04-23-2025 12:15 AM
Hi,
we had situation where two nodes PAN,MNT must be installed on the cloud and two nodes PSN must be installed on prem, catalyst center (DNAC) installed on prem as well and we want to make integration with DNAC and ISE, question where we should enable pxgrid should we enable it on the cloud along with PAN, MNT only or along with PSN on prem only or enable it on all the nodes?
thanks
05-13-2025 02:36 AM
Hello @M_alamin
It is recommended to enable pxGrid on ALL ISE nodes: PAN, MNT, and PSNs, regardless of location (cloud or on-prem). Enabling pxGrid on all ISE nodes ensures comprehensive visibility, centralized policy enforcement, high availability, and simplified management in your hybrid ISE and DNAC deployment.
HTH & Stay Curious!
AshSe
Community Etiquette:
05-13-2025 03:08 AM - edited 05-13-2025 03:29 AM
You should follow the deployment types outlined in the performance and scalability guide: https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#Cisco_Concept.dita_67b428f0-2240-4383-bd49-5eb7a7b98a35
In this case you are running a medium deployment and should enable PXgrid on your PAN nodes.
EDIT:
Remember that the integration between Cat-C and ISE is only for administrative purposes. It doesn't directly affect the dataplane so it won't be an issue for users if the connectivity between Cat-C and your PAN nodes drop.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide