05-28-2025 09:57 AM
Let say you have a 4 nodes ISE environment:
node1: Primary PAN/Primary MnT in AWS USEast-1,
node2: Secondary SAN/Secondary MnT in AWS USWest-1,
node3: PSN in AWS USEast-1,
node3: PSN in AWS USWest-1,
Let say node1 goes down unexpectedly and you promote node2 to be the PAN and PMnT. Two hours later, node1 comes back online. What is going to happen to your cluster because both node1 and node2 are now PAN and Primary MnT? Is this going to cause an issue? How are you going to fix this?
Solved! Go to Solution.
05-29-2025 04:07 AM
@Aref Alsouqi: Here is what happened. Everything was working fine. Node1 was PAN/PMnT and node2 was SAN/SMnT. I removed VPC peering between USEast-1 and USWest-1, so that node1 & node3 could NOT communicate with node2 and node4. I also performed went into AWS console and power OFF node 1. After that, I promoted node2 to PAN/PMnT. Ten hours later, I restored the VPC peering between USEast-1 and USWest-1 and powered up node1 shortly after that. This is where node1 and node2 were both showed up as PAN/PMnT.
05-29-2025 07:09 AM
Would the whole time that node1 was down exceeded 12 hours?
05-29-2025 09:35 AM
@Aref Alsouqi: it is possible that node1 was down for more than 28 hours, now that I remember. Cisco documentation stated that:
Actions must be taken to bring the PAN back into deployment within 12 hours.
What happened if the PAN node is down for more than 12 hours?
05-29-2025 09:45 AM
You will need to perform a manual sync on the node.
05-30-2025 01:09 AM
That seems to be the issue then. Although the documentation doesn't expand much on that, but I think it means exactly what you'd experienced. Tbh, this is something I'd never tested before, but it seems if the PAN goes offline for more than 12 hours it does get disconnected logically from the deployment as you could see.
05-29-2025 11:38 AM
Can anyone explain what this mean? According to Cisco documentation:
Actions must be taken to bring the PAN back into deployment within 12 hours.
What happen if the PAN is down for more than 12 hours? What will happen then?
05-29-2025 12:05 PM
06-26-2025 08:53 AM - edited 06-26-2025 08:54 AM
Hi @adamscottmaster2013 ,
when the PPAN is not online during the SPAN promotion to primary:
At this point you are able to promote the old PPAN back to PPAN.
Hope this helps !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide