cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3376
Views
12
Helpful
9
Replies

Moving MnT from one ISE appliance to another.

Hi,

 

I have two ISE appliances in my deployment. The first ISE appliance is the primary node for Admin and Monitoring.

 

I want to move MnT to the second ISE appliance. Does this cause both ISE appliances to reboot? If only one ISE appliance reboots, which one reboots (first or second). I am trying to maintain service as much as I can during this change.

 

Thanks

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

An ISE node will restart its services when the persona(s) change. I would suggest adding MnT as the primary MnT on the 2nd ISE. For the 1st ISE, remove the MnT persona in a maintenance window.

View solution in original post

9 Replies 9

hslai
Cisco Employee
Cisco Employee

An ISE node will restart its services when the persona(s) change. I would suggest adding MnT as the primary MnT on the 2nd ISE. For the 1st ISE, remove the MnT persona in a maintenance window.

Thanks @hslai do this mean when I am moving the MnT to the secondary node, the secondary node do not restart its services. Only the primary mode will restart it services.

If the 2nd ISE has no MnT and you add MnT to it, the 2nd ISE will restart its ISE services. If the 2nd ISE is serving other ISE services (esp. session services), please also do it in a MW. Changing ISE MnT roles between primary and 2nd will not restart ISE.

Hi @hslai I made this change and the service outage was about 7 minutes. No issues afterwards. thanks for your help.

Ethan Grinnell
Level 1
Level 1

Adding my experience: We have a similar setup, 2 ISE nodes, one is primary PAN and MnT and the other is secondary PAN and MnT. I swapped MnT priority between the 2 nodes. Now the primary PAN is the secondary MnT. No restart was triggered for this change. The difference may have been that both nodes already had MnT persona and I was only changing which was the primary.

Hi @Anthony O'Reilly  @hslai @Ethan Grinnell 

I have the same scenario as mentioned on lab as we have 2 nodes configure as Deployment nodes,
Currently our PAN is secondary M&T, while secondary node is primary M&T. The objective is to change role PAN to primary M&T for Operational Backup and Configuration Backup.

Once we click change the role Primary M&T on PAN node,  Does it require restarting both nodes or just restarting service?  They will be down time both nodes ?
We need to ensure the operation/authentication no downtime. 

Thank you, 
 

JPavonM
VIP
VIP

Node service restarts only happen when you change from one persona to another (like from monitor-2-administration or psn-2-monitor, or viceverssa) but not when you swap primary and secondary roles.

Thank @JPavonM  for sharing your experience 

Hi @JPavonM @hslai @Anthony O'Reilly 

I have a ISE HA pair for PAN and a HA pair for MnT, trouble is they are the wrong way around and I need to swap the PAN and MnT persona roles at the failover 'B' site, as below:- 

tompownall_1-1751645680581.png

Question is service impact and process.

Process: Can I make the swap just in the GUI? Or do I have to de-register each secondary, reset them in console CLI with 'application reset-config ise’ and re-add them for a clean synch with their respective primary nodes?

Impact: When the persona swap is only with secondaries, will the primary reboot at any point?

Primary serve live AAA for campus wireless so if a reboot is on the cards I need to call it out and plan accordingly.

tompownall_2-1751646124013.png

Many Thanks in advance for any advice on the above!

Tom