<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Deployment Advise in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713785#M507377</link>
    <description>Sounds good. Is it possible to just add one standalone psn to the existing 2?</description>
    <pubDate>Wed, 26 Sep 2018 20:38:57 GMT</pubDate>
    <dc:creator>NETAD</dc:creator>
    <dc:date>2018-09-26T20:38:57Z</dc:date>
    <item>
      <title>ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713736#M507371</link>
      <description>&lt;P&gt;Hello, I have a client who will be deploying ISE as a radius proxy server only. He will be doing it for corp wireless to relay authentication requests to an MFA server and he doesn't want to do any further authorization on ISE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He has a about 1 to 2 thousands wireless devices and might scale to a slightly higher number of devices in the future.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;60 sites with 3 data centers and want to deploy the ISE&amp;nbsp;nodes across those 3 DC locations for high availability.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's the minimum number of ISE nodes can we deploy for him and put him in a position that allows him to scale in the future if he decides to do more on ISE and add more PSNs following the Cisco recommendations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is a&amp;nbsp;2 node deployment an option:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Node 1: Primary Admin, Secondary MnT, PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Node 2: Secondary Admin, Primary MnT, PSN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is a 3 node deployment a supported Cisco design?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Node 1: primary Admin, Secondary MnT, PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Node 2: Secondary Admin, Primary MnT, PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Node 3: PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or 4 or 5?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713736#M507371</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-26T19:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713740#M507372</link>
      <description>I would recommend a small ise deployment with 2 servers running all personas (PAN,MNT,PSN) for HA&lt;BR /&gt;&lt;BR /&gt;The supported configurations are here:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#ID-1413-0000008e" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_00.html#ID-1413-0000008e&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:20:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713740#M507372</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-26T19:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713741#M507373</link>
      <description>&lt;P&gt;Thanks Jason is a three or a four node deployment doable at all I know it’s not in the deployment guide but will Cisco still support this model? and How would you configure the personas? the customer keeps asking for a three or four node deployment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also of we go with 3 or 4 would be the same process to add psns down the road?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713741#M507373</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-26T19:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713749#M507374</link>
      <description>The guide shows what’s supported&lt;BR /&gt;&lt;BR /&gt;If you want standalone PSNs you have to move to medium deployment that doesn’t allow that persona to run on same box as PAN/MNT&lt;BR /&gt;&lt;BR /&gt;I would recommend starting in small deployment and then later migrate PSNs to medium or even large down the road.  You could start with a large appliance so that could always be ready for any deployment size . You can always disable the small deployment psn easily in the UI&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713749#M507374</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-26T19:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713775#M507375</link>
      <description>So pretty much start with a small deployment with al all personas then down the road disable the PSNs in the UI, and add standalone PSNs. &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Sep 2018 20:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713775#M507375</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-26T20:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713779#M507376</link>
      <description>Yes&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Sep 2018 20:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713779#M507376</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-26T20:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713785#M507377</link>
      <description>Sounds good. Is it possible to just add one standalone psn to the existing 2?</description>
      <pubDate>Wed, 26 Sep 2018 20:38:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713785#M507377</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-26T20:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713795#M507378</link>
      <description>No as stated before its not supported unless you separate into medium deployment&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Sep 2018 21:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713795#M507378</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-26T21:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713822#M507379</link>
      <description>Thanks. We will be going with a 4 node deployment. &lt;BR /&gt;HQ: &lt;BR /&gt;Node #1: Primary Admin, Secondary MnT&lt;BR /&gt;Node #2: PSN#1&lt;BR /&gt;DC &lt;BR /&gt;              Node #3: Secondary Admin, Primary MnT &lt;BR /&gt;              Node #4: PSN#2 &lt;BR /&gt;</description>
      <pubDate>Wed, 26 Sep 2018 21:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3713822#M507379</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-26T21:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714295#M507380</link>
      <description>Hi Jason, the customer is insisting on 3 standalone ISE nodes and mirroring the config on all nodes. His excuse is that ISE isn't doing what ISE is supposed to be doing. What would be the implications of a such design.</description>
      <pubDate>Thu, 27 Sep 2018 13:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714295#M507380</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-27T13:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714320#M507381</link>
      <description>Now you’re talking about two different things. &lt;BR /&gt;&lt;BR /&gt;As stated before the supported options are in the guys that I shared with you. Other combinations are not tested and therefore not supported.&lt;BR /&gt;&lt;BR /&gt;I see no issue going with a standalone deployment using two separate boxes for high-availability . Each box has a policy service now and running on it and your network access devices would point to each for failover. As we discussed before this can be easily scaled up by removing those personas and then turning them up on separate boxes. This is the recommended approach.If he you are utilizing virtual machines then it makes it even easier to size and split them out. If you’re going with appliances You can start small and when customer decides to split then they could repurpose them as PSNs and then buy larger appliance as admin/monitor &lt;BR /&gt;&lt;BR /&gt;Otherwise It seems like you’re now talking about three separate ise deployments. This is wrong on many levels. &lt;BR /&gt;#1 information and configuration will not be synchronized between the deployments . There is no manager of managers&lt;BR /&gt;#2 since your network access devices will point to a PSN in one deployment and then fail over to another deployment The endpoint information will be mismatch and start fresh&lt;BR /&gt;#3 I believe you have to pay for services support for each?&lt;BR /&gt;#4 for standard licensing you would have to purchase separate licenses&lt;BR /&gt;#5 There are more but I’m pretty much tapped out. This is not a good approach&lt;BR /&gt;</description>
      <pubDate>Thu, 27 Sep 2018 13:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714320#M507381</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-27T13:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714337#M507382</link>
      <description>Thank you Jason. I'm proposing all the supported designs from the Cisco design guide but the customer keeps coming back and insisting on the wrong design and he doesn't care much about re-desigining down the road or being unsupported. I liked all the reasons you provided for a 3 standalone deployment and I agree it's wrong. &lt;BR /&gt;&lt;BR /&gt;I suggested a small deployment with 2 nodes running all personas or a 4 node deployment like I mentioned before but he came back asking for 3!! &lt;BR /&gt;&lt;BR /&gt;When you say "I see no issue going with a standalone deployment using two separate boxes for high-availability" are you referring to the small deployment with 2 admin (1primary one secondary) 2 MnTs (1 primary, one secondary) and 2 PSNs (both active) and of course building that trust relationship between the 2. &lt;BR /&gt;&lt;BR /&gt;Thanks for your help and prompt responses to me.</description>
      <pubDate>Thu, 27 Sep 2018 14:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714337#M507382</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-27T14:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714341#M507383</link>
      <description>Sorry unfortunately customer is wrong and this has to stop &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Quote:&lt;BR /&gt;When you say "I see no issue going with a standalone deployment using two separate boxes for high-availability" are you referring to the small deployment with 2 admin (1primary one secondary) 2 MnTs (1 primary, one secondary) and 2 PSNs (both active) and of course building that trust relationship between the 2.&lt;BR /&gt;&lt;BR /&gt;Recommendation is &lt;BR /&gt;Small deployment standalone&lt;BR /&gt;2 boxes running pan/mnt/pan on each box. &lt;BR /&gt;Box1 runs primary pan/mnt&lt;BR /&gt;Box2 runs secondaries&lt;BR /&gt;Each box has active psn&lt;BR /&gt;This is all in the deployment guide &lt;BR /&gt;</description>
      <pubDate>Thu, 27 Sep 2018 14:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714341#M507383</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-27T14:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Advise</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714346#M507384</link>
      <description>Hoping he will today &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thanks for your help.</description>
      <pubDate>Thu, 27 Sep 2018 14:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-advise/m-p/3714346#M507384</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-09-27T14:33:03Z</dc:date>
    </item>
  </channel>
</rss>

