<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2592052#M72132</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;We have 2 &amp;nbsp;ISE server. I configured wired, wireless,vpn, guest user authentication from ISE server. All of them are normal working. Both of ISE server have same Image.(ver 1.2)&amp;nbsp;I deployed ISE servers as HA. &amp;nbsp;I register second ISE server&amp;nbsp;at&amp;nbsp;primary ISE&amp;nbsp;server.&amp;nbsp;&amp;nbsp;I attached the configuration files.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want one ISE device is primary( Administration, Monitoring and Policy are active in primary ISE)&amp;nbsp;and the other ISE server&amp;nbsp;&amp;nbsp;is backup or standby. (Administration, Monitoring and Policy are standby). When the Primary ISE server&amp;nbsp;is &amp;nbsp;going to down then all AAA process is going &amp;nbsp;through the secondary ISE&amp;nbsp;server( it is like redundancy on &amp;nbsp;ASA)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to configure? If yes how I do this configuration?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for your helping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:10:28 GMT</pubDate>
    <dc:creator>teymur azimov</dc:creator>
    <dc:date>2019-03-11T05:10:28Z</dc:date>
    <item>
      <title>Cisco ISE Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2592052#M72132</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;We have 2 &amp;nbsp;ISE server. I configured wired, wireless,vpn, guest user authentication from ISE server. All of them are normal working. Both of ISE server have same Image.(ver 1.2)&amp;nbsp;I deployed ISE servers as HA. &amp;nbsp;I register second ISE server&amp;nbsp;at&amp;nbsp;primary ISE&amp;nbsp;server.&amp;nbsp;&amp;nbsp;I attached the configuration files.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want one ISE device is primary( Administration, Monitoring and Policy are active in primary ISE)&amp;nbsp;and the other ISE server&amp;nbsp;&amp;nbsp;is backup or standby. (Administration, Monitoring and Policy are standby). When the Primary ISE server&amp;nbsp;is &amp;nbsp;going to down then all AAA process is going &amp;nbsp;through the secondary ISE&amp;nbsp;server( it is like redundancy on &amp;nbsp;ASA)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to configure? If yes how I do this configuration?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for your helping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2592052#M72132</guid>
      <dc:creator>teymur azimov</dc:creator>
      <dc:date>2019-03-11T05:10:28Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 does not have an</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2592053#M72133</link>
      <description>&lt;P&gt;ISE 1.2 does not have an Automatic Failover for the Admin Nodes.&amp;nbsp; If the primary node goes down, you have to manually promote the secondary node.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" src="https://community.cisco.com/legacyfs/online/attachments/discussion/promote_secondary.png" style="width: 855px; height: 473px;" /&gt;&lt;/P&gt;&lt;P&gt;Until you promote the secondary, the deployment has very serious limitations:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" src="https://community.cisco.com/legacyfs/online/attachments/discussion/promote_secondary_2.png" style="width: 846px; height: 65px;" /&gt;&lt;/P&gt;&lt;P&gt;So, you see, there is no true HA with Automatic Failover for ISE 1.2.You have to have both ISE servers on anyway and the Monitoring Persona is the only one that does support Automatic Failover, so it really does make sense to deploy your nodes as noted here:&lt;/P&gt;&lt;P&gt;Node1:&amp;nbsp; Admin (Primary), Monitoring (Secondary), Policy Service&lt;/P&gt;&lt;P&gt;Node2:&amp;nbsp; Admin (Secondary), Monitoring (Primary), Policy Service&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The notes I referenced can be found in the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_dis_deploy.html#pgfId-1230090"&gt;ISE 1.2 User Guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.&amp;nbsp; Otherwise, feel free to post follow-up questions.&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2014 13:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2592053#M72133</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2014-11-12T13:16:49Z</dc:date>
    </item>
  </channel>
</rss>

