01-08-2019 05:16 AM
I want to confirm this is still true today with 2.4
https://community.cisco.com/t5/identity-services-engine-ise/pan-auto-failover-for-2-ise/td-p/3512753
I require automatic failover for guest/sponsorship services and currently running in standalone mode.
It appears that the minimum deployment mode in this case is medium. Example:
PSNs also acting as health check boxes for their respective DC.
Can I get confirmation?
Also, based on the timers are we looking at best time for guest services to be available during auto failover is 20 minutes?
Thanks
Solved! Go to Solution.
01-08-2019 06:37 AM
01-08-2019 03:24 PM
Regarding the timers, I don't know if there is enough field experience to answer this reliably, but let's be clear about what this Automatic PAN failover is for. If the PAN fails, then Guests will still get to the guest portal and MAB etc will still work. The urgency is around the Sponsor Portal because that will be unavailable while the PAN is not running 100%. That's the only issue as far as I know. How quickly do you need the Sponsor portal back up? 20min sounds reasonable. Why not make it more aggressive? Because if the PAN is restarted intentionally (or there is a transient LAN failure), then you don't want to Auto failover to kick in and start causing havoc. Leave yourself some room. Remember that this mechanism causes the Standby to restart - that is not fast. So you want to avoid that if it's not required.
01-08-2019 06:37 AM
01-08-2019 11:46 AM
Just to be clear -
Multiple DCs I would required a medium deployment
Each PSN acting as a health check node for their respective DC PAN/MNT as well as PSN
Single DC is this supported
Single PSN acting as a health check node for their respective DC PAN/MNT as well as PSN.
Also, with the timers - can I tweak them to reduce the overall time to failover? Recommended?
Thanks,
Jason
01-08-2019 03:24 PM
Regarding the timers, I don't know if there is enough field experience to answer this reliably, but let's be clear about what this Automatic PAN failover is for. If the PAN fails, then Guests will still get to the guest portal and MAB etc will still work. The urgency is around the Sponsor Portal because that will be unavailable while the PAN is not running 100%. That's the only issue as far as I know. How quickly do you need the Sponsor portal back up? 20min sounds reasonable. Why not make it more aggressive? Because if the PAN is restarted intentionally (or there is a transient LAN failure), then you don't want to Auto failover to kick in and start causing havoc. Leave yourself some room. Remember that this mechanism causes the Standby to restart - that is not fast. So you want to avoid that if it's not required.
01-08-2019 03:34 PM
01-08-2019 03:41 PM
Hey Jason
Would 3 be a supported solution 2x PAN/MNt and 1xPSN? Just want to have all the options available - I realize that 2x PSN provides redundancy for policies and health checks but need to be clear what min is supported
01-08-2019 03:58 PM
01-08-2019 03:36 PM
Thanks on the timers. Just need confirmation on the examples single vs. Dual DCs
01-08-2019 03:42 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide