<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maximum SGACLs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680591#M495709</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;if you have N number of SGT's added into ISE then the matrix will have N rows and N columns. So, the matrix will be N x N.&lt;/P&gt;
&lt;P&gt;So, in ISE 2.4 there is now a limit of a 10k x 10k matrix BUT that would be for a very very special use-case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="text-align: start;"&gt;&lt;SPAN style="font-family: Calibri, sans-serif;"&gt;Most customers are using less than 250 SGTs, almost all are using less than 500.&lt;/SPAN&gt; Some customers are using 2000 SGTs but we know exactly what platforms they are using and have worked through it carefully. You can have large no.s if the specific infrastructure and use cases are carefully understood.&lt;/DIV&gt;
&lt;DIV style="text-align: start;"&gt;We do support multiple matrices in ISE so you could maybe have a matrix per use case and we do have custom matrix views plus a tree view to make management easier.&lt;/DIV&gt;
&lt;DIV style="text-align: start;"&gt;Normally keeping it simple to meet the customer needs is the way to go.&lt;/DIV&gt;
&lt;P&gt;Regards, Jonothan.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Aug 2018 07:09:15 GMT</pubDate>
    <dc:creator>jeaves@cisco.com</dc:creator>
    <dc:date>2018-08-03T07:09:15Z</dc:date>
    <item>
      <title>Maximum SGACLs</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3679892#M495675</link>
      <description>&lt;DIV class="jive-rendered-content"&gt;
&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this document &lt;A class="jive-link-external-small" href="https://communities.cisco.com/docs/DOC-68347" rel="nofollow" target="_blank"&gt;ISE Performance &amp;amp; Scale | Cisco Communities&lt;/A&gt;&amp;nbsp; it's mentioned that the maximum number of SGACLs supported in ISE 2.2 was 2500, and it seems it's decreased to 1000 in ISE 2.4, is that correct or a doc typo? On the other hand, do we have any limits in terms of maximum Source / Destination SGTs supported when creating the TrustSec Policy Matrix?&lt;/P&gt;
&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Oriol&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Aug 2018 10:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3679892#M495675</guid>
      <dc:creator>omadrile</dc:creator>
      <dc:date>2018-08-02T10:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGACLs</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680166#M495676</link>
      <description>I'm checking with the author of the doc to be sure but it does seem we have rolled back the amount of SGACLs.  I'll update once I hear back.  As for the second part of your question, I'm not sure I understand.  Could you elaborate?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Tim</description>
      <pubDate>Thu, 02 Aug 2018 15:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680166#M495676</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-08-02T15:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGACLs</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680241#M495707</link>
      <description>&lt;P&gt;Performance and Scale page updated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 17:01:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680241#M495707</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-08-02T17:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGACLs</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680296#M495708</link>
      <description>&lt;P&gt;Thanks for your reply Tim. What I meant in the second question is whether there's a max NxN dimension limit for the TrustSec Policy Matrix in ISE. Given that the max number of SGTs in ISE 2.4 is 10000, does that mean that the max dimension for such matrix is 100 x 100 ?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 18:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680296#M495708</guid>
      <dc:creator>omadrile</dc:creator>
      <dc:date>2018-08-02T18:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGACLs</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680591#M495709</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;if you have N number of SGT's added into ISE then the matrix will have N rows and N columns. So, the matrix will be N x N.&lt;/P&gt;
&lt;P&gt;So, in ISE 2.4 there is now a limit of a 10k x 10k matrix BUT that would be for a very very special use-case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="text-align: start;"&gt;&lt;SPAN style="font-family: Calibri, sans-serif;"&gt;Most customers are using less than 250 SGTs, almost all are using less than 500.&lt;/SPAN&gt; Some customers are using 2000 SGTs but we know exactly what platforms they are using and have worked through it carefully. You can have large no.s if the specific infrastructure and use cases are carefully understood.&lt;/DIV&gt;
&lt;DIV style="text-align: start;"&gt;We do support multiple matrices in ISE so you could maybe have a matrix per use case and we do have custom matrix views plus a tree view to make management easier.&lt;/DIV&gt;
&lt;DIV style="text-align: start;"&gt;Normally keeping it simple to meet the customer needs is the way to go.&lt;/DIV&gt;
&lt;P&gt;Regards, Jonothan.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 07:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgacls/m-p/3680591#M495709</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2018-08-03T07:09:15Z</dc:date>
    </item>
  </channel>
</rss>

