cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
10461
Views
12
Helpful
11
Replies

Cisco ISE Small Deployment High Availability

Kevin Raditheo
Level 1
Level 1

Hi All,

I want to ask some question regarding Cisco ISE HA in Small Deployment Network (with two node of ISE):

  1. Is it true that in Small Deployment, Secondary node need to be promoted manually when Primary node down? Since I read a document that says auto-failover can only be enabled in Distributed Node
  2. If failover is manual, what is the purpose of secondary admin persona since you will need to promote it manually and can not configure policy when it still in secondary position.
  3. Will the failover change the IP address of Secondary to Primary node IP address? Must I input Primary and Secondary node IP address to all the NAD?

Thanks for your answers in advance.

Regards,

Kevin

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

Is it true that in Small Deployment, Secondary node need to be promoted manually when Primary node down? Since I read a document that says auto-failover can only be enabled in Distributed Node

Yes, this is true.

If failover is manual, what is the purpose of secondary admin persona since you will need to promote it manually and can not configure policy when it still in secondary position.

The policies and settings (The entire PAN database) is synchronized with the Secondary Admin Node and is kept in synchronization.  Once the Secondary is promoted, all the settings and policies previously configured on the Primary Node will be there.

*Remember to add both the Primary and Secondary Admin Nodes to ALL Licenses installed, as these are synchronized as well.  If you do not have them both registered on the license you can "Re-Host" the license(s) by following this process:

Re-Host ISE Licenses*

Will the failover change the IP address of Secondary to Primary node IP address? Must I input Primary and Secondary node IP address to all the NAD?

Both nodes should be added to the NAD in this deployment (Standalone), as each node hosts a Policy Service Persona.  It is only the PSNs that are added to the nodes for RADIUS.

Charles Moreton

View solution in original post