZLANE Haroun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-align-justify"&gt;Deployment&lt;/H2&gt;
&lt;P class="lia-align-justify"&gt;Please take a look at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_blank" rel="noopener"&gt;Performance and Scalability Guide for Cisco Identity Services Engine&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&lt;/STRONG&gt;, you can create a &lt;STRONG&gt;Medium Deployment&lt;/STRONG&gt;&amp;nbsp;- &lt;STRONG&gt;ISE Cluster&lt;/STRONG&gt; (search for&amp;nbsp;&lt;STRONG&gt;Different Types of Cisco ISE Deployment&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Datacenter01&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="lia-align-justify"&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;: PPAN + SMnT&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 2&lt;/STRONG&gt;: PSN (always active)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Datacenter02&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="lia-align-justify"&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 3&lt;/STRONG&gt;: SPAN + PMnT&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;&lt;STRONG&gt;Node 4&lt;/STRONG&gt;: PSN (always active)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd&lt;/STRONG&gt;, for &lt;STRONG&gt;ISE Deployment Sizing&lt;/STRONG&gt; (search for &lt;STRONG&gt;Sizing Guidelines for ISE Deployment&lt;/STRONG&gt;),&amp;nbsp;you &lt;STRONG&gt;MUST&lt;/STRONG&gt; know the &lt;STRONG&gt;Maximum Concurrent Active Sessions&lt;/STRONG&gt; of your &lt;STRONG&gt;Deployment&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;This is an important number to create the correct &lt;STRONG&gt;SNS/VM&lt;/STRONG&gt; (search for&amp;nbsp;&lt;STRONG&gt;Cisco ISE Hardware Appliances&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-align-justify"&gt;Software&lt;/H2&gt;
&lt;P class="lia-align-justify"&gt;Please take a look at &lt;A href="https://cs.co/ise-software" target="_blank" rel="noopener"&gt;Cisco ISE Software Download&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&lt;/STRONG&gt;, today &lt;STRONG&gt;Cisco ISE Suggested Release&lt;/STRONG&gt; is &lt;STRONG&gt;ISE 3.3 Patch 4&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-align-justify"&gt;Load Balancer / NAD&lt;/H2&gt;
&lt;P class="lia-align-justify"&gt;If you have a &lt;STRONG&gt;Load Balancer&lt;/STRONG&gt;,&lt;/P&gt;
&lt;OL class="lia-align-justify"&gt;
&lt;LI class="lia-align-justify"&gt;then load balance your &lt;STRONG&gt;RADIUS Request&lt;/STRONG&gt; between &lt;STRONG&gt;Node 2&lt;/STRONG&gt; and &lt;STRONG&gt;Node 4&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;else manually point&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px lia-align-justify"&gt;&lt;U&gt; half of your &lt;STRONG&gt;NADs&lt;/STRONG&gt;&lt;/U&gt; to &lt;STRONG&gt;Node 2&lt;/STRONG&gt; as a &lt;STRONG&gt;Primary PSN&lt;/STRONG&gt; &amp;amp; &lt;STRONG&gt;Node 4&lt;/STRONG&gt; as a &lt;STRONG&gt;Secondary PSN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px lia-align-justify"&gt;&lt;U&gt;the other half&lt;/U&gt; to &lt;STRONG&gt;Node 4&lt;/STRONG&gt; as a &lt;STRONG&gt;Primary PSN&lt;/STRONG&gt; &amp;amp; &lt;STRONG&gt;Node 2&lt;/STRONG&gt; as a &lt;STRONG&gt;Secondary PSN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 22:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250492#M594381</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-21T22:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250848#M594400</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks ,&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex max-w-full flex-col flex-grow"&gt;
&lt;DIV class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="e89e64d6-479f-4952-bddd-a45f0844e12a" data-message-model-slug="gpt-4o"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;&lt;SPAN&gt;How does failover work between &lt;STRONG&gt;No&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;de 1&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;Node 3&amp;nbsp;&lt;/STRONG&gt; if the link goes down?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; During the downtime, do will we have two distributed ISE nodes, and will both be manageable? Additionally, what happens when the link is restored?&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="flex max-w-full flex-col flex-grow"&gt;
&lt;DIV class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="46c80997-0062-41cc-9608-7c4cc66645ab" data-message-model-slug="gpt-4o"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;Is it mandatory to have two nodes dedicated to PAN and MNT roles?,&amp;nbsp; I intend to assign the PSN role to all four VM nodes.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Jan 2025 09:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250848#M594400</guid>
      <dc:creator>GHOZLANE Haroun</dc:creator>
      <dc:date>2025-01-22T09:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250969#M594404</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699"&gt;@GHOZLANE Haroun&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;about: "&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;Is it mandatory to have two nodes dedicated to PAN and MNT roles? ...&lt;/EM&gt; "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;STRONG&gt;PAN&lt;/STRONG&gt; and &lt;STRONG&gt;MnT&lt;/STRONG&gt; are important &lt;STRONG&gt;Roles&lt;/STRONG&gt;, that is why a &lt;STRONG&gt;PPAN/SPAN&lt;/STRONG&gt; and &lt;STRONG&gt;PMnT/SMnT&lt;/STRONG&gt; is a &lt;STRONG&gt;MUST&lt;/STRONG&gt; on a &lt;STRONG&gt;Small&lt;/STRONG&gt;, &lt;STRONG&gt;Medium&lt;/STRONG&gt; or &lt;STRONG&gt;Large Deployment&lt;/STRONG&gt; (please take a look at&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_blank" rel="noopener"&gt;Performance and Scalability Guide for Cisco Identity Services Engine&lt;/A&gt;, search for&amp;nbsp;&lt;STRONG&gt;Different Types of Cisco ISE Deployment&lt;/STRONG&gt;).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;about: "&lt;EM&gt; ...&amp;nbsp;During the downtime, do will we have two distributed ISE nodes, and will both be manageable? Additionally, what happens when the link is restored? ...&lt;/EM&gt; "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;If &lt;STRONG&gt;Datacenter02&lt;/STRONG&gt; is down,&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="lia-align-justify"&gt;you can use &lt;STRONG&gt;PPAN&lt;/STRONG&gt; at &lt;STRONG&gt;Node 1&lt;/STRONG&gt; for &lt;STRONG&gt;Administration&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;you can use &lt;STRONG&gt;PSN&lt;/STRONG&gt; at &lt;STRONG&gt;Node 2&lt;/STRONG&gt; for &lt;STRONG&gt;RADIUS Request&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;If &lt;STRONG&gt;Datacenter01&lt;/STRONG&gt;&amp;nbsp;is down,&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="lia-align-justify"&gt;you can &lt;U&gt;manually&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;Promote&lt;/STRONG&gt; the&amp;nbsp;&lt;STRONG&gt;SPAN&lt;/STRONG&gt; at &lt;STRONG&gt;Node 3&lt;/STRONG&gt;&amp;nbsp;for &lt;STRONG&gt;Administration&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Promote to Primary.png" style="width: 787px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238197i2357436F1C5BC9E6/image-dimensions/787x369?v=v2" width="787" height="369" role="button" title="Promote to Primary.png" alt="Promote to Primary.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="lia-align-justify"&gt;you can use &lt;STRONG&gt;PSN&lt;/STRONG&gt; at &lt;STRONG&gt;Node 4&lt;/STRONG&gt;&amp;nbsp;for &lt;STRONG&gt;RADIUS Request&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;about "&lt;EM&gt; ...&amp;nbsp;How does failover work between&amp;nbsp;&lt;STRONG&gt;No&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;de 1&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;Node 3&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;if the link goes down? ...&lt;/EM&gt; "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;PPAN&lt;/STRONG&gt; and &lt;STRONG&gt;SPAN&lt;/STRONG&gt; will &lt;U&gt;automatically synchronize&lt;/U&gt; (you can also you the &lt;STRONG&gt;SyncUp&lt;/STRONG&gt; option):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Syncup.png" style="width: 800px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238198i5D03765B5E79378B/image-dimensions/800x312?v=v2" width="800" height="312" role="button" title="Syncup.png" alt="Syncup.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Hope this helps !!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 13:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250969#M594404</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-22T13:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250979#M594406</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks very much for awsome clarifications&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex max-w-full flex-col flex-grow"&gt;
&lt;DIV class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="e6e61d87-4091-4872-9b0b-df40543eeda1" data-message-model-slug="gpt-4o"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;Is it possible to assign the PSN role to all four VM nodes, with two of them also serving as PAN and MNT.&lt;/P&gt;
&lt;P&gt;My goal is to have two PSN nodes for each data center, with one node in each data center acting as PAN, MNT, and PSN, while the second node is dedicated to PSN&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 13:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5250979#M594406</guid>
      <dc:creator>GHOZLANE Haroun</dc:creator>
      <dc:date>2025-01-22T13:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5251070#M594413</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699"&gt;@GHOZLANE Haroun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, it's possible to assign a &lt;STRONG&gt;PSN Role&lt;/STRONG&gt; to a &lt;STRONG&gt;PAN &amp;amp; MnT Node&lt;/STRONG&gt;, it's considered a &lt;STRONG&gt;Shared PSN&lt;/STRONG&gt; and not a &lt;STRONG&gt;Dedicated PSN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: remember that, if your&amp;nbsp;&lt;STRONG&gt;Hardware/VM&lt;/STRONG&gt; is compatible with a &lt;STRONG&gt;SNS 3655&lt;/STRONG&gt;, then &lt;U&gt;each&lt;/U&gt; &lt;STRONG&gt;Dedicated PSN&lt;/STRONG&gt; is capable of handle &lt;U&gt;up to&lt;/U&gt; &lt;STRONG&gt;50K Concurrent Active Sessions&lt;/STRONG&gt;., in other words, double check if you really need a &lt;STRONG&gt;PSN Role&lt;/STRONG&gt; into the &lt;STRONG&gt;PAN &amp;amp; MnT Node&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 10:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5251070#M594413</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-23T10:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5252563#M594481</link>
      <description>&lt;P&gt;Nothing wroing with having the PSN services running on the same node where you also have the administration and monitoring services, actually it is quite common to have a deployment like that.&lt;/P&gt;
&lt;P&gt;Here is my take on the auto-failover, this will only be applicable to the administration services and I think it will depend on how you configure it if it will be triggered or not. For instance, if the configured failover monitoring node is sitting in DC1 then I don't believe the failover will happen in that case, because from that&amp;nbsp;failover monitoring node perspective the primary PAN will still be available. In this scenario you wouldn't be able to manage the nodes sitting in DC2.&lt;/P&gt;
&lt;P&gt;However, if the configured failover monitoring node is sitting in DC2 and the link between DC1 and 2 goes down, then I think the failover will happen because that&amp;nbsp;failover monitoring node will not be able to reach the primary PAN and it will instruct the secondary PAN to become the primary. I think in this scenario you would have a split-brain deployment because you would have the primary PAN in DC1 and the new primary PAN in DC2.&lt;/P&gt;
&lt;P&gt;Although I think you could manage the nodes in DC1 via the PAN in DC1 and the nodes in DC2 via the PAN in DC2 there is a caveat here which is that there is no preemption with ISE auto-failover. This means that even when the link between the two DCs is restored the new PAN in DC2 will remain as is. I'm not sure if in that case the primary PAN in DC1 would be automatically demoted.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 12:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5252563#M594481</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-25T12:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5252699#M594491</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;I have a new deployment I'm testing with with two 3795's in two different DC's.&amp;nbsp; I have one in each running PAN, PMNT and the other a PSN, then other DC I have one running SAN, SMNT and PSN.&amp;nbsp; I did have the one node in each running all personas for a few months.&amp;nbsp; Our production has 20 nodes and the PAN/MNT are dedicated nodes and are located in a different DC than the SAN and MNT. I didn't like the auto-failover, because I wanted to be able to control which was the PAN.&amp;nbsp; Like what the others have already mentioned, it's possible to do, but you need to also look at the various types of failures. Node failure, traffic to a specific DC, failure between the DC and maybe AD, etc.&amp;nbsp; That way you have a grasp of what can happen in various situations.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 20:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cluster/m-p/5252699#M594491</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-01-25T20:41:23Z</dc:date>
    </item>
  </channel>
</rss>

