<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Adding Secondary cluster in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630149#M74816</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I am already having ISE in distributed deployment as&lt;/P&gt;&lt;P&gt;1)Primary Admin node&lt;/P&gt;&lt;P&gt;2)Primary Monitor node&lt;/P&gt;&lt;P&gt;3)PSN&lt;/P&gt;&lt;P&gt;Now i have 3 more ISE boxes &amp;amp; i need to build secondary cluster.&lt;/P&gt;&lt;P&gt;1) Secondary Admin node&lt;/P&gt;&lt;P&gt;2) Secondary Monitor node&lt;/P&gt;&lt;P&gt;3) PSN&lt;/P&gt;&lt;P&gt;To do this what all prerequisites .. any maintanance window required..?&lt;/P&gt;&lt;P&gt;Secondary cluster will be deployed at different location where firewall facing scenario. is there any ports need to be opened for synchronization..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:23:44 GMT</pubDate>
    <dc:creator>Prasan Venky</dc:creator>
    <dc:date>2019-03-11T05:23:44Z</dc:date>
    <item>
      <title>Adding Secondary cluster</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630149#M74816</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I am already having ISE in distributed deployment as&lt;/P&gt;&lt;P&gt;1)Primary Admin node&lt;/P&gt;&lt;P&gt;2)Primary Monitor node&lt;/P&gt;&lt;P&gt;3)PSN&lt;/P&gt;&lt;P&gt;Now i have 3 more ISE boxes &amp;amp; i need to build secondary cluster.&lt;/P&gt;&lt;P&gt;1) Secondary Admin node&lt;/P&gt;&lt;P&gt;2) Secondary Monitor node&lt;/P&gt;&lt;P&gt;3) PSN&lt;/P&gt;&lt;P&gt;To do this what all prerequisites .. any maintanance window required..?&lt;/P&gt;&lt;P&gt;Secondary cluster will be deployed at different location where firewall facing scenario. is there any ports need to be opened for synchronization..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630149#M74816</guid>
      <dc:creator>Prasan Venky</dc:creator>
      <dc:date>2019-03-11T05:23:44Z</dc:date>
    </item>
    <item>
      <title>After you register the</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630150#M74818</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;After you register the secondary node, the configuration of the secondary node is added to the database of the primary node and the application server on the secondary node is restarted. After the restart is complete, the secondary node will be running the personas and services that you have enabled on it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_dis_deploy.html#pgfId-1053327&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;ISE 1.2 what ports need to be open between different personas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_c-ports.html&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;ISE 1.3 what ports need to be open between different personas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/installation_guide/b_ise_InstallationGuide13/b_ise_InstallationGuide12_appendix_01001.html&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Jan 2015 04:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630150#M74818</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2015-01-31T04:22:23Z</dc:date>
    </item>
    <item>
      <title>Thanks Jatin.I have two PSN's</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630151#M74819</link>
      <description>&lt;P&gt;Thanks Jatin.&lt;/P&gt;&lt;P&gt;I have two PSN's. So i should create a node group to achieve redundancy and load balancing right ?&lt;/P&gt;&lt;P&gt;I have a doubt on EAP certificate installation on secondary ISE that i am going to introduce.(we are using posture redirect for client to get NAC agent).&lt;/P&gt;&lt;P&gt;In primary ISE cluster, i installed with FQDN of PSN(DNS=PSN-Primary.local.com,DNS=*.local.com). How should i install certificate on secondary...Is it like (DNS=PSN-Secondary.local.com &amp;amp; DNS=*.local.com) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2015 07:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630151#M74819</guid>
      <dc:creator>Prasan Venky</dc:creator>
      <dc:date>2015-02-05T07:32:34Z</dc:date>
    </item>
    <item>
      <title>Node group does not give you</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630152#M74820</link>
      <description>&lt;P&gt;Node group does not give you redundancy or load-balancing. It just tells ise to re-authenticate the devices that were currently trying to authenticate when one of your psn wen't down, so they are not left in an unusable state. To load-balance, you need an external load-balancer, or just use redundancy by configuring both psn's in your switches and wlc. Som switch versions support more advanced load-balancing of psn requests.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 17:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-secondary-cluster/m-p/2630152#M74820</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-02-06T17:28:16Z</dc:date>
    </item>
  </channel>
</rss>

