<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius server fall back for 802.1X SSID in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-server-fall-back-for-802-1x-ssid/m-p/5337937#M598507</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have only 2 ISE nodes configured as PAN and PSN's, and both are running only Wired and wireless Dot1x with PEAP-MSCHAPv2.&lt;/P&gt;
&lt;P&gt;I have C9800 controller and AP's in Flex mode, also Meraki MR Access points both are integrated with ISE for user authentications.&lt;/P&gt;
&lt;P&gt;My question is how can i ensure services to continue incase my both ISE servers are down.&lt;/P&gt;
&lt;P&gt;Both Platforms are enabled with Do1x on SSID's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 13 Oct 2025 09:52:29 GMT</pubDate>
    <dc:creator>Mateen Ahmad</dc:creator>
    <dc:date>2025-10-13T09:52:29Z</dc:date>
    <item>
      <title>Radius server fall back for 802.1X SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-server-fall-back-for-802-1x-ssid/m-p/5337937#M598507</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have only 2 ISE nodes configured as PAN and PSN's, and both are running only Wired and wireless Dot1x with PEAP-MSCHAPv2.&lt;/P&gt;
&lt;P&gt;I have C9800 controller and AP's in Flex mode, also Meraki MR Access points both are integrated with ISE for user authentications.&lt;/P&gt;
&lt;P&gt;My question is how can i ensure services to continue incase my both ISE servers are down.&lt;/P&gt;
&lt;P&gt;Both Platforms are enabled with Do1x on SSID's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 09:52:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-server-fall-back-for-802-1x-ssid/m-p/5337937#M598507</guid>
      <dc:creator>Mateen Ahmad</dc:creator>
      <dc:date>2025-10-13T09:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Radius server fall back for 802.1X SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-server-fall-back-for-802-1x-ssid/m-p/5337985#M598510</link>
      <description>&lt;P&gt;You need to configure your ISE deployment for high availability.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/install_guide/b_ise_installationGuide32/b_ise_InstallationGuide32_chapter_1.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/install_guide/b_ise_installationGuide32/b_ise_InstallationGuide32_chapter_1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 12:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-server-fall-back-for-802-1x-ssid/m-p/5337985#M598510</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-10-13T12:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Radius server fall back for 802.1X SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-server-fall-back-for-802-1x-ssid/m-p/5338137#M598515</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp; - you need to ensure that at least one ISE is always alive, and that the wireless NAD devices (Meraki, C9800 etc.) have both ISE IPs configured. If you have total ISE failure, then wireless 802.1X will fail - I am not aware of a "fail open" mechanism for wireless 802.1X.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the wired side, you can implement clever critical auth mechanisms on Cisco Catalysts switches using IBNS 1.0 and IBNS 2.0&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 21:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-server-fall-back-for-802-1x-ssid/m-p/5338137#M598515</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-10-13T21:22:03Z</dc:date>
    </item>
  </channel>
</rss>

