<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAC limitation and performance impact for adding to ISE database for MAC auth bypass in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mac-limitation-and-performance-impact-for-adding-to-ise-database/m-p/4031687#M453866</link>
    <description>&lt;P&gt;I came in to a customers 2.4 deployment which was up to 4.9 million known endpoints in the context visibility database.&amp;nbsp; There was no observable performance impact due to that.&amp;nbsp; The only impact was to me as an admin, exporting the endpoint database resulted in a 5GB csv file that was a pain to use, excel no longer works since it's only happy with less than a million rows.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have since enabled aggressive purge policies and dropped that back down to around 500k.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My experience has been that, profiling and accounting syslogs result in more of an impact than just having endpoints in the DB.&amp;nbsp; &amp;nbsp;the&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Feb 2020 16:35:46 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2020-02-18T16:35:46Z</dc:date>
    <item>
      <title>MAC limitation and performance impact for adding to ISE database for MAC auth bypass</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-limitation-and-performance-impact-for-adding-to-ise-database/m-p/4031214#M453864</link>
      <description>&lt;P&gt;&lt;SPAN&gt;1 trying to figure out if there is a known upper limit to the number of MACs that can be added to the ISE database for MAC auth bypass&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 Would the customer see a performance hit as the near they MAC limit?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 21:44:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-limitation-and-performance-impact-for-adding-to-ise-database/m-p/4031214#M453864</guid>
      <dc:creator>jlubick</dc:creator>
      <dc:date>2020-02-17T21:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: MAC limitation and performance impact for adding to ISE database for MAC auth bypass</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-limitation-and-performance-impact-for-adding-to-ise-database/m-p/4031277#M453865</link>
      <description>&lt;P&gt;The maximum number of endpoints in ISE 2.6 is 2,000,000.&amp;nbsp; Check out this post: &amp;nbsp;&lt;FONT&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;My guess is that as that number increases and gets large, the MAC lookup may take slightly longer; however, I wouldn't think it would be noticeable by the end user.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 00:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-limitation-and-performance-impact-for-adding-to-ise-database/m-p/4031277#M453865</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-02-18T00:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: MAC limitation and performance impact for adding to ISE database for MAC auth bypass</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-limitation-and-performance-impact-for-adding-to-ise-database/m-p/4031687#M453866</link>
      <description>&lt;P&gt;I came in to a customers 2.4 deployment which was up to 4.9 million known endpoints in the context visibility database.&amp;nbsp; There was no observable performance impact due to that.&amp;nbsp; The only impact was to me as an admin, exporting the endpoint database resulted in a 5GB csv file that was a pain to use, excel no longer works since it's only happy with less than a million rows.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have since enabled aggressive purge policies and dropped that back down to around 500k.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My experience has been that, profiling and accounting syslogs result in more of an impact than just having endpoints in the DB.&amp;nbsp; &amp;nbsp;the&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 16:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-limitation-and-performance-impact-for-adding-to-ise-database/m-p/4031687#M453866</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-02-18T16:35:46Z</dc:date>
    </item>
  </channel>
</rss>

