<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: switch to the secondary PAN node in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363837#M599605</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1739732"&gt;@nastiakhon&lt;/a&gt;&amp;nbsp;you can automatically failover, but it does&amp;nbsp;require there be at least one other non-admin node in the deployment (in addition to the Primary PAN and Secondary PAN). If you only have a small 2 node ISE deployment, then you cannot automatically failover.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jan 2026 14:38:48 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2026-01-21T14:38:48Z</dc:date>
    <item>
      <title>switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363834#M599603</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;Is there any way to automatically switch to the secondary PAN node if the primary PAN node crashes? This usually has to be done manually.&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 14:33:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363834#M599603</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2026-01-21T14:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363835#M599604</link>
      <description>&lt;P&gt;Depends on the deployment; if you configured PAN AutoFailover, then yes. if not then manually promote required.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#toc-hId-118574828" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#toc-hId-118574828&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;OLD document still good for understanding :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscopress.com/articles/article.asp?p=2812072" target="_blank"&gt;https://www.ciscopress.com/articles/article.asp?p=2812072&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 14:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363835#M599604</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-01-21T14:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363837#M599605</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1739732"&gt;@nastiakhon&lt;/a&gt;&amp;nbsp;you can automatically failover, but it does&amp;nbsp;require there be at least one other non-admin node in the deployment (in addition to the Primary PAN and Secondary PAN). If you only have a small 2 node ISE deployment, then you cannot automatically failover.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 14:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363837#M599605</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-01-21T14:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363849#M599606</link>
      <description>&lt;P&gt;We don't have a deployed ISE yet, we're only in the planning stage, so we'd like to immediately create a scheme that will automatically switch over if the main node becomes unavailable.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 14:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363849#M599606</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2026-01-21T14:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363850#M599607</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1739732"&gt;@nastiakhon&lt;/a&gt; well you'd need to design your ISE cluster accordingly, with at least 3 ISE nodes for auto failover functionality, with the non-admin node acting as the health check node. The health check node can also function as a non-admin role, i.e., PSN.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/admin_guide/b_ise_admin_3_4/b_ISE_admin_deployment.html#ID59" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/admin_guide/b_ise_admin_3_4/b_ISE_admin_deployment.html#ID59&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 14:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363850#M599607</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-01-21T14:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363858#M599608</link>
      <description>&lt;P&gt;So, if we have two data centers, we'll set up a separate PAN1 node and a separate PSN1 node in the first data center. We'll do the same in the second data center, setting up a separate PAN2 node and a separate PSN2 node. We'll select PAN1 as the primary node in data center 1, and specify that its health check node will be PSN1. We'll do the same for the second data center.&lt;BR /&gt;So, we'll have a total of 4 nodes.&lt;BR /&gt;Am I correct in understanding that with this setup, if PAN1 fails, PAN2 will automatically become the primary node, and the workflow won't be interrupted?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 15:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363858#M599608</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2026-01-21T15:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363865#M599609</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1739732"&gt;@nastiakhon&lt;/a&gt;&amp;nbsp;some features are unavailable when the Primary PAN is unavailable. So during the brief period during PAN switchover is occurring there maybe some features unavailable. Refer to Table 10 for a full list-&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_deployment.html#ID59" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_deployment.html#ID59&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Health Check design:-&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1769009624141.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/258340i9A7643D74614E7CC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobIngram_0-1769009624141.png" alt="RobIngram_0-1769009624141.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 15:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363865#M599609</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-01-21T15:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: switch to the secondary PAN node</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363866#M599610</link>
      <description>&lt;P&gt;I understand everything. Thank you very much for your help!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 15:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-to-the-secondary-pan-node/m-p/5363866#M599610</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2026-01-21T15:41:25Z</dc:date>
    </item>
  </channel>
</rss>

