<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2 node deployment at multiple sites in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923811#M457173</link>
    <description>So I have few questions on this:&lt;BR /&gt;&lt;BR /&gt;1. If one ISE box (running all personas) is placed in US and other in India, would it be recommended to configure them in HA?&lt;BR /&gt;2. What's the recommended latency for ISE-AD integration and ISE-NAD?&lt;BR /&gt;3. For instance, integrating US_ISE_node with UK_AD, though they are in different timezone, would be a challenge for NTP sync?</description>
    <pubDate>Fri, 13 Sep 2019 10:24:44 GMT</pubDate>
    <dc:creator>raksec</dc:creator>
    <dc:date>2019-09-13T10:24:44Z</dc:date>
    <item>
      <title>ISE 2 node deployment at multiple sites</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923793#M457134</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a requirement, below is the detail:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. There are a total of 2500 endpoints&lt;/P&gt;
&lt;P&gt;2. Total number of sites are 16 across the globe (7 sites in US, 3 in UK, 1 in Japan, 1 in Singapore, 2 in India, rest in other APJC locations). Each sites having on-prem Active Directory (active/standby)&lt;/P&gt;
&lt;P&gt;3. ISE will be licensed for Base, Plus, Apex and device administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Considering just 2500 endpoints and customer's budget, we are suggesting 2-node deployment, one node in US and other node in India. So US_ISE_node has to be integrated with ADs in US and UK and India_ISE_node with ADs in APJC. Please suggest if there are any challenges for ISE redundant node deployment and ISE-AD integrations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Rakesh Kumar&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 09:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923793#M457134</guid>
      <dc:creator>raksec</dc:creator>
      <dc:date>2019-09-13T09:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2 node deployment at multiple sites</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923801#M457138</link>
      <description>&lt;P&gt;if i were you. i would deploy each 2xPSN at each country (2xUK,2xJP,2xSingapoor) and so on. two because if the one PNS goes down the other will pick it up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the PAN side you can keep in the one main location and add your ADs&amp;nbsp; to PAN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 10:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923801#M457138</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-09-13T10:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2 node deployment at multiple sites</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923804#M457147</link>
      <description>Unfortunately, this design is not affordable to customer. We have to cut the number of PSNs to as minimum as possible.</description>
      <pubDate>Fri, 13 Sep 2019 10:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923804#M457147</guid>
      <dc:creator>raksec</dc:creator>
      <dc:date>2019-09-13T10:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2 node deployment at multiple sites</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923808#M457156</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As long as the ADs are integrated in ISE this should not be a problem. however, NTP needs to keep in syn all the time. if you using hardware NTP that would be ideal. apart from that would be ideal if customer could spend more monies on the ISE. however, if that that case with limit budget.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 10:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923808#M457156</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-09-13T10:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2 node deployment at multiple sites</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923811#M457173</link>
      <description>So I have few questions on this:&lt;BR /&gt;&lt;BR /&gt;1. If one ISE box (running all personas) is placed in US and other in India, would it be recommended to configure them in HA?&lt;BR /&gt;2. What's the recommended latency for ISE-AD integration and ISE-NAD?&lt;BR /&gt;3. For instance, integrating US_ISE_node with UK_AD, though they are in different timezone, would be a challenge for NTP sync?</description>
      <pubDate>Fri, 13 Sep 2019 10:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923811#M457173</guid>
      <dc:creator>raksec</dc:creator>
      <dc:date>2019-09-13T10:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2 node deployment at multiple sites</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923894#M457174</link>
      <description>&lt;P&gt;Here are my thoughts/questions without knowing all the details:&lt;BR /&gt;IMO when customer requirements come out I always bump the number of endpoints up for future growth. So 2500 endpoints could potentially be 3000. What are the desired needs to have base, plus, &amp;amp; apex licenses?&amp;nbsp; Could you save money here to deploy additional PSN/s?&lt;BR /&gt;My recommendation would be 2 PANs, 2 PSNs if you cannot do what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;suggested.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 13:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-node-deployment-at-multiple-sites/m-p/3923894#M457174</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-09-13T13:02:58Z</dc:date>
    </item>
  </channel>
</rss>

