<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE EAP-TLS performance question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853616#M473223</link>
    <description>&lt;P&gt;Sorry I should make it clear 1.x is for their existing cluster. For new cluster they will go with 2.4 or 2.6. Existing ISE 1.x cluster has more than 10 PSN, however for new cluster customer plan only two PSN and they are not sure if 3595 has enough capacity thus the question. thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2019 01:19:41 GMT</pubDate>
    <dc:creator>alehsieh</dc:creator>
    <dc:date>2019-05-10T01:19:41Z</dc:date>
    <item>
      <title>ISE EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853131#M473219</link>
      <description>&lt;P&gt;hi experts:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; My customer plan to purchase new ISE cluster to replace the old ones. Primary authentication is&lt;/P&gt;
&lt;P&gt;EAP-TLS+DACL. Couple of questions from customer:&lt;/P&gt;
&lt;P&gt;1. From the scale guide section ISE 2.4 RADIUS Performance, it mentioned concurrent EAP-TLS radius auth is 320 for 3595. Does this number factor into DACL processing?&lt;/P&gt;
&lt;P&gt;2. How can we find out peak concurrent authentication in existing ISE so that can purchase hardware with enough capacity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 12:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853131#M473219</guid>
      <dc:creator>alehsieh</dc:creator>
      <dc:date>2019-05-09T12:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853524#M473220</link>
      <description>&lt;P&gt;It doesn't factor in dACL processing. But, dACL process isn't taxing as full EAP transaction. It would be close to what PAP would be using internal DB as long as the dACL size is within reason. If using auth/sec, I suggest adding 10-15% overhead to EAP-TLS performance number to account for dACL. Since dACL process doesn't add to the session maintenance on the ISE node, # of concurrent endpoints will not change.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 21:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853524#M473220</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-05-09T21:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853613#M473221</link>
      <description>&lt;P&gt;hi Hosuk:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; Thanks for your explanation it's really helpful. By the way customer is still not sure to order 3595 or 36xx hardware. Do you know where I can find peak authentication request per second statistics on ISE 1.x? This way they can purchase appropriate hardware. thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 01:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853613#M473221</guid>
      <dc:creator>alehsieh</dc:creator>
      <dc:date>2019-05-10T01:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853614#M473222</link>
      <description>&lt;P&gt;ISE 1.x can't run on SNS-3500 or SNS-3600. I would suggest recommending customer to go to 2.4 or 2.6.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 01:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853614#M473222</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-05-10T01:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853616#M473223</link>
      <description>&lt;P&gt;Sorry I should make it clear 1.x is for their existing cluster. For new cluster they will go with 2.4 or 2.6. Existing ISE 1.x cluster has more than 10 PSN, however for new cluster customer plan only two PSN and they are not sure if 3595 has enough capacity thus the question. thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 01:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853616#M473223</guid>
      <dc:creator>alehsieh</dc:creator>
      <dc:date>2019-05-10T01:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853620#M473224</link>
      <description>&lt;P&gt;Please reach out to me directly howon@cisco.com.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 01:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-tls-performance-question/m-p/3853620#M473224</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-05-10T01:27:31Z</dc:date>
    </item>
  </channel>
</rss>

