<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE HA-Mode (Control Webgui) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346364#M598932</link>
    <description>&lt;P&gt;You need to enable all nodes where required for the device admin service; this does not require a restart of ISE.&lt;/P&gt;
&lt;P&gt;Only PAN will be able to manage all the nodes in the deployment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Nov 2025 07:55:02 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2025-11-12T07:55:02Z</dc:date>
    <item>
      <title>ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346313#M598928</link>
      <description>&lt;P&gt;Dear professionals,&lt;/P&gt;&lt;P&gt;We have two Cisco ISE (Primary-Secondary)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Xibachao1_3-1762920904783.png" style="width: 704px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255071i500903DDF94D2991/image-dimensions/704x57?v=v2" width="704" height="57" role="button" title="Xibachao1_3-1762920904783.png" alt="Xibachao1_3-1762920904783.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We have concern about Device Admin Services. What is it purpose? We have research about it, seem likes relate to Tacas service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In webgui ise-primary we can control all function like Livelogs, Cert, Endpoint .... but in webgui ise-secondary just have only Administration tab. We wonder it is relate to Device Admin service which the one missing in the ise-secondary?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Xibachao1_4-1762921211480.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255072iE58769C7707193C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Xibachao1_4-1762921211480.png" alt="Xibachao1_4-1762921211480.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone explain this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 04:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346313#M598928</guid>
      <dc:creator>Xibachao1</dc:creator>
      <dc:date>2025-11-12T04:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346360#M598929</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1854286"&gt;@Xibachao1&lt;/a&gt;&amp;nbsp;Yes, Device Admin is for TACACS+ management of networking devices.&amp;nbsp;It looks like you just need to enable Device Admin on the secondary node. From the Primary Policy Administration Node (PAN) go to Administration &amp;gt; Deployment edit the Secondary node and select &lt;STRONG&gt;Enable Device Admin Service.&lt;/STRONG&gt; Click &lt;STRONG&gt;Save&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;An a distributed deployment only the PAN will display all the tabs, as the configuration is performed centrally on the Primary PAN, which is why you will not see all the tabs on the other node(s).&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 07:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346360#M598929</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-11-12T07:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346361#M598930</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank for you support.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wonder one more if i do enable that config have any require reboot or something downtime?&lt;/P&gt;&lt;P&gt;And how can i manage all the tabs in the SPAN (Must over 3 nodes or it is impossible please tell me) ?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 07:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346361#M598930</guid>
      <dc:creator>Xibachao1</dc:creator>
      <dc:date>2025-11-12T07:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346363#M598931</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1854286"&gt;@Xibachao1&lt;/a&gt;&amp;nbsp;enabling the Device Admin service won't require a reboot.&lt;/P&gt;
&lt;P&gt;You can only manage the cluster (all the tabs) from the Primary PAN. The Secondary PAN will only manage the cluster if the Primary has failed and the Secondary is promoted. Only one can be active to manage the cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 07:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346363#M598931</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-11-12T07:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346364#M598932</link>
      <description>&lt;P&gt;You need to enable all nodes where required for the device admin service; this does not require a restart of ISE.&lt;/P&gt;
&lt;P&gt;Only PAN will be able to manage all the nodes in the deployment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 07:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346364#M598932</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-11-12T07:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346365#M598933</link>
      <description>&lt;P&gt;Thank&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;alot.&lt;/P&gt;&lt;P&gt;It seem likes both ISE using same database authentication (replicate). So i can understand that if ISE-Pri dies then all the database (drop, failed, passed) switch to ISE-Secondary too and not relate to the "Device admin" service, right?&lt;/P&gt;&lt;P&gt;Like user1 has failed many times in the ISE-Primary (20 times) and still keep that count on ISE-Second when ISE-Pri dies.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 08:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346365#M598933</guid>
      <dc:creator>Xibachao1</dc:creator>
      <dc:date>2025-11-12T08:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346366#M598934</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1854286"&gt;@Xibachao1&lt;/a&gt;&amp;nbsp;yes, but in a two node cluster, you have to manually promote the Secondary node to Primary. The PAN persona is independant to the Device Admin role. You just need to enable the services on both nodes, for them both to work as TACACS+ servers.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 08:11:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346366#M598934</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-11-12T08:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE HA-Mode (Control Webgui)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346395#M598936</link>
      <description>&lt;P&gt;You have the option to always promote the other node as primary.&lt;/P&gt;
&lt;P&gt;check the guide for reference :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_deployment.html#ID246" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_deployment.html#ID246&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 09:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ha-mode-control-webgui/m-p/5346395#M598936</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-11-12T09:29:50Z</dc:date>
    </item>
  </channel>
</rss>

