<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE VM Large used as PAN, PSN, PxGrid in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3911698#M484862</link>
    <description>&lt;P&gt;Large VM which essentially had more resources, was introduced to improve the MnT performance. We clearly mentioned that this can be used as an MnT node only since we did not qualify the other personas on the large VM. Hence not recommended.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but having said that, you can still allocate more resources to your PAN and PSN nodes other than the standard available.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the equivalent of large VM is the new 3695 appliances which can run any of the personas today.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;with 2.4 patch 9, on 3695 as PAN and MnT , the max concurrent sessions supported is 500k sessions. there were some code changes done to achieve 2 M in 2.6 hence we dont recommend scaling beyond 2.4 scaling numbers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nidhi&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2019 14:43:14 GMT</pubDate>
    <dc:creator>Nidhi</dc:creator>
    <dc:date>2019-08-21T14:43:14Z</dc:date>
    <item>
      <title>ISE VM Large used as PAN, PSN, PxGrid</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3809134#M484851</link>
      <description>&lt;P&gt;In the ISE installation guide, it states that ISE Large VM cannot be used as PAN, PSN or PxGrid. Is it a hard restriction (system will check and prevent such configuration?) or just a suggestion? I am planning to have a 6-node design where all 6 nodes are VM Large based on SNS3695. PAN and PSN will be designated on Large VM. Is it a supported design?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"The Large memory size is only for use as a performance-enhanced MnT node. You cannot use the Large VM as a PAN, PSN, or pxGrid node."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 03:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3809134#M484851</guid>
      <dc:creator>fellai</dc:creator>
      <dc:date>2019-03-09T03:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Large used as PAN, PSN, PxGrid</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3809142#M484853</link>
      <description>&lt;P&gt;It sounds like you are reading the ISE 2.4 guide, or there is a typo in the 2.6 guide, link what you were reading and we can clear it up. Using a large VM for all roles is supported in 2.6 and in standalone (1-2 nodes), or hybrid (PAN/MNT same nodes, 7 nodes max), with scale up to 50,000 active endpoints. &lt;BR /&gt;&lt;BR /&gt;It would probably be wise to use 6 or 8x3655 appliances. This for example would have peak support for 200k active, and 100k if half the PSN's failed. 50k active per 3655 PSN in a dedicated deployment. &lt;BR /&gt;2xPAN&lt;BR /&gt;2x MNT&lt;BR /&gt;4x PSN - 200k total, 100k HA&lt;BR /&gt;&lt;BR /&gt;optional, use 2 3655 PSN&lt;BR /&gt;2x PSN - 100k total, 50k HA&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 17:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3809142#M484853</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-25T17:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Large used as PAN, PSN, PxGrid</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3809218#M484855</link>
      <description>that's referring to the Super MNT as something like the 3695 size introduced in 2.6. in 2.4 it will get your a faster reporting, in , it can certainly be used but just overkill. in 2.6 will give you 2M active endpoints (dot1x/mab only)&lt;BR /&gt;&lt;BR /&gt;3655 will give you 500k active endpoints with separate PAN/MNT&lt;BR /&gt;&lt;BR /&gt;Or a distributed deployment of 2 PAN/MNT on same box and up to 5 separate PSNs&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I would recommend looking at the cisco live slides for Designing ISE for Scale &amp;amp; High Availability as well&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944#toc-hId-1281981443" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944#toc-hId-1281981443&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 25 Feb 2019 17:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3809218#M484855</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-02-25T17:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Large used as PAN, PSN, PxGrid</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3908583#M484857</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320219"&gt;@Damien Miller&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Apologies for digging this subject up again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I understand Damien's point, running LARGE VM on any persona is technically OK because the software will run and not complain about it.&amp;nbsp; And Cisco TAC should hopefully have no issues supporting a non-MnT node deployed as a VM LARGE?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It was always my understanding that throwing more RAM and CPU at the MnT made sense because this persona could benefit from it.&amp;nbsp; My question is, what benefit would a &lt;STRONG&gt;PAN node&lt;/STRONG&gt; get if it had 256GB RAM?&amp;nbsp; It doesn't change any of the hard limits of 2 million endpoints, right?&amp;nbsp; In my opinion, this RAM would be wasted (or at best, used by Linux as a cache of some sort).&amp;nbsp; And what significance does more RAM and CPU have for &lt;STRONG&gt;a PSN&lt;/STRONG&gt;?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would never want to stop anyone buying LARGE VM licenses if they can afford it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I am more interested in what effect it has on the different Personas.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 11:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3908583#M484857</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-08-15T11:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Large used as PAN, PSN, PxGrid</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3908592#M484859</link>
      <description>Adding my 2 cents here.&lt;BR /&gt;&lt;BR /&gt;IMHO, adding more resources to PAN helps when there is large deployment of say 10 + nodes. PAN does a lot of functions and it just is not an interface for configuration. There are so many micro services that run in PAN that bring coordination between different features/components. For example, Endpoint persistence from various PSN when any change is done to an endpoint, maintaining the configuration in sync across all the nodes in the deployment (replication and JGroups are no joke, they can seriously consume a lot of resources in a big deployment), maintenance work is done predominantly done on the PAN and most importantly, the number of calls it needs to make to each and every node in the deployment to display whatever you see in the ISE GUI. All of these are not easily done and one of the very reason where we push for a separate node for PAN in a deployment. Improving resources will improve the experience of the admin using ISE and also greatly reduces the risk of any sort of issues in the deployment. For the PSN, it is just not one server if you look at it in a much deeper split. PSN hosts two apache servers one for regular ISE operations and one for CA services. Practically every persona on a PSN is a service in its own and they put their share of load on all of it. With the increasing number of endpoints that hit a PSN, the load increases in a way exponentially. Having said this, all things considered, the recommendation is given by our PMs and TMEs in the performance and scaling guide. However, increasing resources to a node is not a bad thing at all and having large VMs for each node is a safe haven approach for ISE.&lt;BR /&gt;</description>
      <pubDate>Thu, 15 Aug 2019 11:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3908592#M484859</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-08-15T11:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Large used as PAN, PSN, PxGrid</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3908739#M484861</link>
      <description>I would have a concern that not running a standard vm template could result in the wrong platform properties being picked up at boot.  &lt;BR /&gt;&lt;BR /&gt;The platform properties file sets various components such as java memory allocation, tomcat threads, oracle settings, profiler settings, etc. So if a VM gets picked up as something other than a SNS35x5 or SNS 36x5 template, it could use a UCS or some default and cause all sorts of issues.  &lt;BR /&gt;&lt;BR /&gt;Now that 2.6 supports 3695 VM's for any persona, and 2.4 p9 includes platform properties for 36x5 templates, I suspect there is little risk if you were running 2.4 P9 on a 3695 template.  I wouldn't push endpoint counts beyond what 2.4 was tested for.</description>
      <pubDate>Thu, 15 Aug 2019 16:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3908739#M484861</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-08-15T16:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Large used as PAN, PSN, PxGrid</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3911698#M484862</link>
      <description>&lt;P&gt;Large VM which essentially had more resources, was introduced to improve the MnT performance. We clearly mentioned that this can be used as an MnT node only since we did not qualify the other personas on the large VM. Hence not recommended.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but having said that, you can still allocate more resources to your PAN and PSN nodes other than the standard available.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the equivalent of large VM is the new 3695 appliances which can run any of the personas today.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;with 2.4 patch 9, on 3695 as PAN and MnT , the max concurrent sessions supported is 500k sessions. there were some code changes done to achieve 2 M in 2.6 hence we dont recommend scaling beyond 2.4 scaling numbers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nidhi&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 14:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-large-used-as-pan-psn-pxgrid/m-p/3911698#M484862</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2019-08-21T14:43:14Z</dc:date>
    </item>
  </channel>
</rss>

