<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: It would be supported. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/3953520#M37511</link>
    <description>&lt;P&gt;Sorry, if I warm up this thread again.&lt;BR /&gt;I've come across this question so often. Recently, even from Cisco side this was shown in a upgrade demo. A Cisco employee said that this is a valid small hybrid deployment. However, the ISE Installation Guide specifically states "Hybrid-Distributed deployment (Admin and MnT on same appliance; Policy Service on dedicated appliance)" and "In a medium-sized network deployment, you can not enable the policy persona on a node that runs the Administration persona, Monitoring persona, or Both. You need dedicated policy service node (s) ". So there is probably still need for explanation here.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#reference_A4A76D628B6847EDB1715F2C11C3B753" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#reference_A4A76D628B6847EDB1715F2C11C3B753&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Nov 2019 17:49:13 GMT</pubDate>
    <dc:creator>Uwe Siegrist</dc:creator>
    <dc:date>2019-11-05T17:49:13Z</dc:date>
    <item>
      <title>Cisco ISE Hybrid Distributed Node Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949158#M37486</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is it possible or recommended to have the deployment shown below; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Node 1 - Running Admin+MnT (Primary)+&lt;STRONG&gt;PSN&lt;/STRONG&gt; - SNS3595 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Node 2 - Running Admin+MnT (Secondary)+&lt;STRONG&gt;PSN&lt;/STRONG&gt; - SNS3595 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Node 3 - PSN - SNS3515 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Node 4 - PSN - SNS3515 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How many endpoints would such a deployment handle? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How many PSN nodes would it support max?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:15:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949158#M37486</guid>
      <dc:creator>edwardonelife</dc:creator>
      <dc:date>2019-03-11T07:15:01Z</dc:date>
    </item>
    <item>
      <title>Hi Edward,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949159#M37489</link>
      <description>&lt;P&gt;Hi Edward,&lt;/P&gt;
&lt;P&gt;You would be interested in this document below:&lt;/P&gt;
&lt;P&gt;https://communities.cisco.com/docs/DOC-68347&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kanwal&lt;/P&gt;
&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 20:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949159#M37489</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2016-11-23T20:10:21Z</dc:date>
    </item>
    <item>
      <title>20,000 concurrent endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949160#M37496</link>
      <description>&lt;P&gt;20,000 concurrent endpoints max - that is noted on Craig's document which Fnu shared. To get to that you would need at least three SNS-3515 level appliances with ISE 2.1 (or 4 with ISE 2.0.1).&lt;/P&gt;
&lt;P&gt;However a single PSN on SNS-3595 could handle it.&lt;/P&gt;
&lt;P&gt;You could put a maximum of 5 PSNs in a deployment with combined PAN + MnT nodes. However, without a load balancing scheme in place, their use will be constrained based on capabilities of your NADs to load balance RADIUS natively.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 03:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949160#M37496</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-11-24T03:47:29Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949161#M37501</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;Based on the below setup, what do you think will be the&amp;nbsp;maximums?&lt;/P&gt;
&lt;P&gt;Is it a supported deployment?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Node 1 - Running Admin + MnT (Primary) + PSN - SNS3595&lt;/P&gt;
&lt;P&gt;Node 2 - Running Admin + MnT (Secondary) + PSN - SNS3595&lt;/P&gt;
&lt;P&gt;Node 3 - PSN - SNS3515&lt;/P&gt;
&lt;P&gt;Node 4 - PSN - SNS3515&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 06:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949161#M37501</guid>
      <dc:creator>edwardonelife</dc:creator>
      <dc:date>2016-11-24T06:57:50Z</dc:date>
    </item>
    <item>
      <title>It would be supported.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949162#M37506</link>
      <description>&lt;P&gt;It would be supported.&lt;/P&gt;
&lt;P&gt;The maximum concurrent sessions would be 20,000 with just the first two nodes you listed. Adding Node 3 and Node 4 in that scenario would not do a lot for you unless you have some intelligent load balancing to allocate &amp;nbsp;RADIUS sessions among the PSNs.&lt;/P&gt;
&lt;P&gt;Remember a given NAD is limited in its ability to use multiple RADIUS servers. A Cisco WLC, for example, will only ever use the first defined RADIUS server for a given SSID as long as it is reachable. A Cisco switch with a 15.x IOS will do crude round robin load balancing of RADIUS server. 12.x IOS will not.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 13:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/2949162#M37506</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-11-24T13:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: It would be supported.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/3953520#M37511</link>
      <description>&lt;P&gt;Sorry, if I warm up this thread again.&lt;BR /&gt;I've come across this question so often. Recently, even from Cisco side this was shown in a upgrade demo. A Cisco employee said that this is a valid small hybrid deployment. However, the ISE Installation Guide specifically states "Hybrid-Distributed deployment (Admin and MnT on same appliance; Policy Service on dedicated appliance)" and "In a medium-sized network deployment, you can not enable the policy persona on a node that runs the Administration persona, Monitoring persona, or Both. You need dedicated policy service node (s) ". So there is probably still need for explanation here.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#reference_A4A76D628B6847EDB1715F2C11C3B753" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#reference_A4A76D628B6847EDB1715F2C11C3B753&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 17:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/3953520#M37511</guid>
      <dc:creator>Uwe Siegrist</dc:creator>
      <dc:date>2019-11-05T17:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/3953539#M37513</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/71898"&gt;@edwardonelife&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;Based on the below setup, what do you think will be the&amp;nbsp;maximums?&lt;/P&gt;
&lt;P&gt;Is it a supported deployment?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Node 1 - Running Admin + MnT (Primary) + PSN - SNS3595&lt;/P&gt;
&lt;P&gt;Node 2 - Running Admin + MnT (Secondary) + PSN - SNS3595&lt;/P&gt;
&lt;P&gt;Node 3 - PSN - SNS3515&lt;/P&gt;
&lt;P&gt;Node 4 - PSN - SNS3515&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This is not supported. Once you install a PSN outside of the node running admin and/or MNT then its a distributed hybrid model and policy services needs to be disabled on any node running admin and/or MNT&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#reference_A4A76D628B6847EDB1715F2C11C3B753" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#reference_A4A76D628B6847EDB1715F2C11C3B753&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 18:21:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/3953539#M37513</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-11-05T18:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/3953581#M37516</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;thank you for your clarification.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 19:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hybrid-distributed-node-deployment/m-p/3953581#M37516</guid>
      <dc:creator>Uwe Siegrist</dc:creator>
      <dc:date>2019-11-05T19:42:54Z</dc:date>
    </item>
  </channel>
</rss>

