08-02-2016 01:33 PM
Hi,
I have a customer with only one FMC 5.4.1.5 and ISE 1.3 distributed deployment with 2xPAN, 2xMnT and 2xPSN. He wants to perform Rapid Threat Containment. My doubt is in which ISE nodes are usually activated pxgrid personas and how can I get some high availability.
I saw in FMC v6.x we can integrate with ISE specifying a primary and secondary ISE nodes but in v5.x we have to use the script still and not sure if possible specifying a secondary node.
Thanks and regards.
Solved! Go to Solution.
08-03-2016 08:08 AM
Hi,
Please send me an email and we can discuss the details.
Thanks,
John
08-02-2016 04:47 PM
Our recommendation is to dedicate pxGrid on its own nodes. The solution for FMC 5.4 does not support secondary ISE node so it needs a manual failover.
08-03-2016 12:51 AM
Many thanks for your answer.
Unfortunately, customer has no the possibility of using dedicated nodes for pxGrid.
PSN nodes are behind a load balancer, would it be possible to activate pxGrid persona in PSN nodes and balance the pxGrid service in the same way we do for AAA services? FMC pxGrid agent would point to a VIP balancing the pxGrid service (TCP/8910)..
08-03-2016 08:08 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: