05-14-2019 02:44 AM
Hi experts,
Our customer adopted SDA, and use redundant two ISE servers which version is 2.4 patch 6.
When failure happens on PRIMARY ISE, customer will operate the following procedure without promoting SECONDARY ISE to PRIMAY.
Now, I describe HA ISE servers as ISE-1 and ISE-2.
To assume configure backup has already taken.
Partner tried the above procedure, and confirmed there are no problems with this step.
(such as pxGrid between DNAC and ISE, authentication, SXP with outside of Fabric, and traffic from endpoints)
We understand the regular step is to promote SECONDARY ISE to PRIMARY,
but our customer request the above procedures because of company regulations.
Do you have any concerns about this step?
Cisco team suspect that step 6. and 8. may not be necessary.
05-14-2019 08:59 AM
Assuming ISE-1 is the original primary and ISE-3 is the replacement primary..
I am not clear why ISE-3 configured with a temporary IP address instead of the same IP as ISE-1, unless the customers want to play safe. IIRC if an ISE CFG backup from a deployment is restored to a standalone ISE node with the same FQDN, the restored host will change as the primary. Because of (3) ISE-3 has a different IP address, we can't change the IP address unless standalone:
myISE26/admin(config-GigabitEthernet)# ip address 10.1.100.27 255.255.255.0 % Warning: GigabitEthernet0 IP address change disallowed as this node is part of a deployment. Make it a standalone to change the IP.
05-14-2019 07:50 PM
05-15-2019 05:20 AM
No. Please do take regular backups and test restoring them regularly.
05-15-2019 06:27 PM
05-17-2019 07:38 PM
To ensure the backups are good.
05-19-2019 11:13 PM
I appreciate your support.
Finally, we understand customers can get the TAC support in this env?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide