<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Distributed Deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment/m-p/4872603#M582833</link>
    <description>&lt;P&gt;If it was my choice I would lay it out like this for a deployment that needs to support 25k+ active endpoints. You can increase the number of PSN nodes as the scale requires but the key component for me is that I would recommend putting the PSN nodes behind load balancers. This is not a hard requirement but this greatly simplifies the network device configuration since you can deploy all three load balancer virtual IP's to each network device in the order that makes sense. You can scale the deployment by adding PSN nodes without having to do much rework, and the maintanance/patching becomes much more transparent since network devices can have a VIP remain up with nodes being down.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Primary DC&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;1x Primary Admin Node&lt;/LI&gt;
&lt;LI&gt;1x Primary Monitoring Node&lt;/LI&gt;
&lt;LI&gt;At least 2x Policy Service Node (behind a load balancer)&lt;/LI&gt;
&lt;LI&gt;1x PxGrid Node if required&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Secondary DC&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;1x Secondary Admin Node&lt;/LI&gt;
&lt;LI&gt;1x Secondary Monitoring Node&lt;/LI&gt;
&lt;LI&gt;At least 2x Policy Service Node (behind a load balancer)&lt;/LI&gt;
&lt;LI&gt;1x PxGrid node if required&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Tertiary DC&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;At least 2x Policy Service Node (behind a load balancer)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2023 15:18:18 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2023-07-12T15:18:18Z</dc:date>
    <item>
      <title>ISE Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment/m-p/4871808#M582794</link>
      <description>&lt;P&gt;How can i best structure a large deployment with three Data Centers?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 14:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment/m-p/4871808#M582794</guid>
      <dc:creator>isabela</dc:creator>
      <dc:date>2023-07-11T14:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment/m-p/4871901#M582801</link>
      <description>&lt;P&gt;There are many options Which is best for you depends a lot on your particular requirements.&lt;/P&gt;
&lt;P&gt;You should start by reviewing this guide: &lt;A href="https://cs.co/ise-scale" target="_blank"&gt;https://cs.co/ise-scale&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 17:06:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment/m-p/4871901#M582801</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-07-11T17:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment/m-p/4872603#M582833</link>
      <description>&lt;P&gt;If it was my choice I would lay it out like this for a deployment that needs to support 25k+ active endpoints. You can increase the number of PSN nodes as the scale requires but the key component for me is that I would recommend putting the PSN nodes behind load balancers. This is not a hard requirement but this greatly simplifies the network device configuration since you can deploy all three load balancer virtual IP's to each network device in the order that makes sense. You can scale the deployment by adding PSN nodes without having to do much rework, and the maintanance/patching becomes much more transparent since network devices can have a VIP remain up with nodes being down.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Primary DC&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;1x Primary Admin Node&lt;/LI&gt;
&lt;LI&gt;1x Primary Monitoring Node&lt;/LI&gt;
&lt;LI&gt;At least 2x Policy Service Node (behind a load balancer)&lt;/LI&gt;
&lt;LI&gt;1x PxGrid Node if required&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Secondary DC&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;1x Secondary Admin Node&lt;/LI&gt;
&lt;LI&gt;1x Secondary Monitoring Node&lt;/LI&gt;
&lt;LI&gt;At least 2x Policy Service Node (behind a load balancer)&lt;/LI&gt;
&lt;LI&gt;1x PxGrid node if required&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Tertiary DC&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;At least 2x Policy Service Node (behind a load balancer)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 15:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment/m-p/4872603#M582833</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2023-07-12T15:18:18Z</dc:date>
    </item>
  </channel>
</rss>

