04-17-2017 12:53 PM
Hello,
What is the ideal time taken for PAN Failover in ISE 2.1 ?
I've seen Cisco Live slides mention 15 - 20 minutes but in our testing it took between 35 - 45 minutes.
The customer has raised serious concerns since new endpoints could not be profiled during this transition.
Solved! Go to Solution.
04-18-2017 02:36 PM
This failover is configurable by the polling interval and the count. When it not happening as expected, please analyze the timeline based on the debug logs and verify whether the monitoring node(s) not detecting the events fast enough. Please engage Cisco TAC, if needed.
04-18-2017 02:36 PM
This failover is configurable by the polling interval and the count. When it not happening as expected, please analyze the timeline based on the debug logs and verify whether the monitoring node(s) not detecting the events fast enough. Please engage Cisco TAC, if needed.
04-19-2017 02:45 PM
A couple points here:
04-19-2017 03:59 PM
Paul, Thanks for your comments.
PAN needs to be up for new endpoints to be profiled.
Existing profiled endpoints will have no issue in getting authenticated but new endpoints will not be profiled unless a PAN is up and running .
Thanks,
Utkarsh
04-19-2017 05:21 PM
Does the PAN need to be up to profile or does one PSN profile but the PAN is needed to update all the other PSNs?
Sent from my iPhone
04-20-2017 07:52 AM
PAN needs to be up for new endpoints to be profiled.
Existing profiled endpoints will not have any issue as profiling information already stays with PSN.
Check this document for ISE 2.1
The document for ISE 1.4 says otherwise
04-20-2017 08:06 AM
Ahh thanks. I haven’t looked at that in detail before. Learned something new about ISE. Now I can take the rest of the week off. ☺
Paul Haferman
Office- 920.996.3011
Cell- 920.284.9250
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide