07-12-2016 08:38 AM
Please help to comment on followings:
Solved! Go to Solution.
07-12-2016 09:01 AM
1. That is correct. There is no synchronization between MNT nodes. I’m making the assumption here that your two ISE nodes have all personas (ADM,MNT,PSN). You can always navigate directly to ISE2 to see the sessions specific to that node. In a normal environment, the session database is naturally synchronized between the two MNT nodes. In your situation, the sessions would end up being normalized over time. You could change the secondary MNT node to become primary for a while if you want to see the most accurate representation of sessions on your network.
2. That seems odd. If you can reproduce, you may consider opening a TAC case.
3. You also can’t assume every failed attempt is making it to ISE. There may be times where the attempts are being blocked at the wireless controller for instance if client exclusion is triggered. Also, ISE may be dropping requests if anomalous client detection is triggered.
07-12-2016 09:01 AM
1. That is correct. There is no synchronization between MNT nodes. I’m making the assumption here that your two ISE nodes have all personas (ADM,MNT,PSN). You can always navigate directly to ISE2 to see the sessions specific to that node. In a normal environment, the session database is naturally synchronized between the two MNT nodes. In your situation, the sessions would end up being normalized over time. You could change the secondary MNT node to become primary for a while if you want to see the most accurate representation of sessions on your network.
2. That seems odd. If you can reproduce, you may consider opening a TAC case.
3. You also can’t assume every failed attempt is making it to ISE. There may be times where the attempts are being blocked at the wireless controller for instance if client exclusion is triggered. Also, ISE may be dropping requests if anomalous client detection is triggered.
07-12-2016 09:16 AM
George, thanks for the swift response.
1. Yes, only two nodes are configured. I am not sure the normal environment that you've mentioned. Is that more two ISE nodes or MNT must be on separte nodes?
2. will open case to followup
3. It's a wired environment, so it may be related to anomalous client detection.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide