<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Small/Basic distributed deployment with 3 datacenters in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/small-basic-distributed-deployment-with-3-datacenters/m-p/3603151#M511452</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;jean-francois&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;I too had to justify the need.&amp;nbsp; Your 3 locations need 2 PAN's / MnT just to have basic redundancy, and dual MnT will allow you to load balance the AAA functions across the 2 nodes.&amp;nbsp; As for your other sites, if they are across weaker WAN circuits, then you would need / want to have nodes to perform the same functions at that location and so on.&amp;nbsp; Best practice is to separate the functions of ISE, but of course you CAN have a deployment where you have all the roles enabled on each server, but the performance will definitely take a hit.&amp;nbsp; Just don't call TAC to complain about latency and resource usage if you dont follow the recommended deployment model, &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/wink.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Realistically, I have 2 VM's one is the primary PAN and secondary Monitoring and secondary PxGrid, the other is &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;secondary&lt;/SPAN&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt; PAN and &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;primary&lt;/SPAN&gt; Monitoring and &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;primary&lt;/SPAN&gt; PxGrid.&amp;nbsp; What i can't do is have true PAN failover, which takes 2 primary nodes and 1 secondary.&amp;nbsp; Would I like to have done it differently? Yes, but sometimes budgeted projects get trimmed down.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;HTH-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Vince&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Mar 2018 20:31:33 GMT</pubDate>
    <dc:creator>vrostowsky</dc:creator>
    <dc:date>2018-03-19T20:31:33Z</dc:date>
    <item>
      <title>Small/Basic distributed deployment with 3 datacenters</title>
      <link>https://community.cisco.com/t5/network-access-control/small-basic-distributed-deployment-with-3-datacenters/m-p/3603149#M511449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ISE Performance &amp;amp; Scale" and the new "ISE-best practices" documents both require when using a 2 PAN/ MnT nodes setup a maximum of 5 PSNs and 20K active sessions (on 3595 as PAN+MnT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For a world-wide support design with 3 zones (each 2 PSNs, so total = 6), that requires to use a fully distribution model with separate PAN / MnT nodes, even if the number of maximum sessions remains quite low (around 5K).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we reasonably deploy a cluster with 6 PSNs if the number of active sessions is far below what a 3595 can handle as a PAN+MnT server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer is asking why we need so many management appliances to handle a mere 5k sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jean-francois&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 17:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/small-basic-distributed-deployment-with-3-datacenters/m-p/3603149#M511449</guid>
      <dc:creator>jpujol</dc:creator>
      <dc:date>2018-03-19T17:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Small/Basic distributed deployment with 3 datacenters</title>
      <link>https://community.cisco.com/t5/network-access-control/small-basic-distributed-deployment-with-3-datacenters/m-p/3603150#M511450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This has been answered several times before on the reasons why&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see&lt;/P&gt;&lt;P&gt;https://www.google.com/search?q=ise&lt;EM&gt;5&lt;/EM&gt;psn&amp;amp;oq=ise&lt;EM&gt;5&lt;/EM&gt;psn&amp;amp;aqs=chrome..69i57j69i64.3094j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 17:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/small-basic-distributed-deployment-with-3-datacenters/m-p/3603150#M511450</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-19T17:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Small/Basic distributed deployment with 3 datacenters</title>
      <link>https://community.cisco.com/t5/network-access-control/small-basic-distributed-deployment-with-3-datacenters/m-p/3603151#M511452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;jean-francois&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;I too had to justify the need.&amp;nbsp; Your 3 locations need 2 PAN's / MnT just to have basic redundancy, and dual MnT will allow you to load balance the AAA functions across the 2 nodes.&amp;nbsp; As for your other sites, if they are across weaker WAN circuits, then you would need / want to have nodes to perform the same functions at that location and so on.&amp;nbsp; Best practice is to separate the functions of ISE, but of course you CAN have a deployment where you have all the roles enabled on each server, but the performance will definitely take a hit.&amp;nbsp; Just don't call TAC to complain about latency and resource usage if you dont follow the recommended deployment model, &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/wink.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Realistically, I have 2 VM's one is the primary PAN and secondary Monitoring and secondary PxGrid, the other is &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;secondary&lt;/SPAN&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt; PAN and &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;primary&lt;/SPAN&gt; Monitoring and &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;primary&lt;/SPAN&gt; PxGrid.&amp;nbsp; What i can't do is have true PAN failover, which takes 2 primary nodes and 1 secondary.&amp;nbsp; Would I like to have done it differently? Yes, but sometimes budgeted projects get trimmed down.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;HTH-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Vince&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 20:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/small-basic-distributed-deployment-with-3-datacenters/m-p/3603151#M511452</guid>
      <dc:creator>vrostowsky</dc:creator>
      <dc:date>2018-03-19T20:31:33Z</dc:date>
    </item>
  </channel>
</rss>

