<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE VM resource best practices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448916#M496285</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&amp;nbsp; I could use some guidance for ISE VMs.&amp;nbsp; A Partner has a customer who wants to be flexible in how he deploys the VMs in VMware.&amp;nbsp; I would love to talk to someone about best practices vs what is supported.&amp;nbsp; I am a little unclear with the documentation I have read. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;Questions they have, just snipping a little of a long detailed e-mail, Partner would love to have a discussion.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;STRONG style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;Call Bridge VM or Combined VM (Edge + Call Bridge)&lt;/STRONG&gt;&lt;SPAN style="color: black; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;:&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;&lt;EM&gt;Running a single VM&lt;/EM&gt;When running a single virtual machine on a host, one physical core per host must be left unused by apps for ESXi scheduler. With a single VM, it is possible to use hyper-threading to increase the available capacity. In this case the number of available vCPUs is double the number of physical cores in use. So a two socket system which has 20 physical cores will have 19 available to the application. With hyper-threading enabled, 38vCPUs can be used, which should be allocated to the CMS VM, and the other 2 left unused. If an option is available to choose both number of sockets and number of cores per socket, then these should mirror the underlying hardware.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;EM&gt;Running multiple VMs co-resident on a single host&lt;/EM&gt;&lt;BR /&gt;When running multiple virtual machine on a single host&lt;/STRONG&gt;, &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;&lt;STRONG style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;When using VMware 5.5+ with multiple VMs and the Latency Sensitivity feature&lt;/STRONG&gt;&lt;SPAN style="color: black; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;Although not recommended, it is possible to run other VMs alongside the Cisco Meeting Server&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;VM as long as CPU isolation domains are created to prevent contention&lt;/STRONG&gt;. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jul 2018 12:21:39 GMT</pubDate>
    <dc:creator>tostraus</dc:creator>
    <dc:date>2018-07-11T12:21:39Z</dc:date>
    <item>
      <title>ISE VM resource best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448916#M496285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&amp;nbsp; I could use some guidance for ISE VMs.&amp;nbsp; A Partner has a customer who wants to be flexible in how he deploys the VMs in VMware.&amp;nbsp; I would love to talk to someone about best practices vs what is supported.&amp;nbsp; I am a little unclear with the documentation I have read. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;Questions they have, just snipping a little of a long detailed e-mail, Partner would love to have a discussion.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;&lt;STRONG style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;Call Bridge VM or Combined VM (Edge + Call Bridge)&lt;/STRONG&gt;&lt;SPAN style="color: black; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;:&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;&lt;EM&gt;Running a single VM&lt;/EM&gt;When running a single virtual machine on a host, one physical core per host must be left unused by apps for ESXi scheduler. With a single VM, it is possible to use hyper-threading to increase the available capacity. In this case the number of available vCPUs is double the number of physical cores in use. So a two socket system which has 20 physical cores will have 19 available to the application. With hyper-threading enabled, 38vCPUs can be used, which should be allocated to the CMS VM, and the other 2 left unused. If an option is available to choose both number of sockets and number of cores per socket, then these should mirror the underlying hardware.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;EM&gt;Running multiple VMs co-resident on a single host&lt;/EM&gt;&lt;BR /&gt;When running multiple virtual machine on a single host&lt;/STRONG&gt;, &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;&lt;STRONG style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;When using VMware 5.5+ with multiple VMs and the Latency Sensitivity feature&lt;/STRONG&gt;&lt;SPAN style="color: black; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;Although not recommended, it is possible to run other VMs alongside the Cisco Meeting Server&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;STRONG&gt;VM as long as CPU isolation domains are created to prevent contention&lt;/STRONG&gt;. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 12:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448916#M496285</guid>
      <dc:creator>tostraus</dc:creator>
      <dc:date>2018-07-11T12:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM resource best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448917#M496286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sharing resources is not supported between ISE and any other guest OS. Also, it is required to enable hyper threading, but you should not count additional CPU as result of HT in terms of allocation. In other words, to get 3595 equivalent specification, you need to dedicate 16 vCore (When HT enabled) and 64GB RAM. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 20:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448917#M496286</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-07-11T20:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM resource best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448918#M496287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Howon stated, you don't want to be sharing resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VMware lets you over allocate vcpu because they are virtual, they don't really exist, it's an arbitrary number.&amp;nbsp; An example of this would be the ability to assign two vm's 32 vcpu each on a box with only 2 cpu of 4 cores each.&amp;nbsp; The issue you will run in to is when you try and make a CPU MHz reservation.&amp;nbsp; ISE requires either a 12,000 or 16,000 MHz reservation according to the recommendations, this requires 6 or 8 physical cores of at least 2 GHz each.&amp;nbsp; You can't over allocate MHz because there is a physical and finite supply of real compute. &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ESXi requires at least part of 1 core for host operations, this will require X Mhz, it also requires memory for the host.&amp;nbsp; The ability to run more VM's and still be in "compliance" with Cisco's ISE recommendations relies on the available resources reservations on the host.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take this host for example, from the host resource allocation tab we can see that there is room for two more 3595 VM's. &lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="118564" alt="resources.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/118564_resources.JPG" style="height: 152px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now take this piece how you want but I don't think anyone recommends it.&amp;nbsp; Cisco "officially" says you can install ISE vm's without the reservations but they leave you with a warning.&amp;nbsp; I can also say that one of the first things TAC will call out is when the resource reservations don't match the recommendations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"If you choose to deploy Cisco ISE manually without the recommended reservations, you must assume the responsibility to closely monitor your appliance’s resource utilization and increase resources, as needed, to ensure proper health and functioning of the Cisco ISE deployment."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3/4 the way down the page&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_01.html" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_01.html"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in other words, don't run production ISE vm's without the reservations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 20:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448918#M496287</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-07-11T20:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE VM resource best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448919#M496288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 21:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vm-resource-best-practices/m-p/3448919#M496288</guid>
      <dc:creator>tostraus</dc:creator>
      <dc:date>2018-07-11T21:04:05Z</dc:date>
    </item>
  </channel>
</rss>

