Need to get information regarding Cisco ISE PSN deployment,
How PSN will be synchronizing using a multicast IP address? lets take an scenario, where i have 4 PSN and connected to Cisco switch 3560. what configuration changes are required in Cisco switch?
Lets take another scenario that we have 2 nexus switches in 2 separate DC like SW-1 in DC-1 and SW-2 in DC-2. SW-1 and SW-2 are in VSS mode. 2 PSN connecting in SW-1 and 2 PSN connecting in SW-2. can we maintain a single node group?
The node group is used by PSNs to synchronize the sessions' states only. This becomes useful when a PSN fails and an endpoint and/or user was in the middle of an authentication session. The other node(s) in the group would detect the PSN failure and reset any pending sessions.
Configuration/database synchronization is completely different and is done between the Admin node to the PSNs and it has nothing to do with the PSN node groups.
For your last question: The PSNs must be layer 2 adjacent before they can be placed in a node group. On the other hand, the NADs (Switches, routers, ASAs) can be in different l2/l3 domains.
I think the word replication has triggered a different angle to the question. i understand the theory of node group but in the requirement of multicast, they have just mentioned that it should be L2 adjacent (i.e) in same vlan and same switch.
if multicast traffic should pass through the switch then we need to perform some configuration in switch. By default multicast is enabled in Cisco switches, but no multicast router will be configured. if the application doesn't depend on external multicast router to pass this multicast traffic then default setting is enough. if the application is depends on external multicast router then this should be configured.
if you are seeing the first question, it queries about the configuration requirement in switches to enable multicast between the PSN's in single node group which are connected to same switch and same vlan.
second question queries, in case of Nexus switch in VSS mode, switch behaves as same switch and same vlan will be available. whether single node group in same vlan can be spread across two different nexes switch in VSS mode?
hope the queries are crystal clear. please let me know the answers.
No special multicast configurations are needed on the switch/switches where the PSNs connect. The key here is the layer 2 adjacency. If the devices are in the same l2 domain then all broadcast and multicast traffic would flow/flood the domain. So no special multicast configurations needed.
For question number 2: Nexus switches do not support VSS but that is a different topic :) Nonetheless, if you are using vPC (Nexus) or VSS (Catalyst) then the same rules would apply. As long as the PSN nodes are l2 adjacent the multicast traffic would flow/flood without a problem within the L2 domain.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :