cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
435
Views
0
Helpful
7
Replies

CISCO ISE HA

i have 2 node Cisco ISE3.3 

i need to make HA 

frist node have all configuration and AD external store and everthing 

what i need to do at the sec node befor i make it as secondary ?? 

7 Replies 7

@Saeed Abd Elhalim Hamada patch the new node to the same version as the Primary node, ensure both nodes trust each others "admin" certificate, both nodes are configured with the same DNS servers and the time is synchronised, via the same NTP server.

the sec node will be sec in PAN and MNT , no need to join the SEC to AD ?? it will join aumtaitcally ? lile the primarry ? 

@Saeed Abd Elhalim Hamada once joined to the cluster you will need to manually join to your external identity sources (AD). You would also want to specify the node as a PSN (in addition to Sec PAN/MNT). Enable other node specific features such as Profiling probes on the new node. And obviously configure your NADS (switches/WLC etc) to point to the new ISE node for AAA.

so you mean i need to join the Sec to AD first before i make it as a secodary node ?

 

@Saeed Abd Elhalim Hamada no, you join to AD after you've joined to the cluster.

Hi @Saeed Abd Elhalim Hamada ,

 1st, take a look at Administration > System > Deployment, if all Node Status are Connected.

Node Status.png

 

2nd, take a look at Administration > Identity Management > External Identity Sources, if all Status are Operational.

Status.png

 

Hope this helps !!!