<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed deployment PSN scale in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777036#M488159</link>
    <description>&lt;P&gt;I think your TAC case likely on&amp;nbsp;some older ISE release. I am pretty sure ISE 2.4 will adjust the parameters after the CPU/RAM resized. Even an&amp;nbsp;older ISE release will update the parameters if a change made to the persona(s) of the ISE node.&lt;/P&gt;
&lt;P&gt;Besides the optimization&amp;nbsp;done with the system parameters, ISE and the underlying Linux will still take some advantage of the enlarged RAM allocation.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2019 16:32:18 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2019-01-10T16:32:18Z</dc:date>
    <item>
      <title>Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747773#M488149</link>
      <description>&lt;P&gt;The performance and scale document shows that the max number of PSN's in a deployment is 40 for a 3495 as PAN and 50 for a 3595 as PAN.....In a VM environment of 2.3 with an OVA for 3495 on all does this mean that you can re image each admin node with a 3595 OVA to extend to 50 leaving the PSN's alone with 3495 images? We're at 39 Nodes that include 2x admin and 2x MnT, 35 PSN's so I'm trying to plan ahead what adding 5 more PSN's may look like.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also do Node Groups lower or raise that number?&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 00:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747773#M488149</guid>
      <dc:creator>mitchp75</dc:creator>
      <dc:date>2018-11-16T00:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747844#M488150</link>
      <description>Pretty much. PSN scalability is a factor of PAN and MnT sizing, just make sure they are on dedicated nodes.</description>
      <pubDate>Fri, 16 Nov 2018 06:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747844#M488150</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2018-11-16T06:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747857#M488151</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I guess instead of reimaging the VM, you can extend the VM sizing similar to 3595.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Aravind&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 07:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747857#M488151</guid>
      <dc:creator>Aravind Ravichandran</dc:creator>
      <dc:date>2018-11-16T07:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747868#M488152</link>
      <description>I've heard that's ill advised.&lt;BR /&gt;&lt;BR /&gt;Check out:&lt;BR /&gt;&lt;A href="https://www.ise-support.com/2017/12/23/vmware-and-cisco-ise/" target="_blank"&gt;https://www.ise-support.com/2017/12/23/vmware-and-cisco-ise/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 16 Nov 2018 07:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747868#M488152</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2018-11-16T07:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747957#M488153</link>
      <description>Oh great! thanks for correcting me Nadav!</description>
      <pubDate>Fri, 16 Nov 2018 11:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3747957#M488153</guid>
      <dc:creator>Aravind Ravichandran</dc:creator>
      <dc:date>2018-11-16T11:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748058#M488154</link>
      <description>&lt;P&gt;I would like to know how the claim "ISE doesn't use the extra CPU/memory" was verified.&amp;nbsp; If I shut down a VM and change the memory/CPU, start it up again and look at the ISE counters it correctly recognizes it, i.e. it goes from UCS_Large to SNS_3595.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 13:49:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748058#M488154</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-11-16T13:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748118#M488155</link>
      <description>&lt;P&gt;For years we have been stating this method&lt;BR /&gt;&lt;BR /&gt;You can change the CPU and the memory on a VM just not the disk (build a new node and add to the deployment to replace the node)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Node groups are used for performance and doesn’t change scale. Please see ise performance and scale Cisco live on this page&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 14:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748118#M488155</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-16T14:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748208#M488156</link>
      <description>&lt;P&gt;The documentation states that it can be, but at least two different blogs have stated that it will likely cause adverse effects:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.network-node.com/blog/2017/10/7/ise-design-going-above-the-configuration" target="_self"&gt;https://www.network-node.com/blog/2017/10/7/ise-design-going-above-the-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ise-support.com/2017/12/23/vmware-and-cisco-ise/" target="_self"&gt;https://www.ise-support.com/2017/12/23/vmware-and-cisco-ise/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe they're wrong, maybe they aren't, but that's their experience even though the documentation clearly says otherwise. It would be interesting to know how they came to their conclussions. Any chance you can chime in&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/356679"&gt;@katmcnam&lt;/a&gt;&amp;nbsp;(the first blog is hers)?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 17:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748208#M488156</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2018-11-16T17:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748213#M488157</link>
      <description>The only issue I know about is if you change the memory and CPU is you have to modify the reservations as well.  I have had customers increase memory but the reservations was still at the old memory and worse yet it was limited to that size.  So you go from 16 GB to 64 GB but the reservation is set and limited to 16 GB.  All sorts of issues can happen when a VM is limited to less than the maximum memory.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 16 Nov 2018 16:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3748213#M488157</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-11-16T16:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777025#M488158</link>
      <description>&lt;P&gt;From what I was shown by a TAC engineer during troubleshooting, and they had to get root access to the file system, the sizing is written to a config file during ISE install/setup. It reads the virtual hardware and sets all of the configuration limits (ie database performance/resources) based on those. The configuration file doesn't get re-written if you shut down the VM, add CPU/RAM, and start it back up. All of the old limits are in place even with the additional hardware. Hence,&amp;nbsp;&lt;SPAN&gt;"ISE doesn't use the extra CPU/memory" as in it is not fully utilized.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 16:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777025#M488158</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2019-01-10T16:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777036#M488159</link>
      <description>&lt;P&gt;I think your TAC case likely on&amp;nbsp;some older ISE release. I am pretty sure ISE 2.4 will adjust the parameters after the CPU/RAM resized. Even an&amp;nbsp;older ISE release will update the parameters if a change made to the persona(s) of the ISE node.&lt;/P&gt;
&lt;P&gt;Besides the optimization&amp;nbsp;done with the system parameters, ISE and the underlying Linux will still take some advantage of the enlarged RAM allocation.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 16:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777036#M488159</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-01-10T16:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777044#M488160</link>
      <description>&lt;P&gt;I would need to see proof that it works before I could recommend my customers do it. Based on the previous experience (it was with 2.3), it doesn't work that way because ISE does not take advantage of the new hardware due to the configuration file that was written based on the previous hardware settings. Nothing was brought up in that TAC case about making it work by changing the persona and then changing it back. The TAC engineer was adamant that a reinstall would be needed in order for the configuration to be valid and ISE take advantage of the new hardware.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 16:45:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777044#M488160</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2019-01-10T16:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed deployment PSN scale</title>
      <link>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777128#M488161</link>
      <description>&lt;P&gt;If you provide the TAC case SR number, I may review its case notes. Below is from my ISE 2.4 system ADE.log:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:01:07.531147+00:00 myISE24 root: info:[application:operation:platformproperties.sh] 2019-01-10 18:01:07 INFO PlatformProfileServiceImpl:599 - Gathering platform-specific properties&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:01:07.532810+00:00 myISE24 root: info:[application:operation:platformproperties.sh] Old Memory Size : 16267592&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:01:07.584407+00:00 myISE24 root: info:[application:operation:platformproperties.sh] 2019-01-10 18:01:07 INFO PlatformProperties:61 - PlatformProperties whoami: root&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:01:07.585786+00:00 myISE24 root: info:[application:operation:platformproperties.sh]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:01:07.619669+00:00 myISE24 root: info:[application:operation:platformproperties.sh] 2019-01-10 18:01:07 INFO PlatformProperties:103 - PlatformProperties{udiPid='ISE-VM-K9', udiVid='V01', udiSn='***********', memorySizeKb=16267592, numberOfCpuCores=2}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;------------------------ Power Off; Change CPU core number from 2 to 12; Power On ----------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:38.533482+00:00 myISE24 logger: info:[application:operation:platformproperties.sh] 2019-01-10 18:17:38 INFO PlatformProfileServiceImpl:599 - Gathering platform-specific properties&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:38.540387+00:00 myISE24 logger: info:[application:operation:platformproperties.sh] Old Memory Size : 16267592&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:38.822093+00:00 myISE24 logger: info:[application:operation:platformproperties.sh] 2019-01-10 18:17:38 INFO PlatformProperties:61 - PlatformProperties whoami: root&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:38.823872+00:00 myISE24 logger: info:[application:operation:platformproperties.sh]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:38.890699+00:00 myISE24 logger: info:[application:operation:platformproperties.sh] 2019-01-10 18:17:38 INFO PlatformProperties:103 - PlatformProperties{udiPid='ISE-VM-K9', udiVid='V01', udiSn='***********', memorySizeKb=16266128, numberOfCpuCores=12}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:53.756732+00:00 myISE24 logger: info:[application:operation:platformproperties.sh] Old Memory Size : 16267592&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:53.865711+00:00 myISE24 logger: info:[application:operation:platformproperties.sh] node-config.rc has been modified - rebuilding active properties file&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="1 2 3 4 5 6 7"&gt;2019-01-10T18:17:53.869203+00:00 myISE24 logger: info:[application:operation:platformproperties.sh] Getting profile properties for profile 'sns3515' and persona 'standalone'&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 18:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/distributed-deployment-psn-scale/m-p/3777128#M488161</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-01-10T18:40:17Z</dc:date>
    </item>
  </channel>
</rss>

