Cisco Cisco Identity Services Engine 1.2
3
Release Notes for Cisco Identity Services Engine, Release 1.2.x
OL-27043-01
Deployment Terminology, Node Types, and Personas
running the Administration persona and configured as a primary and secondary pair. If the
primary Administration node goes down, you have to manually promote the secondary
Administration node. There is no automatic failover for the Administration persona.
primary Administration node goes down, you have to manually promote the secondary
Administration node. There is no automatic failover for the Administration persona.
–
Policy Service—Provides network access, posturing, BYOD device onboarding (native
supplicant and certificate provisioning), guest access, and profiling services. This persona
evaluates the policies and makes all the decisions. You can have more than one node assuming
this persona. Typically, there is more than one Policy Service persona in a distributed
deployment. All Policy Service personas that reside behind a load balancer can be grouped
together to form a node group. If one of the nodes in a node group fails, the other nodes in that
group process the requests of the node that has failed, thereby providing high availability.
supplicant and certificate provisioning), guest access, and profiling services. This persona
evaluates the policies and makes all the decisions. You can have more than one node assuming
this persona. Typically, there is more than one Policy Service persona in a distributed
deployment. All Policy Service personas that reside behind a load balancer can be grouped
together to form a node group. If one of the nodes in a node group fails, the other nodes in that
group process the requests of the node that has failed, thereby providing high availability.
Note
At least one node in your distributed setup should assume the Policy Service persona.
–
Monitoring—Enables Cisco ISE to function as a log collector and store log messages from all
the Administration and Policy Service personas on the Cisco ISE nodes in your network. This
persona provides advanced monitoring and troubleshooting tools that you can use to effectively
manage your network and resources.
the Administration and Policy Service personas on the Cisco ISE nodes in your network. This
persona provides advanced monitoring and troubleshooting tools that you can use to effectively
manage your network and resources.
A node with this persona aggregates and correlates the data that it collects to provide
meaningful reports. Cisco ISE allows a maximum of two nodes with this persona that can
assume primary or secondary roles for high availability. Both the primary and secondary
Monitoring personas collect log messages. In case the primary Monitoring persona goes down,
the secondary Monitoring persona automatically assumes the role of the primary Monitoring
persona.
meaningful reports. Cisco ISE allows a maximum of two nodes with this persona that can
assume primary or secondary roles for high availability. Both the primary and secondary
Monitoring personas collect log messages. In case the primary Monitoring persona goes down,
the secondary Monitoring persona automatically assumes the role of the primary Monitoring
persona.
Note
At least one node in your distributed setup should assume the Monitoring persona. It is
recommended that the Monitoring persona be on a separate, designated node for higher
performance in terms of data collection and reporting.
recommended that the Monitoring persona be on a separate, designated node for higher
performance in terms of data collection and reporting.
•
Inline Posture node is a gatekeeping node that is positioned behind network access devices such as
wireless LAN controllers (WLCs) and VPN concentrators on the network. An Inline Posture node
enforces access policies after a user has been authenticated and granted access, and handles change
of authorization (CoA) requests that a WLC or VPN is unable to accommodate. Cisco ISE allows
up to 10,000 Inline Posture Nodes in a deployment. You can pair two Inline Posture nodes together
as a failover pair for high availability.
wireless LAN controllers (WLCs) and VPN concentrators on the network. An Inline Posture node
enforces access policies after a user has been authenticated and granted access, and handles change
of authorization (CoA) requests that a WLC or VPN is unable to accommodate. Cisco ISE allows
up to 10,000 Inline Posture Nodes in a deployment. You can pair two Inline Posture nodes together
as a failover pair for high availability.
Note
An Inline Posture node is dedicated solely to that service and cannot operate concurrently with
other Cisco ISE services. Likewise, due to the specialized nature of its service, an Inline Posture
node cannot assume any persona. Inline Posture nodes are not supported on VMware server
systems.
other Cisco ISE services. Likewise, due to the specialized nature of its service, an Inline Posture
node cannot assume any persona. Inline Posture nodes are not supported on VMware server
systems.
Note
Each Cisco ISE node in a deployment can assume more than one persona (Administration, Policy
Service, or Monitoring) at a time. By contrast, each Inline Posture node operates only in a dedicated
gatekeeping role.
Service, or Monitoring) at a time. By contrast, each Inline Posture node operates only in a dedicated
gatekeeping role.