Adding Secondary cluster

Dear All,
I am already having ISE in distributed deployment as
1)Primary Admin node
2)Primary Monitor node
3)PSN
Now i have 3 more ISE boxes & i need to build secondary cluster.
1) Secondary Admin node
2) Secondary Monitor node
3) PSN
To do this what all prerequisites .. any maintanance window required..?
Secondary cluster will be deployed at different location where firewall facing scenario. is there any ports need to be opened for synchronization..?
Thanks in advance

After you register the secondary node, the configuration of the secondary node is added to the database of the primary node and the application server on the secondary node is restarted. After the restart is complete, the secondary node will be running the personas and services that you have enabled on it.
http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_dis_deploy.html#pgfId-1053327
ISE 1.2 what ports need to be open between different personas?
http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_c-ports.html
ISE 1.3 what ports need to be open between different personas?
http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/installation_guide/b_ise_InstallationGuide13/b_ise_InstallationGuide12_appendix_01001.html
Hope this helps.
Regards,
Jatin

Similar Messages

  • An error occurred while adding the Cluster to the list

    Hello,
    I've installed the HFM 9.3.1 client on a Windows Server 2003 machine and now I'm attempting to configure it. I get all the way to the Server/Cluster Registration and when I try to add my one and only HFM application server to the list I'm present with this error.
    "An error occurred while adding the Cluster to the list".
    I don't see anything of use in the config tool log and as a result, I'm stuck. The odd thing is that not more than 10 minutes previously I added just finished installing the HFM client on another Windows Server 2003 machine and it installed / configured perfectly.
    What am I missing?
    Thanks!

    You may have a DNS error of sorts. From a command line on the server which presents the error, ping the servername you are trying to reach. Do not use the cluster name, but instead use the server name or IP address. If you successfully reach it, use this in the registration utility. Once the server has been reached, it will return the cluster's name. If you cannot reach it using ping, focus on the underlying DNS problem.
    --Chris                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       

  • DCOM Error 10005 in PRD System - Secondary Cluster

    Hi,
    We have noticed the following errors getting listed in the Production
    Server - Secondary Cluster System.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    2008/12/04,12:15:48,DCOM got error "The service cannot be started, either
    because it is disabled or because it has no enabled devices associated
    with it." attempting to start the service SAPPRD_10 with arguments
    "-Service" in order to run the server:
    {EFC29CCA-A03C-11D0-A1F2-0000F62893CC}
    2008/12/04,12:15:47,DCOM got error "The service cannot be started, either
    because it is disabled or because it has no enabled devices associated
    with it." attempting to start the service SAPPRD_02 with arguments
    "-Service" in order to run the server:
    {EFC29CCA-A03C-11D0-A1F2-0000F62893CC}
    2008/12/04,12:15:46,DCOM got error "The service cannot be started, either
    because it is disabled or because it has no enabled devices associated
    with it." attempting to start the service SAPPRD_01 with arguments
    "-Service" in order to run the server:
    {EFC29CCA-A03C-11D0-A1F2-0000F62893CC}
    2008/12/04,12:15:45,DCOM got error "The service cannot be started, either
    because it is disabled or because it has no enabled devices associated
    with it." attempting to start the service SAPPRD_00 with arguments
    "-Service" in order to run the server:
    {EFC29CCA-A03C-11D0-A1F2-0000F62893CC}
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    the above log has been translated from Japanese to English.
    We have gone the cluster log but could not find any clue as to what
    actually caused the error.
    BTW, we have noticed the below SAP Services are in Disabled mode in the
    secondary Cluster system
    01) SAPPRD_00
    02) SAPPRD_01
    03) SAPPRD_02
    04) SAPPRD_10
    Any Idea ?
    Thanking you in anticipation.
    Best Regards
    LRaghunahth

    Hi Goran,
    Thanks for your reply.
    It was really helpful. According to my knowledge we did not set the SAP services to  Disabled.
    So wondering how the SAP services on the secondary cluster is set to Disabled.
    Is there any possibility that the services are changed from manual to Disabled by itself ?
    Thanking in anticipation.
    Best Regards
    L Raghunahth

  • Adding Secondary Site SCCM2012

    I have a Primary Site Setup with general roles and  Distribution Point roles, Reporting services, Software Update point.
    Now we have added an another site and need to set up one more site server at site-2.
    I need to distribute the software updates of site-2 clients using the new sccm-2 server located in Site-2 by having an Distribution in site-2.
    what all the additional roles needs to be setup in site-2.
    do I need to install WSUS in site-2 sccm server to push software updates?
    And prior installing the secondary Site, do I need to install an SQL server Instance at Sccm2 server?
    or the default mssql express edition is enough at site-2 which will be taken care during addition of secondary site wizard?
    Pls clarify
    Raj

    Assuming you actually want/need a secondary site:
    - No there is no advantage of using a full SQL instance over SQL Express. Overhead of a full SQL instance would be a disadvantage as its simply not necessary.
    - Correct, clients at the remote site would connect to the WSUS instance at the main location to download/access update metadata. The download of this metadata is (depending upon what you have selected in the catalog) generally around 10MB but after that
    it's purely deltas which generally are 500KB per month (the catalog is only updated twice a month by Microsoft).
    - You cannot install reporting services on a secondary site -- is there a specific reason you are wanting to?
    Going back to my first statement above, without knowing the details we can't make a definite recommendation, but using a remote distribution point is the preferred method of handling remote locations in ConfigMgr 2012. The primary generator of traffic in
    ConfigMgr is content transfer (accounting for at least 90% of traffic typically) thus the only traffic you truly need to worry about (once again typically, there are many factors that can potentially influence this) is content from DPs.
    Jason | http://blog.configmgrftw.com

  • Adding ASAv cluster into APIC: Status remains as init

    Hi,
    I've been trying to integrate an ASAv cluster into the APIC, but couldn't seem to get it working. The status remains as "init". However, when I add a standalone ASAv into APIC, the integration seems to work fine. Could someone offer some insight into why this is happening?
    I've attached an XML file describing the fault.
    Basically, what I did was the following:
    1) Set up my 2 ASAv VMs as active-standby with the following configuration:
    - Mgmt IP of 10.88.88.201 for ASAv-Pri and 10.88.88.202 for ASAv-Sec
    - Failover LAN IP of 192.168.0.1 for ASAv-Pri and 192.168.0.2 for ASAv-Sec
    2) Under one of the tenants, I added the ASAv cluster under the L4-L7 Devices, with the necessary interfaces configured. I also configured the necessary interfaces under Parameters, although I'm not sure if I did it correct. I've attached the configuration in xml format for reference (you can remove the *.txt extension)
    Was there something that I did wrongly, or missed out?
    Thanks for reading!

    It looks like your failover configuration is incomplete.  You need to specify the failover_lan_interface under the LAN Failover Interface folder.  The name used should match the interface_name (failover) you specified under the Failover Interface Configuration.
    See the following screenshot for an example:
    Regards,
    Zach

  • Adding another Cluster into existing CSS LB

    Hi,
    Im in the process of adding a new cluster into the existing LB. I understand the concept of configuring a new LB but adding a new network to it is a question.
    I have preconfigured the LB with a new service called SPWeb 1-4 and an assign this to the content owner Central_Platform using VLAN 144 and 145.
    I have one physical connection to the PIX and all port on the PIX is taken. Do I have to setup another physical connection for the new server SPWeb to the PIX?
    Both owners Servcorp and Central_Platform are using separate public IP Subnets.
    Also, please advise if I miss anything and if you have any suggestions.
    Thansks
    !************************* INTERFACE *************************
    interface 1/1
    bridge vlan 200
    interface 2/1
    phy 100Mbits-FD
    description "To PIX"
    bridge vlan 300
    interface 2/2
    phy 100Mbits-FD
    description "To LB switches"
    bridge vlan 301
    interface 2/3
    phy 100Mbits-FD
    bridge vlan 303
    description "Management"
    interface 2/4
    phy 100Mbits-FD
    bridge vlan 144
    description "SPWeb1/2"
    interface 2/5
    phy 100Mbits-FD
    bridge vlan 145
    description "SPWeb3/4"
    !************************** CIRCUIT **************************
    circuit VLAN1
    ip address 192.168.10.1 255.255.255.0
    circuit VLAN300
    ip address (Network 1) 255.255.255.0
    circuit VLAN301
    ip address (Network 1) 255.255.255.0
    circuit VLAN303
    ip address (Network 1) 255.255.255.0
    circuit VLAN144
    ip address (Network 2) 255.255.255.0
    circuit VLAN145
    ip address (Network 2) 255.255.255.0
    !************************** SERVICE **************************
    service TS1
    ip address 172.16.250.1
    active
    service TS2
    ip address 172.16.250.2
    active
    service Spweb1
    ip address 172.16.144.51
    keepalive type HTTP
    active
    service Spweb2
    ip address 172.16.144.52
    keepalive type HTTP
    active
    service Spweb3
    ip address 172.16.145.53
    keepalive type HTTP
    active
    service Spweb4
    ip address 172.16.145.54
    keepalive type HTTP
    active
    !*************************** OWNER ***************************
    owner Servcorp
    content hottdesk.au
    add service TS1
    add service TS2
    protocol tcp
    port 3389
    vip address (Network 1)
    active
    content hottdesk_FTP
    add service TS1
    add service TS2
    port 20
    protocol tcp
    vip address (Network 1)
    active
    content hottdesk_FTP2
    add service TS1
    protocol tcp
    port 21
    application ftp-control
    add service TS2
    vip address (Network 1)
    active
    owner Central_Platform
    content WebServers_1
    add service Spweb1
    add service Spweb2
    protocol tcp
    port 90
    vip address (Network 2)
    active
    content WebServers_2
    add service Spweb3
    add service Spweb4
    protocol tcp
    port 81
    vip address (Network 2)
    active
    content WebServers_3
    add service Spweb3
    add service Spweb4
    protocol tcp
    port 83
    vip address (Network 2)
    active
    !*************************** GROUP ***************************
    group TS-WebAccess
    add service TS2
    add service TS1
    vip address (Network 1)
    active

    It would help if you could attach a picture of the network. I really can't understand why you have 2 VLANs on the same network ? Or am I missing the ide ?
    Generally I would just do VLAN tag towards the PIX and have several networks that way. If speed isn't a issue I see no problems with that.

  • Adding secondary IP address

    When adding a secondary IP addess to the public side of the BM 3.7
    server do we need to specify the mask or can we just do a add secondary
    ipaddress 111.111.111.111

    Hi Pete,
    the secondary Ip address must be in the same subnet as the primary IP
    address, therefore you don't need to add a mask.
    For instance, if the primary is
    192.168.1.1/255.255.255.0
    you can
    ADD SECONDARY IPADDRESS 192.168.1.56
    Note that if you want to bind an IP address that is NOT in the same
    subnet as the primary IP address, you've to use inetcfg.
    Caterina
    Novell Support Connection Volunteer Sysop

  • Adding SQL Cluster to MARS

    What is the best way to add the physical servers and SQL server instances to MARS?
    As a bit of background we have a SQL cluster with 3 physical servers and each one has an ip address. There are also 3 SQL instances with an associated IP address. These are similar in nature to virtual addresses. Both the physical servers and the SQL instances have their own netbios name.
    Do we add both the physical servers and the SQL instances to MARS?

    Hi Fredrik,
    There are alot of events on the IDSSM but these events aren't appeared on MARS although IDSSM is successfully discovered by MARS. That's also happened with Cisco NAC appliance which i added it to MARS but there are no incidents for it on MARS.

  • Adding a Cluster Hyper-V 2012 into SCVMM 2012 SP1 causes a Crash in VMMService.exe

    I'm trying to register a 5 node Cluster into SCVMM 2012 SP1 host, but when the registration job is running the SCVMMService crashes and then registration becomes inconsistent.
    this is the error log from App Event Viewer:
    Event 1000: Application Error:
    Faulting application name: vmmservice.exe, version: 3.1.6011.0, time stamp: 0x50aaba3f
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x000007fae7615fdb
    Faulting process id: 0x1050
    Faulting application start time: 0x01ce1b77516905f8
    Faulting application path: F:\Program Files\Microsoft System Center 2012\Virtual Machine Manager\Bin\vmmservice.exe
    Faulting module path: unknown
    Report Id: a450c591-876d-11e2-93fe-00155d011c01
    Faulting package full name:
    Faulting package-relative application ID:
    Event 1026: .Net Runtime
    Application: vmmservice.exe
    Framework Version: v4.0.30319
    Description: The process was terminated due to an unhandled exception.
    Exception Info: System.NullReferenceException
    Stack:
       at Microsoft.VirtualManager.Engine.RefreshDriver`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].RefreshThreadFunction(System.Object)
       at Microsoft.VirtualManager.Utils.Multithreading.ThrottledThreadPool+<>c__DisplayClass3.<ScheduleNextThread>b__2(System.Object)
       at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
       at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
       at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
       at System.Threading.ThreadPoolWorkQueue.Dispatch()
    Faulting application name: vmmservice.exe, version: 3.1.6011.0, time stamp: 0x50aaba3f
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x000007fae7615fdb
    Faulting process id: 0x1050
    Faulting application start time: 0x01ce1b77516905f8
    Faulting application path: F:\Program Files\Microsoft System Center 2012\Virtual Machine Manager\Bin\vmmservice.exe
    Faulting module path: unknown
    Report Id: a450c591-876d-11e2-93fe-00155d011c01
    Faulting package full name:
    Faulting package-relative application ID:
    Its important that this error occurs only with my Windows 2012 Datacenter cluster, with a Windows 2008R2 Cluster doesn't, and works perfect the registration.
    What's going wrong???
    Thank you very much.

    Dear All,
    I can't find a solution for this error....
    Faulting application name: vmmservice.exe, version: 3.1.6011.0, time stamp: 0x50aaba3fFaulting module name: KERNELBASE.dll, version: 6.2.9200.16451, time stamp: 0x50988aa6Exception code: 0xe0434352Fault offset: 0x000000000003811cFaulting process id: 0x1070Faulting application start time: 0x01cf1b5d8e2c9535Faulting application path: C:\Program Files\Microsoft System Center 2012\Virtual Machine Manager\Bin\vmmservice.exeFaulting module path: C:\Windows\system32\KERNELBASE.dllReport Id: e35b1662-8750-11e3-9417-00155d00795aFaulting package full name: Faulting package-relative application ID: 
    I've a cluster with 2 nodes.
    1) The NIC teaming is configured in the cluster (the VMM is installed in one VM in the cluster).
    2) yes
    3) yes
    Thanks a lot for the replies!
    SF

  • Adding secondary ADFS server to farm fails with Could Not Load Assembly error

    Hi all,
    I have two servers running Server 2012 R2.
    There are two AD sites, in site 1, I have the primary ADFS server running on a member server.  In site 2 I have a secondary ADFS server running on the only DC in the site.  There will be WAP servers publishing these servers in either site.
    I successfully set up the first ADFS server in site 1, and this is working ok.  However, when I set up the server in site 2 I get the following error during the prerequisite checker:
    Could not load file or assembly 'System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089' or one of its dependencies. Access is denied.
    Unable to retrieve configuration from the primary server. Could not load file or assembly 'System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089' or one of its dependencies. Access is denied.
    I ran this as my domain admin account and also as domain\administrator which is seldom used.
    When I run the resulting PowerShell script, I get errors relating to the GSMA, so not sure if that is where my issue lies.  Here is the script:
    # Windows PowerShell script for AD FS Deployment
    Import-Module ADFS
    # Get the credential used for performaing installation/configuration of ADFS
    $installationCredential = Get-Credential -Message "Enter the credential for the account used to perform the configuration."
    Add-AdfsFarmNode `
    -CertificateThumbprint:"Thumbprint Here" `
    -Credential:$installationCredential `
    -GroupServiceAccountIdentifier:"DOMAIN\STSSvc`$" `
    -PrimaryComputerName:"machine.domain.net"
    I tried using the FQDN of the ADFS server as well as the common name of sts.domain.net, neither worked.
    Any suggestions?
    Andrew Hodgson

    Hi,
    Thanks for your post.
    According to the error message, it is more about permission issue.
    Please refer to this artile about how to resolve the error "Could not load file or assembly or one of its dependencies. Access is denied"
    http://blogs.msdn.com/b/sayanghosh/archive/2007/04/21/solution-to-could-not-load-file-or-assembly-or-one-of-its-dependencies-access-is-denied.aspx
    Regards.
    Vivian Wang

  • Adding secondary ACS server

    presently i am using cisco acs version 4.1.1 build 23. now i am planning to add secondary server. After installing the new server. can anyone help me,what are the steps i need to configure.
    do i need to configure all the devices on that server. thanks in advance.

    Hi,
    You dont have to add each device on secodary ACS once the proper replication is configured between two ACS servers.
    Make sure that replication is initiated and done by the primary ACS replicated to the secondary ACS server.
    For more details on replication refer to the following link:
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/SCAdv.html#wp756330
    HTH
    Regards,
    Ahmed

  • Adding Secondary Homepage

    We are trying to add a primary and secondary home page for our users.  Unfortunately "Disable changing home page settings" cannot be used with "Disable changing secondary home page settings".  Our goal is to have our specified
    home page tabs open each time IE is launched.  These two tabs must be placed in #1 & #2 order.  Some people have suggested login scripts but this needs to occur every time IE is opened.  Any suggestions on how to accomplish this would
    be helpful.
    Thank You,
    Eric

    Hi,
    Yes, the Group Policy refresh interval policy setting also applies to Preference. For details about how to configure the refresh interval time, please refer to the following article.
    Group Policy refresh interval for computers
    http://technet.microsoft.com/en-us/library/cc940895.aspx
    Hope it helps.
    Best Regards,
    Andy Qi
    TechNet Subscriber Support
    If you are
    TechNet Subscription user and have any feedback on our support quality, please send your feedback
    here.
    Andy Qi
    TechNet Community Support

  • Adding Secondary DNS entry in server, but Changes didnt take effects

    Hello.
    we have two servers, at time of installation we didnt configured ADC+secondary Dns in our network, so these servers were configured with only DC and Primary DNS server IP. later on we built ADC with secondary DNS, now when we add ADC+secondary DNS
    IP to these server it demands restart. and after restarting no changes made. means it didnt add  the secondary dns ip.
    Please advise

    Hi,
    Maybe you need to registry the secondary DNS server under Networks in the
    Windows Azure management portal. In addition, it seems that you also need to add the secondary DNS server in the
    DNS Servers and VPN Connectivity page.
    More information:
    Setup a Windows Server 2012 R2 Domain Controller in Windows Azure: IP Addressing and Creating a Virtual Network
    Install a Replica Active Directory Domain Controller in Windows Azure Virtual Networks
    In addition, according to the article below, it seems that you can use Powershell to make change in
    .NETCFG files to achieve that.
    Editing DNS in Windows Azure
    Note: Microsoft is providing this information as a convenience to
    you. The sites are not controlled by Microsoft. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.
    Best regards,
    Susie

  • Adding to Cluster Problem

    I have two c350's on separate networks with two firewalls between them.
    When trying to add the second 350 am getting a time out error. When checking the logs it tries to connect to the cluster as anonymous and is refused access.
    any ideas?????

    can you review the following KB article please and verify all the steps?
    http://tinyurl.com/pjmpwh
    once you're done, if there's still trouble, you can include outputs from your 'system_logs' during the failed join.

  • Controls lose data binding when added to cluster

    Please forgive me if this is a newbie question, but I can't seem to find an answer.
    In a nutshell, I have an array (constant) of strings and a cluster of booleans.  I want to search the name of each boolean in the cluster for a match to a string in the array and perform an action for each match.  Say I want to turn on all booleans that match.
    The problem is that the booleans are bound by datasocket - to OPC server to PLC.  So when I add a boolean to the cluster, the data binding is dropped.  Attempts to reassign data binding are unsuccessful.  If I move the control outside the cluster and reassign data binding, it works.  There are a fair number of booleans so I want to avoid wiring them one by one.
    I am using LabVIEW 8.6 and there is a known bug similar to this for arrays of fixed size.  However I don't totally understand the solution and how I would apply it to a cluster:  "Uncheck autopreallocate arrays and strings in the VI properties execution category for all VIs not intended to run on an FPGA."  There is no listing for clusters.  Could I be doing something wrong?  Should I be using shared variables instead of data binding?
    3OLE2573
    Return
    DataSocket and Fixed Size Array Do Not Work
    You cannot use front panel DataSocket data binding with fixed-sized arrays.
    Workaround: Uncheck autopreallocate arrays and strings in the VI properties execution category for all VIs not intended to run on an FPGA.
    Message Edited by Katelyn on 08-18-2009 12:14 PM

    Peter,
    Thanks. i will separate this in 3 questions.
    I posted the whole thing, so people could copy the code on
    Flex and tested to see what I am talking about.
    "evt.target.selectedItem should be a <module> element.
    Is that not happening?"
    Yes, when loading is a module. Once a click on a list item I
    get the following error:
    TypeError: Error #1009: Cannot access a property or method of
    a null object reference.
    at SPADE2/::changeHandler()
    at SPADE2/__cList1_change()
    at
    flash.events::EventDispatcher/flash.events:EventDispatcher::dispatchEventFunction()
    at flash.events::EventDispatcher/dispatchEvent()
    at mx.core::UIComponent/dispatchEvent()
    at
    mx.controls.listClasses::ListBase/mx.controls.listClasses:ListBase::mouseUpHandler()
    at mx.controls::List/mx.controls:List::mouseUpHandler()
    If a click dismiss all, I can click on the tabs and the
    content on the list changes as expected, but when clicking on the
    list items, they don't work.
    If a click on the video tab the state changes, but I have to
    click on the list twice to play a video. After that I the list
    items for the other tabs work.
    Gilbert

Maybe you are looking for

  • Adobe CS3 Windows 7 installation says does not meet minimum requirements

    I am trying to install Adobe Creative Suite 3 Design Premium on a brand new Windows 7 machine (32-bit). It is a downloaded copy from Adobe's website. When I start the install process, it takes me to the "Options" Screen and will not let me install Ph

  • ADOBE: How to print a table only on uneven pages and a text on the back?

    Hi, I am looking for a clear document on how to use pagination and the Odd and Even pages. We need to print a table over several pages, but the table should only appear on Odd pages. The even pages should be skipped. On the even (back) pages we need

  • Set up ix500 scansnap with AP Extreme {6th gen}

    I am having problems getting my ix500 scansnap to set up wirelessly with my AP Extreme 6th generation.  I keep getting a message that the security access is not established and that I need to change the access on the ap extreme.  Not sure how to do t

  • Quotation Mark Issue

    Is there any way to change the default double quotation in Dreamweaver CS4 to a single quotation?  For example: <form name="ex"> to <form name='ex'> Right now if I use the autocomplete for tags I get double quotes.  Is there any way to change that?

  • How to use Tag IDs generically

    Well, its harder to ask this question properly than it is to display an example of what I'm looking for. <jsp:useBean id="myId" class="myClass" /> Now in scriptlet code I can access the methods as so: <% myId.myMethod() %> OK what I want to do is thi