<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE SDA Deployment Sizing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sda-deployment-sizing/m-p/3867482#M472547</link>
    <description>&lt;P&gt;Thanks Jason!&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2019 15:02:32 GMT</pubDate>
    <dc:creator>Krzysztof Grabowski</dc:creator>
    <dc:date>2019-06-04T15:02:32Z</dc:date>
    <item>
      <title>ISE SDA Deployment Sizing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sda-deployment-sizing/m-p/3865655#M472545</link>
      <description>&lt;P dir="ltr"&gt;Hi Guys,&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;I have a question regarding ISE sizing in context of maximum supported authentications per second. ISE Performance and Scale provides unidirectional numbers for different authentication types (PAP/EAP-TLS etc... ) but does not provide a recommendation on number of PSN's.&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;One of my customers challenged my why not to use a single pair of SNS-3695's running PAN+MnT+PSN&amp;nbsp;for an SDA deployment which according to papers should support up to 50K sessions in 2.6. I think that it is&amp;nbsp;a risky approach due to PAN and MnT load and potential RADIUS congestion (in case of spike like WLC reload or major outage-recovery situation)&amp;nbsp;but with data on ISE Performance and Scale I don't have solid arguments to defend my position to recommend hybrid/distributed deployment with more than 2 PSNs.&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;Could you please let me know what are the recommendations for number of PSNs with regards to auth/second rate? This dimension of ISE&amp;nbsp;scaling seem to be a grey zone with no clear recommendations...&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;Cheers,&lt;BR /&gt;Chris&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 09:48:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sda-deployment-sizing/m-p/3865655#M472545</guid>
      <dc:creator>Krzysztof Grabowski</dc:creator>
      <dc:date>2019-05-31T09:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SDA Deployment Sizing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sda-deployment-sizing/m-p/3865800#M472546</link>
      <description>The information for everything running on one box as standalone with HA is the best scenario. If customer is starting with less than 50k then this is a good starting design depending on how network is design and tuned following Cisco live guidelines . Once approaching limit would evaluate system performance and anticipate a need to split out the PSNs where needed into a medium distributed model.&lt;BR /&gt;&lt;BR /&gt;The limits are tested and recommended per that testing to include all persona models accordingly&lt;BR /&gt;&lt;BR /&gt;I would also recommend looking at the information from BRKSEC-2059 and the BRKSEC-3432 from Cisco live training site&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 31 May 2019 14:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sda-deployment-sizing/m-p/3865800#M472546</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-05-31T14:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SDA Deployment Sizing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sda-deployment-sizing/m-p/3867482#M472547</link>
      <description>&lt;P&gt;Thanks Jason!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 15:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sda-deployment-sizing/m-p/3867482#M472547</guid>
      <dc:creator>Krzysztof Grabowski</dc:creator>
      <dc:date>2019-06-04T15:02:32Z</dc:date>
    </item>
  </channel>
</rss>

