01-30-2019 10:52 PM
Hello everyone,
I have distributed deployment of ISE with 2 PAN (Active-Standby) and 2 PSN. I have couple of but quite easy questions about internet access of ISE nodes.
1)Do PAN nodes have to have constant Internet access? I think it must because of smart license.
2)Do PSN nodes have to have Internet access? I predict no because as i know they take license information from PAN
Thanks in advance!
01-30-2019 11:09 PM
01-30-2019 11:10 PM
Thank you, for your quick response. However, with PSNs, they do not require any Internet Access.
01-30-2019 11:21 PM
No internet access is needed for a dedicated psn mode.
01-30-2019 11:25 PM
Sorry, but, i did not understand your answer. In my case, I have 2 dedicated PSN nodes. So do they require internet? If yes why?
01-30-2019 11:57 PM
Just to clarify ,
There are a couple of types of models for licensing.
One is traditional licensing using PAK file which would not need Internet access to manage.
The other model is smart licensing where you would have a Cisco account to monitor the type of licenses you have purchased , in this case you would need Internet Access.
Heres a document explaining the models as well as pros and cons.
"Licenses are uploaded to the Primary PAN and propagated to the other Cisco ISE nodes in the cluster. Licenses are centrally managed by the PAN. If you have two PANs deployed in a high-availability pair, obtain a license based on the hardware IDs (UIDs) of both the Primary and Secondary PANs. After you obtain the license, add it only to the Primary PAN. The license gets replicated to the Secondary PAN".
01-31-2019 12:17 AM
Thank you, for your response. I am using Smart Licensing so therefore i have opened internet access for license and feeds. What i got from your answer that i am right on my opinion for PSN nodes. Becuase they get everything replciated from PAN nodes they do not need Internet access at all. Am i right?
01-31-2019 12:47 AM
Yes that is correct , only your PAN would need Internet access for smart licensing.
01-31-2019 01:54 AM
I think the responses so far have covered everything - but I wanted to add from my own experience one case where the PSN's do have to have internet access - it might not be immediately obvious - but it's when you have a Guest Sponsor portal and you wish to send SMS's to the guest account holders. The SMS is initated from the PSN nodes (e.g. https or REST API call). This might be a corner case, but it's one instance where I had to have the PSN be able to route to the internet.
cheers
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide