04-03-2022 11:58 PM
Can secondary ISE serve any authentication requests? Current setup is primary ISE at DC and secondary ISE at DR.
Testing anyconnect VPN via DR. Since DR ISE is in a secondary role, can it server the authentication requests from DR ASA.
Solved! Go to Solution.
04-04-2022 03:25 AM
@manvik Yes, you should be able to see the authentications in the DC ISE Logs. DC/DR are part of the same cluster, the Primary MnT will log traffic for any PSN in the cluster, regardless of where it is physically located.
04-04-2022 12:36 AM
@manvik I assume these ISE nodes part of the same cluster? If so, then as long as the secondary node is running the PSN persona then yes it can authenticate requests from the DR ASA. It's the configuration of the ASA which is configured with the PSN and which PSN to prefer.
04-04-2022 01:47 AM
yes, ISE nodes are part of same cluster. currently the authentication is not working, can DR ISE logs viewed from DC ISE in same cluster.
04-04-2022 03:25 AM
@manvik Yes, you should be able to see the authentications in the DC ISE Logs. DC/DR are part of the same cluster, the Primary MnT will log traffic for any PSN in the cluster, regardless of where it is physically located.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide