cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
285
Views
0
Helpful
2
Replies

Cisco ISE in distributed edeployment , All PSN have same Policy sets ?

palani2010
Level 1
Level 1

Cisco ISE in distributed edeployment , All PSN have same Policy sets ?

1 Accepted Solution

Accepted Solutions

@palani2010 yes, the PSN nodes in a distributed cluster would have the same policy sets.

View solution in original post

2 Replies 2

@palani2010 yes, the PSN nodes in a distributed cluster would have the same policy sets.

owbhat
Cisco Employee
Cisco Employee

Yes, @palani2010 
In a Cisco ISE distributed deployment, all Policy Service Nodes (PSNs) share the same Policy Sets because:

  • Policies are centrally managed on the Primary Administration Node (PAN) and then replicated to all PSNs.
  • This ensures consistent policy enforcement across all PSNs in the deployment.
  • PSNs are stateless regarding policies—they only apply the rules received from PAN.

PAN as Central Management in Cisco ISE

  • The Primary Administration Node (PAN) is responsible for configuration, policy management, logging, and reporting.
  • All changes made on PAN are pushed to other nodes (PSNs, Secondary PAN).
  • The Secondary PAN remains passive and takes over only if promoted.