cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1231
Views
0
Helpful
7
Replies

pxGrid High availability

e-chuah
Level 1
Level 1

Hi,

I am running ISE 3.1.
two nodes:

Node1:
- Primary PAN
- Primary MnT
- PSN1
- pxGrid 1

Node2:
- Secondary PAN
- Secondary MnT
- PSN2
- pxGrid 2

I understand that ISE 3.1, only pxgrid v2 is supported and we can run pxigrid active/active.

In the above setup, if Node1 fails, Primary PAN fails. Have to bring up Secondary PAN manually.
During this time, if secondary PAN is not up yet, will my existing pxGrid services affected?
I will assume that Node2 pxGrid 2 will still be available.

Is this the correct understanding ?

Thanks
Eng Wee

 

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

The pxgrid service on the secondary node might still respond on port 8910 since pxgv2 is active/active, but the high availability guide indicates that when the primary admin node is down, pxgrid services will not be available. I haven't tested this personally, but I suspect the guide is correct. 

https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_deployment.html#ID59

View solution in original post

7 Replies 7

Damien Miller
VIP Alumni
VIP Alumni

The pxgrid service on the secondary node might still respond on port 8910 since pxgv2 is active/active, but the high availability guide indicates that when the primary admin node is down, pxgrid services will not be available. I haven't tested this personally, but I suspect the guide is correct. 

https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_deployment.html#ID59

Thanks Damien for the reply. I believe you are right based on the documentation provided.

 

That table does not provide the full details, so it is a bit misleading. See the following table pulled from the CiscoLive BRKSEC-3432 session. The MnT node publishes the session directory to PXG nodes.

Screen Shot 2022-09-28 at 9.20.29 am.png

 

Hi Greg,

Thanks for the inputs. I will further test this out in the lab to understand the behaviour.

Rgds

Eng Wee

 

 

 

peter.matuska1
Level 1
Level 1

basic question...if I do the integration FMC<->ISE and I shutdown FMC, what would happen? Is pxgrid communication done directly between FTD and ISE or FMC is some kind of proxy for pxgrid? So in this case high availability for FMC is a must?

thank you

@peter.matuska1 the FTD learns the IP/User bindings from the FMC, which learns them from ISE via pxGrid. If you only have a single FMC and you lose that, no new IP/username bindings will be learnt by the FTDs. So yes, have HA FMC in this scenario.

ok, that's what I thought. thank you for confirmation.