Adding a new ISE node to the deployment

Below are the steps to add a new ISE node to the deployment:

Preparation: You need to have the below prerequisites before you try to add the new ISE node:

  1. DNS records must be created in the DNS server for the new ISE node. The FQDN of the primary PAN and the node being registered must be resolvable from each other.
  2. NTP and time zone must be configured on new ISE node
  3. Admin GUI credentials for the new ISE node.
  4. AD credentials to join the nodes to the deployment
  5. The new ISE node should be in same version and patch  number as the deployment
  6. The domain of ISE nodes could be different.


Adding a new ISE node to the deployment:

  1. Login to the Primary admin Node (PAN) GUI.
  2. Go to Administration > System > Deployment.
  3. Click on “Register” to initiate registration of a secondary node.
  4. Enter the FQDN of the new ISE node that you are going to register. For example:
  5. Enter the GUI credentials of new ISE node in the Username and Password fields. For example: Username: Admin, Password: Passw0rD
  1. Click Next. The PAN tries to establish TLS communication with new ISE node.
  2. If the new node uses a CA signed certificate, then no warning message will be displayed.
  3. If the new node uses a self-signed certificate that is not trusted, a certificate warning message is displayed as below. In this case, click “Import Certificate and proceed” if you choose to import the CA signed certificate later.

  1. Then, you need to select the personas and services to be enabled on the node, and then click Save.
  2. The new ISE node will start synching with PAN. You can see the status in the deployment page as “In progress”. Finally, the status will change to green.

Joining the new ISE node to the Active directory:

  1. If you want to join the new ISE node to the Active directory, then click on Administration > Identity Management > External Identity Sources > Active directory > (Choose the AD domain name)
  2. Select the new ISE node and click on join.
  3. Insert the AD credentials under AD username and Password field and click on OK.
  4. After few minutes, the status will change to green.


Now you have successfully added a new ISE node to the existing deployment.

Leave a Reply

Your email address will not be published.