cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
304
Views
0
Helpful
3
Replies

Cisco ISE - Migration From Middle to Large Architecture

doverture
Level 1
Level 1

Good Morning, a customer is going to add other PSNs to the current distributed Cisco ISE environment. By now they have a Middle size architecture with a couple of PAN and MNT and five PSNs. In order to add new PSNs (by now four or five) I suppose that a Large architecture has to be deployed (2 PAN + 2 MNT + Max 50 PSN). Did you have had similar experiences? Can you suggest a right procedure to minimize out of services in the production distributed environment?

Any suggestion is appreciated!

DN

1 Accepted Solution

Accepted Solutions

@doverture This can be sequence. 1. Disable secondary MNT persona from primary PAN node 2. Register one new node in deployment and make it secondary MNT. 3. Disable secondary PAN from the primary MNT node. 4. Register one more new node in deployment and make it secondary PAN. 5. Thereafter you can add additional PSNs as needed.     

View solution in original post

3 Replies 3

PSM
Level 1
Level 1

@doverture  To convert from Medium deployment to Large deployment you need dedicated nodes for PAN and MNT personas. So this means you will be using 4 nodes in total only for PAN and MNT purpose instead of existing 2 nodes. You can increase PSNs without disturbing existing PSNs as they are dedicated already. For advise on migration procedure need detail about the current setup. You can share the the existing personas of different nodes here or feel free to contact directly via DM.

doverture
Level 1
Level 1

Hello @PSM the current setup is easy: there are 2 PAN that are also MNT (primary PAN is secondary MNT and viceversa) and then there are already 5 dedicated PSN. 

DN

@doverture This can be sequence. 1. Disable secondary MNT persona from primary PAN node 2. Register one new node in deployment and make it secondary MNT. 3. Disable secondary PAN from the primary MNT node. 4. Register one more new node in deployment and make it secondary PAN. 5. Thereafter you can add additional PSNs as needed.