12-24-2025 11:04 PM
Hi All,
I am currently expanding an existing Cisco ISE cluster. The current setup consists of two dedicated nodes: one acting as the Primary Admin/MNT and the other two nodes as a Policy Service Node (PSN).
I am now adding another appliance which I intend to configure as the Secondary Admin/MNT. I have a few questions regarding the deployment process:
Root CA Certificates: Should I manually import the Root CA certificates onto the new node prior to registration? Specifically, is it best practice to export the Root CA (.pem) from the Primary PAN and manually import on the trusted Certificates on the new secondary node?
System Certificates: I am using separate certificates for the Admin role and another for multi-purpose roles (Portal, EAP, pxGrid, RADIUS DTLS, Messaging Service). Do these certificates need to be manually exported from the Primary and imported to the Secondary, or are they automatically synchronized during the registration process?
Initial Node State: Before registering the new node to the cluster, should its persona be set to Standalone or Primary?
Any guidance or best practices would be greatly appreciated. Thank you!
12-25-2025 01:27 AM
Most of the steps at the high level you covered, I suggest the following steps be officially documented:
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
12-25-2025 11:53 AM - edited 12-25-2025 11:54 AM
about item 3.
To create a Distributed Deployment the 1st Node of the Cluster should be a Primary Node, all the other new Nodes, a Standalone Node.
about item 2 and 1.
Your new Node needs a Certificate (at Administration > System > Certificates > Certificate Management > System Certificates) with the following possible usage:
To install this Certificate, you need to trust the "Certification Chain", in other words, you need to install 1st the Root CA (at Administration > System > Certificates > Certificate Management > Trusted Certificates).
about item 4.
Before registering ...
After registering ...
Hope this helps !
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide