11-05-2020 11:12 PM
Hello,
I want to know, are we supposed to create all the policies in the PSN node?
Thanks
Solved! Go to Solution.
11-05-2020 11:50 PM
Hi
No, the PSN node is responsible for network access request processing, RADIUS, Posture, Profiling, Web Redirection and Guest Portal. In short, all communication from your network environment goes to the PSN for processing.
All configurations such as Policies, Guest Portal, External Identity Stores etc. is done on the PAN (Policy Administration Node) while the MnT (Monitoring & Troubleshooting) node collects logs from your PAN, PSN and Network Devices (NAD's)
11-05-2020 11:50 PM
Hi
No, the PSN node is responsible for network access request processing, RADIUS, Posture, Profiling, Web Redirection and Guest Portal. In short, all communication from your network environment goes to the PSN for processing.
All configurations such as Policies, Guest Portal, External Identity Stores etc. is done on the PAN (Policy Administration Node) while the MnT (Monitoring & Troubleshooting) node collects logs from your PAN, PSN and Network Devices (NAD's)
11-09-2020 01:50 AM
thank u for that,
Also which would u consider the best way to do a user and machine authentication ?
11-09-2020 08:05 AM
11-09-2020 10:01 AM
So I have used eap chaining and I am facing some issues. the endpoint is already using anyconnect for wireless, and when i connect an endpoint to the switch it is not hitting any of the policies I have created for EAP chaining, in fact, it picks up the employee unknown policy for provisioning and does not detect that the endpoint already has anyconnect.
11-09-2020 10:41 AM
So the Anyconnect NAM module is already deployed for Wireless 802.1X? In that case you need to create an XML profile for Wired 802.1X using EAP-FASTv2 and enable Wired Autoconfig service in Windows.
See this document for reference https://www.cisco.com/c/en/us/support/docs/wireless-mobility/eap-fast/200322-Understanding-EAP-FAST-and-Chaining-imp.html
11-09-2020 11:00 AM
No wireless was not configured for ISE, but they use it when connecting to wireless normally, so when i connect my pc it shows that wired anyconnect has been connected but nothing happens after. So not really sure wht is actually going on.
11-06-2020 01:32 AM
ISE has 3 components - ( Depending on the size of your deployment all three personas can be run on the same device or spread across multiple devices for redundancy and scalability).
coming to your point - Policy Administration Node is where the administrator configure policies and make changes to the entire ISE system
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide