06-07-2018 01:55 AM
Hi,
I have a large implementation of ISE in a distributed model with 2 ISEs for PAN and 2 for MnT and centralized PSNs in multiple regions "4 in each region" which will cover a lot of branches.
unfortunately we can't afford a load balancers behind PSNs.
I want to know best practice solution to configure NADs in one region to saturate all PSNs in that region and consider the fail-over in case of multiple PSNs become down or the entire region.
also i want to know in case that WAN connection is down and no reachable PSN in any region how wireless connections will be treated ? Is there anything like a fail open or fall back to a Vlan like switches for WLC ?
06-07-2018 06:35 AM
Hi,
Have you seen the below ISE high availability and load balancing doc?
Regards,
-Tim
06-07-2018 07:22 AM
Thanks for your reply Timothy.
I went through the document quickly and as I understand and as I don't have load balancer and have 4 PSNs in each region I should configure each branch in each region to use one PSN and wait till it fails and then goes for the other till the entire region goes down then it will try another PSN in another region.
and as i can't use anycast i will need at least 5 servers configuration in each NAD "switch or WLC" , am i correct ?
but still these doc don't answer my question about wireless connection in case of WAN failure. do you know if there an equivalent thing to critical VLAN or fail open in WLC ?
06-08-2018 06:32 AM
For WLC, there is no critical VLAN. Instead, we simply create another WLAN not using RADIUS.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: