<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSN Limits in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3897868#M536449</link>
    <description>&lt;P style="text-align: left;"&gt;I would keep the ISE PSN's to a minimum for a few reasons.&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;1. The latency of authentication is not typically the issue, the issue is the latency between the ISE admin nodes and the PSN's.&amp;nbsp; We can account for authentication latency, but an ISE PSN should only be 300 ms RTT from the Admin.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;2. When you go to upgrade, every node adds significant time to the work effort.&lt;BR /&gt;3. Cost, PSN's are not cheap to buy/deploy/maintain.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;4. To have more than 5 PSN's, you have to leverage a distributed deployment where the Admin and Monitoring personas are on they own dedicated nodes.&amp;nbsp; This typically means 4 nodes just for PAN/MNT.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;There are some fringe use cases where PSN's in sites can be useful, but I would try to avoid it here.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2019 20:05:47 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2019-07-25T20:05:47Z</dc:date>
    <item>
      <title>PSN Limits</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424774#M536441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking at some of the ISE designs and had a question around the following design. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I run two PAN/MnT nodes but run primary PAN/secondary MnT on Node 1 and Primary MnT/secondary PAN on Node 2 is there still a limit of 5 PSNs in this deployment type?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, is the 5 PSNs a hard limit or just a recommendation? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;-Cory&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jan 2017 18:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424774#M536441</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2017-01-18T18:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: PSN Limits</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424775#M536444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="text" style="font-family: Helvetica; padding: 7px 0 0; color: #000000;"&gt;&lt;SPAN style="font-family: 'Segoe UI'; color: #1a1a1a; font-size: 10pt;"&gt;Yes...still a limit...if you want to scale higher, they have to be dedicated.&lt;/SPAN&gt;&lt;SPAN class="message_id"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="text" style="font-family: Helvetica; padding: 7px 0 0; color: #000000;"&gt;&lt;SPAN style="font-family: 'Segoe UI'; color: #1a1a1a; font-size: 10pt;"&gt;I believe it is a hard limit, but I haven't tested.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jan 2017 23:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424775#M536444</guid>
      <dc:creator>joeshoj</dc:creator>
      <dc:date>2017-01-18T23:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: PSN Limits</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424776#M536446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a recommendation based on our testings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2017 04:54:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424776#M536446</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-01-19T04:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: PSN Limits</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424777#M536447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So if not crystal clear already... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 5 PSN limit (when PAN and MNT personas collocated on same ISE node) is not a hard limit in the sense that UI prevents admin from registering additional PSNs, but it is a hard limit in terms of official Cisco support.&amp;nbsp; All testing is conducting based on supported deployment models.&amp;nbsp; Mileage may vary, but as Hsing rightly stated, it is our &lt;EM&gt;recommendation&lt;/EM&gt; to stay within supported limits, even though UI may allow unsupported configurations to be deployed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2017 23:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3424777#M536447</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-01-19T23:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: PSN Limits</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3897801#M536448</link>
      <description>&lt;P&gt;For a small, but distributed deployment (30 sites with less than 500 total "client" nodes), where you want to add PSNs at the remote sites in order to mitigate latency, is it practical to have more than the recommended 5 limit? BTW, the need is to do only TACACS+ AAA.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 18:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3897801#M536448</guid>
      <dc:creator>troy.moyers</dc:creator>
      <dc:date>2019-07-25T18:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: PSN Limits</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3897868#M536449</link>
      <description>&lt;P style="text-align: left;"&gt;I would keep the ISE PSN's to a minimum for a few reasons.&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;1. The latency of authentication is not typically the issue, the issue is the latency between the ISE admin nodes and the PSN's.&amp;nbsp; We can account for authentication latency, but an ISE PSN should only be 300 ms RTT from the Admin.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;2. When you go to upgrade, every node adds significant time to the work effort.&lt;BR /&gt;3. Cost, PSN's are not cheap to buy/deploy/maintain.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;4. To have more than 5 PSN's, you have to leverage a distributed deployment where the Admin and Monitoring personas are on they own dedicated nodes.&amp;nbsp; This typically means 4 nodes just for PAN/MNT.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;There are some fringe use cases where PSN's in sites can be useful, but I would try to avoid it here.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 20:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-limits/m-p/3897868#M536449</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-25T20:05:47Z</dc:date>
    </item>
  </channel>
</rss>

