11-16-2018 02:19 AM
Team,
Can you please let me know in a distributed environment, if a PSN looses connectivity to both the PAN's does it still does authentication/posturing?...
Thanks
Solved! Go to Solution.
11-16-2018 02:31 AM
Hi,
If connection between PAN & PSN breaks, PSN will be having all the old configuration,it won't affect authentication/posturing, Only the new changes in PAN will not get replicated on the PSN.
Please check this When Primary PAN is down
-Aravind
11-19-2018 07:21 AM - edited 11-19-2018 07:37 AM
If you enable health check on PSN to enable auto Failover, it continuously monitors the of PAN node. ISE will generate alarm if the PAN node is down. it does not leave after some time.
once the PAN node is back up, it regains the connectivity.
Thanks,
Nidhi
11-21-2018 02:34 AM
Please see my response inline-
a) According to the discussion here PSN can now work as usual but might not
work in the case of any new policy changes and any new dictionary updates.
right?
NP - Yes thats correct
b) Regarding Licensing the licenses are downloaded to PAN and then
distributed to PSN right?
If b) is right then how does PAN know that the licensing is violated since
now tracking of endpoints are not accurate (since one site is isolated and
does not have the count of endpoints from that site)
NP-PAN queries the session directory from MnT for showing any kind of license violation. If the PAN is not available, there will be no alerts for license violation. Also, Since MnT is available, the operational data will be available in MnT for all the sessions in PSN.
11-16-2018 02:31 AM
Hi,
If connection between PAN & PSN breaks, PSN will be having all the old configuration,it won't affect authentication/posturing, Only the new changes in PAN will not get replicated on the PSN.
Please check this When Primary PAN is down
-Aravind
11-16-2018 08:52 AM
11-19-2018 07:21 AM - edited 11-19-2018 07:37 AM
If you enable health check on PSN to enable auto Failover, it continuously monitors the of PAN node. ISE will generate alarm if the PAN node is down. it does not leave after some time.
once the PAN node is back up, it regains the connectivity.
Thanks,
Nidhi
11-19-2018 07:47 AM
11-21-2018 02:34 AM
Please see my response inline-
a) According to the discussion here PSN can now work as usual but might not
work in the case of any new policy changes and any new dictionary updates.
right?
NP - Yes thats correct
b) Regarding Licensing the licenses are downloaded to PAN and then
distributed to PSN right?
If b) is right then how does PAN know that the licensing is violated since
now tracking of endpoints are not accurate (since one site is isolated and
does not have the count of endpoints from that site)
NP-PAN queries the session directory from MnT for showing any kind of license violation. If the PAN is not available, there will be no alerts for license violation. Also, Since MnT is available, the operational data will be available in MnT for all the sessions in PSN.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide