Cisco Cisco Identity Services Engine 1.2

Página de 186
 
3
Release Notes for Cisco Identity Services Engine, Release 1.2.x
OL-27043-01
  Deployment Terminology, Node Types, and Personas
running the Administration persona and configured as a primary and secondary pair. If the 
primary Administration node goes down, you have to manually promote the secondary 
Administration node. There is no automatic failover for the Administration persona.
Policy Service—Provides network access, posturing, BYOD device onboarding (native 
supplicant and certificate provisioning), guest access, and profiling services. This persona 
evaluates the policies and makes all the decisions. You can have more than one node assuming 
this persona. Typically, there is more than one Policy Service persona in a distributed 
deployment. All Policy Service personas that reside behind a load balancer can be grouped 
together to form a node group. If one of the nodes in a node group fails, the other nodes in that 
group process the requests of the node that has failed, thereby providing high availability.
Note
At least one node in your distributed setup should assume the Policy Service persona.
Monitoring—Enables Cisco ISE to function as a log collector and store log messages from all 
the Administration and Policy Service personas on the Cisco ISE nodes in your network. This 
persona provides advanced monitoring and troubleshooting tools that you can use to effectively 
manage your network and resources.
A node with this persona aggregates and correlates the data that it collects to provide 
meaningful reports. Cisco ISE allows a maximum of two nodes with this persona that can 
assume primary or secondary roles for high availability. Both the primary and secondary 
Monitoring personas collect log messages. In case the primary Monitoring persona goes down, 
the secondary Monitoring persona automatically assumes the role of the primary Monitoring 
persona.
Note
At least one node in your distributed setup should assume the Monitoring persona. It is 
recommended that the Monitoring persona be on a separate, designated node for higher 
performance in terms of data collection and reporting.
Inline Posture node is a gatekeeping node that is positioned behind network access devices such as 
wireless LAN controllers (WLCs) and VPN concentrators on the network. An Inline Posture node 
enforces access policies after a user has been authenticated and granted access, and handles change 
of authorization (CoA) requests that a WLC or VPN is unable to accommodate. Cisco ISE allows 
up to 10,000 Inline Posture Nodes in a deployment. You can pair two Inline Posture nodes together 
as a failover pair for high availability.
Note
An Inline Posture node is dedicated solely to that service and cannot operate concurrently with 
other Cisco ISE services. Likewise, due to the specialized nature of its service, an Inline Posture 
node cannot assume any persona. Inline Posture nodes are not supported on VMware server 
systems.
Note
Each Cisco ISE node in a deployment can assume more than one persona (Administration, Policy 
Service, or Monitoring) at a time. By contrast, each Inline Posture node operates only in a dedicated 
gatekeeping role.