cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
326
Views
0
Helpful
2
Replies

Sd- Access Design help

M_alamin
Level 1
Level 1

Hi,

we had situation where two nodes PAN,MNT must be installed on the cloud and two nodes PSN must be installed on prem, catalyst center (DNAC) installed on prem as well and we want to make integration with DNAC and ISE, question where we should enable pxgrid should we enable it on the cloud along with PAN, MNT only or along with PSN on prem only or enable it on all the nodes?

thanks

2 Replies 2

AshSe
VIP
VIP

Hello @M_alamin 

It is recommended to enable pxGrid on ALL ISE nodes: PAN, MNT, and PSNs, regardless of location (cloud or on-prem). Enabling pxGrid on all ISE nodes ensures comprehensive visibility, centralized policy enforcement, high availability, and simplified management in your hybrid ISE and DNAC deployment.

 

HTH & Stay Curious!

AshSe

 

Community Etiquette: 

  1. Insert photos/images inline - don't attach.
  1. Always mark helpful and correct answers, it helps others find what they need.
  1. For a prompt reply, kindly tag @name. An email will be automatically sent to the member.

Torbjørn
VIP
VIP

You should follow the deployment types outlined in the performance and scalability guide: https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#Cisco_Concept.dita_67b428f0-2240-4383-bd49-5eb7a7b98a35 

In this case you are running a medium deployment and should enable PXgrid on your PAN nodes. 

EDIT: 
Remember that the integration between Cat-C and ISE is only for administrative purposes. It doesn't directly affect the dataplane so it won't be an issue for users if the connectivity between Cat-C and your PAN nodes drop.

Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev