01-13-2025 05:17 AM
i have 2 node Cisco ISE3.3
i need to make HA
frist node have all configuration and AD external store and everthing
what i need to do at the sec node befor i make it as secondary ??
01-13-2025 05:22 AM
@Saeed Abd Elhalim Hamada patch the new node to the same version as the Primary node, ensure both nodes trust each others "admin" certificate, both nodes are configured with the same DNS servers and the time is synchronised, via the same NTP server.
01-13-2025 05:26 AM
the sec node will be sec in PAN and MNT , no need to join the SEC to AD ?? it will join aumtaitcally ? lile the primarry ?
01-13-2025 05:31 AM - edited 01-13-2025 05:33 AM
@Saeed Abd Elhalim Hamada once joined to the cluster you will need to manually join to your external identity sources (AD). You would also want to specify the node as a PSN (in addition to Sec PAN/MNT). Enable other node specific features such as Profiling probes on the new node. And obviously configure your NADS (switches/WLC etc) to point to the new ISE node for AAA.
01-13-2025 05:37 AM
so you mean i need to join the Sec to AD first before i make it as a secodary node ?
01-13-2025 05:40 AM
@Saeed Abd Elhalim Hamada no, you join to AD after you've joined to the cluster.
01-13-2025 05:28 AM
This video I know it for old ver. But the idea is same check it.
01-15-2025 06:18 PM
Hi @Saeed Abd Elhalim Hamada ,
1st, take a look at Administration > System > Deployment, if all Node Status are Connected.
2nd, take a look at Administration > Identity Management > External Identity Sources, if all Status are Operational.
Hope this helps !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide