11-21-2020 02:01 AM
Hello all
I have three simple questions that I would like to know the answer, since I never done it before.
I have in production 2 nodes with PAN,MNT and PSN (One Primary and one Secondary) and I will take out the PSN role to a dedicated machine. So my doubts are in the configuration, right now I have the radius on all the switches pointing to the 2 nodes that have, since I will take off the PSN role to a dedicated node do I need to rebuild the entire configuration?
And with the policy’s do I need to do anything?
And in the networking tab where I add all the switches do I need to do some changes?
Thank you in advance for who can help me with this
11-21-2020 02:28 AM
- In the running config of the switches, all you have to do is to point the radius-server-config to the dedicated PSN. But this is far from best practice. I would recommend to have at least 2 working PSN, for failover reasons.
M.
11-21-2020 05:43 AM - edited 11-21-2020 05:43 AM
Thank you for the reply,
Will definitely have 2 PSN's.
So that's the only thing i need to do? Add the PSN to the Deploy and change config in swith's, instead of appoint to the actual node will appoint to the new PSN right?
11-21-2020 09:41 AM
- Switches determine which radius servers (PSN's) are used in the running config. On a first approach make sure that there are at least two. If you want to play with load balancing schemes and preferences , check this document :
M.
11-23-2020 08:14 AM
Add the PSNs to the Deployment, point switches to the new PSNs, disable PSN role on the Admin Nodes.
BR
Rick
11-23-2020 09:31 AM
About the certificates that are installed even the public one for the Portal Guest, do i need to do anything or can stay in the PAN?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide