<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Passive ID Preferred Options/Scalability in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-preferred-options-scalability/m-p/3596156#M557468</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All member servers are allowed to automatically WMI poll DCs for security logs?  Or how is the member server getting the security logs from the DCs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other solutions even when you deploy agents on member servers they need AD credentials to make WMI calls to the DCs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure I am missing something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Jun 2017 19:27:46 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2017-06-29T19:27:46Z</dc:date>
    <item>
      <title>ISE Passive ID Preferred Options/Scalability</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-preferred-options-scalability/m-p/3596154#M557413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to put some of my thoughts down in ISE Passive ID and cofirm what I am thinking as we lay this out for customers.&amp;nbsp; Please let me know if I have anything incorrect or am missing something.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am listing the Passive ID options in order of how I would prefer to implement them:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Option #1- Agent Installed on Each DC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Advantages&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Only requires elevated privilege account to install the agent.&amp;nbsp; i.e. no persistent service account needed.&lt;/LI&gt;&lt;LI&gt;Removes polling requirements from the PSNs.&lt;/LI&gt;&lt;LI&gt;No WMI modifications on the DCs. (registry settings, CIMv2 modifications, etc.)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Disadvantages&lt;/STRONG&gt;&lt;/P&gt;&lt;OL style="font-size: 13.3333px;"&gt;&lt;LI&gt;Requires the installation of a service on the DCs which some customers may not like the idea of.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Scalability and Performance&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Can scale up to 100 DCs.&amp;nbsp; In terms of performance, I would think this would be the middle performer of the 3.&amp;nbsp; The workload is offloaded from the PSNs, but I have 1:1 feeds coming into the PSNs from the agents.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Option #2- WMI Queries from the PSNs&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Advantages&lt;/STRONG&gt;&lt;/P&gt;&lt;OL style="font-size: 13.3333px;"&gt;&lt;LI&gt;No services required on the DCs.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Disadvantages&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="font-size: 13.3333px;"&gt;&lt;LI&gt;Requires elevated privilege service account.&amp;nbsp; Account in Domain Admins is the simplest, but that won't fly with many customers especially if you ask for a non-expiring password service account.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;WMI modifications on the DCs. (registry settings, CIMv2 modifications, etc.)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;PSNs have to perform the polling work adding load to the PSNs.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Scalability and Performance&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Can scale up to 100 DCs.&amp;nbsp; In terms of performance, I would think this would be the worst performer out of the 3 options as the PSNs have to do all the work.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Option #3- Agent on Member Servers Polling up to 10 DCs Each&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Advantages&lt;/STRONG&gt;&lt;/P&gt;&lt;OL style="font-size: 13.3333px;"&gt;&lt;LI&gt;No services required on the DCs.&lt;/LI&gt;&lt;LI&gt;Aggregate information at a 10:1 ratio before feeding the data into ISE.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Disadvantages&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="font-size: 13.3333px;"&gt;&lt;LI&gt;Requires elevated privilege service account.&amp;nbsp; Account in Domain Admins is the simplest, but that won't fly with many customers especially if you ask for a non-expiring password service account.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;WMI modifications on the DCs. (registry settings, CIMv2 modifications, etc.)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Need member servers provisioned for this role at a 10:1 ratio.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Scalability and Performance&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Can scale up to 100 DCs.&amp;nbsp; In terms of performance, I would think this is the best performance since it is aggregating the data so the PSNs have less data sources to deal with.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-preferred-options-scalability/m-p/3596154#M557413</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2020-02-21T18:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Preferred Options/Scalability</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-preferred-options-scalability/m-p/3596155#M557436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You wouldn't need to deploy an agent on each DC.&amp;nbsp; The agent can monitor up to 10 controllers whether the agent is installed on the controller or a member server.&amp;nbsp; Since the agent is running on a trusted source, you don't need elevated account privileges.&amp;nbsp; That would only be true for the WMI probe because the server would need to be configured for remote monitoring.&amp;nbsp; Here are all 3 options in order of efficiency:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1:&amp;nbsp; Agent (either member or controller) - up to 100 controllers&lt;/P&gt;&lt;P&gt;2: WMI - up to 100 controllers&lt;/P&gt;&lt;P&gt;3: Kerberos SPAN - Zero touch / point-in-time only / no history&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2017 18:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-preferred-options-scalability/m-p/3596155#M557436</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-06-29T18:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Passive ID Preferred Options/Scalability</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-passive-id-preferred-options-scalability/m-p/3596156#M557468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All member servers are allowed to automatically WMI poll DCs for security logs?  Or how is the member server getting the security logs from the DCs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other solutions even when you deploy agents on member servers they need AD credentials to make WMI calls to the DCs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure I am missing something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2017 19:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-passive-id-preferred-options-scalability/m-p/3596156#M557468</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-06-29T19:27:46Z</dc:date>
    </item>
  </channel>
</rss>

