11-30-2024 03:58 AM
Hello,
We are deploying a 2 node Cisco ISE in a virtual environment for single site/location and integrate it with DNA Center as well.
Node 1: PAN, MNT, PSN & PxGrid
Node 2: PAN, MNT, PSN & PxGrid
Any best practices to be followed for distributing personas across the two nodes?
Thank you in advance for your insights!
Solved! Go to Solution.
12-13-2024 06:26 AM - edited 12-13-2024 06:27 AM
No problem @thenetadmin! Let's say your nodes are named A and B. Your deployment should look like this:
11-30-2024 12:19 PM - edited 11-30-2024 11:55 PM
Hello @thenetadmin,
You should see the following documentation regarding this: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_1.html#node-types-and-personas-in-distributed-deployments
You should keep your primary PAN node and primary MNT node separate to distribute load more evenly. The PSN persona is "primary less" and should be enabled on both nodes. The PxGrid service should be enabled on both nodes, but be aware that it relies on having a functioning primary PAN node.
12-13-2024 06:02 AM
@Torbjørn Sorry for the late reply.
With 2 node deployment, how each personas should be distributed as best practice?
12-13-2024 06:26 AM - edited 12-13-2024 06:27 AM
No problem @thenetadmin! Let's say your nodes are named A and B. Your deployment should look like this:
12-13-2024 06:41 AM
Thank you so much. @Torbjørn Appreciated
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide