cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
441
Views
1
Helpful
6
Replies

ISE admin and monitoring nodes replacement

lwang
Level 1
Level 1

Hey community gurus,

I am gonna replace two ISE admin nodes and two mnt nodes with new hardware model. Need some comments if the replacement process is correct. 

Regarding two admin nodes (ppan and span), I have no problem replacing the span first. But before replacing the existing ppan, do I need to remote the new span to ppan? and then after the new span (which is the old ppan) joins the cluster, I will promote the new span to be new ppan? 

Regarding two mnt nodes replacement, should I follow the same procedure as admin node replacement?  like promote smnt to pmnt and then replace old pmnt as new smnt, and then promite new smnt back to new pmnt? 

6 Replies 6

Marvin Rhoads
Hall of Fame
Hall of Fame

Your scheme of replacing and promoting nodes makes sense. Delete a node from the deployment and then add in the new one with the same version, patch and bootstrap configuration. It will sync from the current Primary PAN and then be eligible to serve whatever persona and roles you assign to it.

Hi, I have similar situation but in medium deployment. So in my case I have 2 nodes with 2 personas on each - primary admin node / secondary MnT and secondary admin node / primary MnT. Process probably will look the same, but just want to confirm it. I’m going to as first delete secondary admin node / primary MnT, then add new node as Secondary Admin node, but MnT will be what - primary or secondary? When node will fully sync I’m going to promote it to Primary admin node and proceed with replacement of last node. It should work, but I’m not sure how MnT will react. Any clue?

You can determine the role of the MNT prior to performing any of the replacement steps. Manually select the current Sec MNT to be Primary MNT - it will do so after a few minutes. The partner MNT will automatically set its role to Secondary. At least then, you have some deterministic behaviour.
The role of the MNT is not as crucial as the role of the Admin. You can flip these roles without any impact

Yeah, MnT was switched without any issues. When I have replaced Sec Admin Node - SMART license kicked in sending information to update it. I think the only option is to de-register and register again. However when I will de-register our deployment will go into Eval mode and that's a problem because with Eval mode only 100 Endpoints will be supported. Is there any other way this sync with SMART can be done without de-registration? Maybe TAC will help?

You can go into Eval without any problems. ISE can tolerate 45 days' worth of violations in a 60-day period. No throttling or performance loss happens in that time.

I just need to have it working without license for 1-2 minutes. But for sure I won't do it during business hours - just to be safe. I will update this case after that.