12-07-2023 09:02 PM
We plan to operate two nodes.
I have one concern regarding design. If ISE HA is not implemented and two NODEs with PAN/MNT/PSN persona roles are operated as ACTIVE/ACTIVE as shown in the configuration diagram, will there be any problems?
From a service perspective, when HQ collapses, we plan to implement DR so that the service can be restored to normal.
Solved! Go to Solution.
12-07-2023 09:56 PM
The two node design in your diagram is a classic 2 node design and it's perfectly acceptable. You can suffer an outage of one of the ISE nodes, and the RADIUS/TACACS+ services will still run on the other node. If you get unlucky and the Primary Admin Node fails, then you won't see any Live Logs. You can promote the Standby PAN to be Primary, and then you will have Live Logs again.
RADIUS and TACACS+ HA is implemented in the Network Devices and not in ISE. The "Services" are enabled on both nodes and each node has the same programming.
12-08-2023 03:49 AM
12-07-2023 09:56 PM
The two node design in your diagram is a classic 2 node design and it's perfectly acceptable. You can suffer an outage of one of the ISE nodes, and the RADIUS/TACACS+ services will still run on the other node. If you get unlucky and the Primary Admin Node fails, then you won't see any Live Logs. You can promote the Standby PAN to be Primary, and then you will have Live Logs again.
RADIUS and TACACS+ HA is implemented in the Network Devices and not in ISE. The "Services" are enabled on both nodes and each node has the same programming.
12-08-2023 12:19 AM
Thanks for your response.
One additional question: Would it be okay if two nodes operate as primary for the Admin node?
In other words, it is assumed that when the HQ Primary PAN fails, the DR PAN status is also operating as Primary, not Standby. (In the case of DR PAN, it is not Standby, so there is no need to promote it)
12-08-2023 03:49 AM
12-10-2023 05:43 PM
Thanks to you, my curiosity has been somewhat resolved.
I agree with you saying it's not fun. I think we need to re-establish our goal in the direction of forming HA.
12-10-2023 07:58 PM
I agree with @Arne Bier, even though it's possible to run two seperate instances, I don't see the benefit since you would have to manually keep everything in sync between the two. With the normal deployment of a two node cube, you can promote the secondary which is easy. You also have an option with configuring PAN failover which will do that automatically , but not really recommended. Keep in mind that the PSN is active on both and your network devices would have entries for both.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide