<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE VM Requirements clarification in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771639#M486616</link>
    <description>&lt;P dir="ltr"&gt;Team, I'm&amp;nbsp;looking for clarification on&amp;nbsp;the virtual machine CPU requirements for ISE&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_01.html" target="_blank" rel="noopener noreferrer"&gt;ISE&amp;nbsp;2.4&amp;nbsp;installation&amp;nbsp;guide&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;states the following as CPU requirements for&amp;nbsp;Medium Virtual Appliance:&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Production&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL id="vmwarevmrequirements__ul_gzw_ykl_vx" dir="ltr"&gt;
&lt;LI id="vmwarevmrequirements__li_01E9EFD6047B4D198B1AC5A928FDADC4"&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;Clock Speed—2.0 GHz or faster&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Number of Cores&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN&gt;SNS 3500 Series Appliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;`Medium—16 processors (8 cores with hyperthreading enabled&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;But later in the document it says:&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Table 3. VM Appliance Specifications for a Production Environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE id="ID-1417-00000074__table_33BD9C6B96F14EA18DA5F3F4322DC54E" dir="ltr" border="1" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH id="ID-1417-00000074__table_33BD9C6B96F14EA18DA5F3F4322DC54E__entry__1"&gt;
&lt;P&gt;Platform&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="ID-1417-00000074__table_33BD9C6B96F14EA18DA5F3F4322DC54E__entry__3"&gt;
&lt;P&gt;Medium VM Appliance (based on SNS-3595)&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;Processor&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;8 total cores (at 2.0 GHz or above)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a total minimum CPU allocation of 16000 MHz.&lt;/P&gt;
&lt;TABLE border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="1%"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;
&lt;SECTION&gt;
&lt;P&gt;You must enable hyperthreading and assign the resulting number of logical processors (16) to each server.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;The "&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;OR&lt;/SPAN&gt;&lt;/FONT&gt;" in the above table is what is confusing.&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Question: If the host&amp;nbsp;is running 3.0Ghz clock-speed procs, will TAC support them if they run only 6 cores to achieve the &amp;gt;16000Mhz CPU reservation? This would contradict the core-count requirement&amp;nbsp;of 8 total cores in the&amp;nbsp;red-highlighted&amp;nbsp;section above.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jan 2019 19:48:38 GMT</pubDate>
    <dc:creator>erigglem</dc:creator>
    <dc:date>2019-01-02T19:48:38Z</dc:date>
    <item>
      <title>ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771639#M486616</link>
      <description>&lt;P dir="ltr"&gt;Team, I'm&amp;nbsp;looking for clarification on&amp;nbsp;the virtual machine CPU requirements for ISE&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_01.html" target="_blank" rel="noopener noreferrer"&gt;ISE&amp;nbsp;2.4&amp;nbsp;installation&amp;nbsp;guide&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;states the following as CPU requirements for&amp;nbsp;Medium Virtual Appliance:&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Production&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL id="vmwarevmrequirements__ul_gzw_ykl_vx" dir="ltr"&gt;
&lt;LI id="vmwarevmrequirements__li_01E9EFD6047B4D198B1AC5A928FDADC4"&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;Clock Speed—2.0 GHz or faster&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Number of Cores&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN&gt;SNS 3500 Series Appliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;`Medium—16 processors (8 cores with hyperthreading enabled&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;But later in the document it says:&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Table 3. VM Appliance Specifications for a Production Environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE id="ID-1417-00000074__table_33BD9C6B96F14EA18DA5F3F4322DC54E" dir="ltr" border="1" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH id="ID-1417-00000074__table_33BD9C6B96F14EA18DA5F3F4322DC54E__entry__1"&gt;
&lt;P&gt;Platform&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="ID-1417-00000074__table_33BD9C6B96F14EA18DA5F3F4322DC54E__entry__3"&gt;
&lt;P&gt;Medium VM Appliance (based on SNS-3595)&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;Processor&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;8 total cores (at 2.0 GHz or above)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a total minimum CPU allocation of 16000 MHz.&lt;/P&gt;
&lt;TABLE border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="1%"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;
&lt;SECTION&gt;
&lt;P&gt;You must enable hyperthreading and assign the resulting number of logical processors (16) to each server.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;The "&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;OR&lt;/SPAN&gt;&lt;/FONT&gt;" in the above table is what is confusing.&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Question: If the host&amp;nbsp;is running 3.0Ghz clock-speed procs, will TAC support them if they run only 6 cores to achieve the &amp;gt;16000Mhz CPU reservation? This would contradict the core-count requirement&amp;nbsp;of 8 total cores in the&amp;nbsp;red-highlighted&amp;nbsp;section above.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2019 19:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771639#M486616</guid>
      <dc:creator>erigglem</dc:creator>
      <dc:date>2019-01-02T19:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771727#M486626</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a great question. In general when using multithreaded application more cores is better. Here is a reference article I found that would explain how it works.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://create.pro/blog/cores-faster-cpu-clock-speed-explained/" target="_blank"&gt;https://create.pro/blog/cores-faster-cpu-clock-speed-explained/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I think this is a bug in the documentation. I will reach out to the relevant team.&lt;/P&gt;
&lt;P&gt;Thank you for pointing this out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Krishnan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2019 21:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771727#M486626</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2019-01-02T21:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771738#M486634</link>
      <description>&lt;P&gt;The hyper threading thing is just confusing because it has nothing to do with the VM setup itself.&amp;nbsp; If you load up the new OVAs Cisco provide a 3515 will be provisioned with 12 CPUs and 12,000 MHz of reservations and the 3595 will be setup with 16 CPUs and 16,000 MHz of reservations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now if the ESX host server has hyper threading enabled the 12 CPUs will only consume 6 CPUs and the 16 CPUs will only consume 8 CPUs, but this has absolutely nothing to do with the VM itself.&amp;nbsp; The VM will always think it has 12 or 16 CPUs.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2019 21:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771738#M486634</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-01-02T21:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771739#M486639</link>
      <description>&lt;P&gt;Thanks Krishan - can you please reply back when you receive an answer from the relevant team? Much appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2019 21:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771739#M486639</guid>
      <dc:creator>erigglem</dc:creator>
      <dc:date>2019-01-02T21:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771741#M486646</link>
      <description>&lt;P&gt;Also, if you don't put the right number of CPUs in the VM, ISE won't detect the platform correctly and allocate resources.&amp;nbsp; That was the whole issue with the OVAs since 2.2.&amp;nbsp; The OVAs had the wrong number of CPUs causing ISE to not detect the correct platform.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2019 21:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771741#M486646</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-01-02T21:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771750#M486651</link>
      <description>Recommend looking at the performance and scale cisco live for deep details as well&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944#toc-hId-1281981443" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944#toc-hId-1281981443&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Jan 2019 21:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771750#M486651</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-02T21:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771904#M486654</link>
      <description>&lt;P&gt;&lt;A href="https://www.reddit.com/r/vmware/comments/3hpwn5/vmware_esxi_more_cores_or_faster_cores/" target="_blank"&gt;VMware ESXi - More cores or faster cores? : vmware&lt;/A&gt;&amp;nbsp;is a good read. Certain tasks in ISE are more CPU-bound; e.g. massy re-profiling and during ISE service initialization. Best to monitor the work loads of various ISE nodes and adjust accordingly.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 05:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3771904#M486654</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-01-03T05:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899112#M486763</link>
      <description>Hi, Have you gotten any updates about this? I run into the same question.</description>
      <pubDate>Mon, 29 Jul 2019 09:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899112#M486763</guid>
      <dc:creator>taasai</dc:creator>
      <dc:date>2019-07-29T09:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899379#M486765</link>
      <description>Regardless of a follow up from Krishnan, I will say that you're going to want the correct number of vCPU/cores regardless of the MHz you configuration provides.  The reason being is that the platform profile (3515 - 3695) won't be allocated correctly if the VM doesn't meet the template.  ISE could boot up with a base/default/platform profile.  From a VMware perspective, you are hard allocating between 12,000 and 24,000 Mhz now depending on the vm template.  How many cores you assign is irrelevant to VMware, the vcpu is an entirely logical construct that you can over allocate, you cannot however over allocate the finite MHz reservations.&lt;BR /&gt;&lt;BR /&gt;Licensing also looks at the vCPU mapping and memory in order to determine if you are licensed correctly, this might be less of an issue since reducing the number of cores should be covered by the larger license still.  &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I would however go out on a limb here and say that the physical appliances perform better than VM's for the sole reason that they are not bound to the VM reservation limit.  The Cisco OVA templates have both a 12,000-24,000 MHz reservation, but they also have the exact same limit set.  A 3595 had a single CPU with 8 x 2.6 GHz cores, this meant the physical appliance had 20800 MHz available, while our VM's only had 16,000 Mhz.</description>
      <pubDate>Mon, 29 Jul 2019 15:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899379#M486765</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-29T15:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899425#M486768</link>
      <description>Just a quick correction Damien.  Cisco has removed the CPU max limit from their OVAs and admitted that it was a mistake to have those in there in the first place.  16,000 MHz is reserved for a 3595 but no upper limit.  So the system can use more if needed.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Jul 2019 16:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899425#M486768</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-07-29T16:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM Requirements clarification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899427#M486774</link>
      <description>That's good to know, makes a lot more sense.  Haven't deployed a new OVA myself in a while.</description>
      <pubDate>Mon, 29 Jul 2019 16:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-requirements-clarification/m-p/3899427#M486774</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-29T16:54:33Z</dc:date>
    </item>
  </channel>
</rss>

