04-09-2025 11:13 PM
Hi Community members,
I have to test failover between ppan and span. what should be the process to test failover ? I have distributed deployment where both ppan and span are in different data centers.
Regards,
MT
Solved! Go to Solution.
04-10-2025 03:07 PM
ISE Admin Node failover happens when you promote the current Standby node to Primary. You can't demote the current Primary.
Browse to the Secondary Admin node and click the Promote button.
At that point, both your Admin nodes will be out of service for a while. The old Primary is restarting and becoming Secondary, and the old Secondary is restarting services to become the new Primary.
If you have MNT and PSN nodes in the network, those will be unaffected during this time. You just won't have any admin GUI to monitor or make any changes.
The other small caveat during this promotion stage, is that Guest account creations won't work - you Guest Portals (running on PSN) will display and allow login etc. - but Sponsor portal won't create new accounts because you need a Primary Admin node to be fully operational to store the data in the master database.
04-10-2025 03:07 PM
ISE Admin Node failover happens when you promote the current Standby node to Primary. You can't demote the current Primary.
Browse to the Secondary Admin node and click the Promote button.
At that point, both your Admin nodes will be out of service for a while. The old Primary is restarting and becoming Secondary, and the old Secondary is restarting services to become the new Primary.
If you have MNT and PSN nodes in the network, those will be unaffected during this time. You just won't have any admin GUI to monitor or make any changes.
The other small caveat during this promotion stage, is that Guest account creations won't work - you Guest Portals (running on PSN) will display and allow login etc. - but Sponsor portal won't create new accounts because you need a Primary Admin node to be fully operational to store the data in the master database.
04-13-2025 11:53 PM
Thanks a lot @Arne Bier for the brief explanation. I have able to test failover successfully without any issues.
Regards,
MT
04-12-2025 04:28 AM - edited 04-15-2025 11:46 AM
To test failover between PPAN and SPAN in a distributed deployment, start by simulating a failure on the PPAN, such as shutting it down or disconnecting it from the network. Observe whether the SPAN automatically takes over operations without service disruption. Monitor system logs, alerts, and overall behavior to ensure a smooth transition. Once verified, bring the PPAN back online and check that it properly re-syncs with the SPAN and resumes its role without issues.
A2game
04-12-2025 07:15 AM
Hi @M Talha ,
1st the basics ... ISE supports automatic failover for the Administration Persona, but:
2nd before testing failover between PPAN and SPAN, please take a look at: Cisco ISE Administrator Guide, Release 3.4 - Deployment of Cisco ISE, search for:
3rd testing failover ...
If your Deployment doesn't have automatic failover, please take a look of what @Arne Bier said earlier
If your Deployment have automatic failover, please take a look of what @M Talha said earlier
Hope this helps !!!
04-14-2025 10:23 AM
it depend you enable automatic failover or not , if you enable it you can go the the PPAN and stop all service from CLI (application stop ISE ) and after while the failover should be triggered , if you not enable it then you need to make it manually be go the the SPAN and promote it to Primary
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide