<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment of Cisco ISE services in a Global Scale in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405901#M567427</link>
    <description>&lt;P&gt;then you are good in the approach, deploy, Monitor, restrict mode, posture and so on..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2021 08:46:22 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-05-20T08:46:22Z</dc:date>
    <item>
      <title>Deployment of Cisco ISE services in a Global Scale</title>
      <link>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405577#M567391</link>
      <description>&lt;P&gt;Dear community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on what I have seen when integrating Cisco ISE in an existing network, configurations are done device per device such as Switch, Router, ASA etc. I feel this can get overwhelming when having more than 100 devices of such to integrate with services like 802.1x, Posture, TACACS etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is as following: What is the process that you guys follow to integrate 802.1x into 100 network devices, that do cover +1L users.&lt;/P&gt;&lt;P&gt;The process I have applied so far has been for small number of devices and was able to manage it, but I think there must be some best practices that Engineers usually follow as part of the process for the tasks that are applied during the integration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The process I have applied is: Deployment of the ISE machines, add small number of NADs for test purposes, connect some test PCs for test also. when all configs seems right, Apply GPO for the Supplicants.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if you guys also do limit the GPO level of for example 802.1x to specific users and then if all configs correct, apply it for the whole company!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any though, ideas, recommendation would be highly appreciated since it would help me towards definition of the strategy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 18:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405577#M567391</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-05-19T18:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of Cisco ISE services in a Global Scale</title>
      <link>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405607#M567393</link>
      <description>&lt;PRE&gt;that do cover +1L users.&lt;/PRE&gt;
&lt;P&gt;can you give the number +1L means 100000 users?&amp;nbsp; all in the same Location or geolocation?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 18:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405607#M567393</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-05-19T18:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of Cisco ISE services in a Global Scale</title>
      <link>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405609#M567394</link>
      <description>&lt;P&gt;I feel it's all relative to what you become accustomed to. I find it routine to deploy dot1x/mab and trustsec configurations to a hundred NADs and 10k+ access ports in a night. It took time to get to this level, and we also developed our own in house tooling to be able to scale. It doesn't get rid of all the prep and environment specific set up, but once through the testing, away I go.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With that in mind I follow the same process as you. Start with a lab poc/test, move on to a production pilot, and once everyone is happy, begin a full scale production roll out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The piece I advocate as a best practice is consistency. Only deploy to tested network platforms, and only if they are running tested/certified software. A known good enables efficiency with automation and a baseline behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other pseudo best practice I advocate as well as many ISE presentations is to focus on the framework. Build the advanced use cases in layers/phases and essentially only bite off manageable pieces at any one time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 18:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405609#M567394</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-05-19T18:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of Cisco ISE services in a Global Scale</title>
      <link>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405841#M567422</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies, I meant +1K users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 05:38:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405841#M567422</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-05-20T05:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of Cisco ISE services in a Global Scale</title>
      <link>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405901#M567427</link>
      <description>&lt;P&gt;then you are good in the approach, deploy, Monitor, restrict mode, posture and so on..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 08:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deployment-of-cisco-ise-services-in-a-global-scale/m-p/4405901#M567427</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-05-20T08:46:22Z</dc:date>
    </item>
  </channel>
</rss>

