cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2975
Views
30
Helpful
4
Replies

Cisco ISE with two nodes and PAN node redundancy

IamSamSaul
Level 1
Level 1

Hello fellow experts,

 

I have installed two Cisco ISE nodes with PAN, PSN and MnT functionality. On one of the nodes the PAN, PSN and MnT are configured as Primary while the Secondary on the second node. As far as redundancy is concerned when the Primary node is down, PSN and MnT functionalities are taken over by the secondary node and PAN-Secondary on the second node will be active. But at this point you can't make any changes on PAN-Sec unless you make this PAN as Primary manually. 

 

Is there any way to automate this process?

 

Thanks & Regards,

Sam

1 Accepted Solution
4 Replies 4

Hi Charlie,

Thanks for your reply. So this means that we have to install an extra node
(health check node) in order for the automatic failover for PAN to work. Am
I correct?

Thanks & Regards,
Sam

Yes, that is correct. While a three node deployment with 2x PAN/MNT/PSN, and 1x PSN is not a published deployment topology, it does work. In this scenario it is very important that all network devices are configured to have all three nodes available. When the automatic PAN failover happens, the remaining PAN node will also go and reload taking down all of its services. The remaining third PSN node will be the only node up while the automatic failover happens. If not planned for correctly this can be a high impact event that you're unable to control the timing of. 

Hi Damien,

Thanks a lot for your reply.

Regards,
Sam