<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Deployment Questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085291#M560395</link>
    <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My team has been tasked with getting ISE deployed from scratch and I had a few questions about the how we should design the deployment. We have roughly 1200 retail locations throughout the United States with between 10k - 15k employees nationwide. Here are my questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Given the size of the company, how big if a distributed design should we do? Should we do dedicated Admin/Monitoring/Policy nodes? Or can we combine the Admin nodes with a Policy node? I was reading that you shouldn't combine the monitoring node with any other node. Is this best practice?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) We will be running ISE VM's in VMWare. What is the difference between the OVA "Sizes" (small, medium, large)? What size OVA is recommended for each persona?&lt;/P&gt;&lt;P&gt;3) How much CPU, Memory and Storage should we allocate for each VM? The installation guide offers few details on how to size each VM other than mimicking a certain SNS appliance. Is it based on persona? How do we know which SNS appliance to use as a template?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really appreciate any feedback you can provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2020 20:06:07 GMT</pubDate>
    <dc:creator>Craddockc</dc:creator>
    <dc:date>2020-05-13T20:06:07Z</dc:date>
    <item>
      <title>ISE Deployment Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085291#M560395</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My team has been tasked with getting ISE deployed from scratch and I had a few questions about the how we should design the deployment. We have roughly 1200 retail locations throughout the United States with between 10k - 15k employees nationwide. Here are my questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Given the size of the company, how big if a distributed design should we do? Should we do dedicated Admin/Monitoring/Policy nodes? Or can we combine the Admin nodes with a Policy node? I was reading that you shouldn't combine the monitoring node with any other node. Is this best practice?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) We will be running ISE VM's in VMWare. What is the difference between the OVA "Sizes" (small, medium, large)? What size OVA is recommended for each persona?&lt;/P&gt;&lt;P&gt;3) How much CPU, Memory and Storage should we allocate for each VM? The installation guide offers few details on how to size each VM other than mimicking a certain SNS appliance. Is it based on persona? How do we know which SNS appliance to use as a template?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really appreciate any feedback you can provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 20:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085291#M560395</guid>
      <dc:creator>Craddockc</dc:creator>
      <dc:date>2020-05-13T20:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085304#M560396</link>
      <description>&lt;P&gt;there is a good post already available, here for refeence :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-planning-amp-pre-deployment-checklists/ta-p/3622635" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/ise-planning-amp-pre-deployment-checklists/ta-p/3622635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;other good resources to start with :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-amp-nac-community-resources/ta-p/3621621#Planning" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-amp-nac-community-resources/ta-p/3621621#Planning&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 20:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085304#M560396</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-05-13T20:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085347#M560398</link>
      <description>You could deploy 2x medium ISE 3655 templates to support all functions of that deployment at a high level. We refer to this as a standalone deployment where all required roles, admin, monitor, and policy service, are hosted on the same one or two nodes, preferably two for HA. These VMs would be 96 GB memory reservations, 24,000 MHz of CPU, and at least 1200 GB each. The resources for ISE VM's mirror the SNS-36x5 appliances that are available. &lt;BR /&gt;&lt;BR /&gt;Two medium 3655 VM's hosting all your roles can support up to 25,000 active endpoints in full HA.</description>
      <pubDate>Wed, 13 May 2020 21:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085347#M560398</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-05-13T21:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085768#M560425</link>
      <description>Thank you both for the great information! I really appreciate it! It really helps to point me in the right direction.</description>
      <pubDate>Thu, 14 May 2020 12:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-questions/m-p/4085768#M560425</guid>
      <dc:creator>Craddockc</dc:creator>
      <dc:date>2020-05-14T12:53:27Z</dc:date>
    </item>
  </channel>
</rss>

