cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1454
Views
0
Helpful
6
Replies

ISE Deployment Change..

Hello..

 

We have 2x3355 ISE appliances and we already deployed them in standalone mode (redundant deployment which support up to 2000 endpoints), After a while the customer ask us to add another PSN using external server with VM version of ISE,  he said that 2000 endpoints is not enough for him and he wants to increase the number of endpoints by adding extra PSN.

 

What I understand is with the current setup (standalone) I cannot add extra PSN unless I re-dpoly the whole thing in distributed mode (which will cause reconfiguring the two appliances and disconnect all ISE services), is this correct? If so Is there any way or guide line  to safely migrate from stand alone to distribution without down time..

 

Thx

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

Once you convert from Standalone to Distributed Mode, the ISE services MUST restart.  There is no getting around this.  This generally does not take more than 15 minutes, depending on your environment.  Once that is done, you can add PSNs to the deployment without an interruption in service.  Just do not remove the Policy Service role from the Admin Node until your PSN is up.

View solution in original post

6 Replies 6

Any suggestion guys..

Any help on this....

Charlie Moreton
Cisco Employee
Cisco Employee

Once you convert from Standalone to Distributed Mode, the ISE services MUST restart.  There is no getting around this.  This generally does not take more than 15 minutes, depending on your environment.  Once that is done, you can add PSNs to the deployment without an interruption in service.  Just do not remove the Policy Service role from the Admin Node until your PSN is up.

Thank you so much Charles..

One more question, After converting to Distribution mode, then add the new external PSN, can I remove the old PSN on the 3355 appliance???

Thx

You can take it off, but it will restart the ISE services on that node.  If this is your Admin Node, then you ISE will have the chance of being down.  The PSN should authenticate users and re-sync with the Admin Node once it comes back up.

Thank you for your answers Charles.. they are very helpful.. yes

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: