<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3615 ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4903613#M583390</link>
    <description>&lt;P&gt;It falls down to what I mentioned - what do you want to achieve, single or split deployment.&lt;/P&gt;
&lt;P&gt;In a single deployment, you can have bot redundancy and flexibility. Here is an example on what you can configure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Site 1, node 1 - PAN and PSN&lt;/LI&gt;
&lt;LI&gt;Site 1, node 2 - MnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 1 - sPAN and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 2 - sMnT and PSN&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This way, you are splitting mgmt roles, so you have redundancy and you also have capacity. Operations-wise, you have a single deployment to configure.&lt;/P&gt;
&lt;P&gt;Second deployment is split deployment or better said two deployments. Example could be:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Site 1, node 1 - PAN, sMnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 1, node 2 - sPAN, MnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 1 - PAN, sMnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 2 - sPAN, MnT and PSN&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This way, you have two independent deployments, with double capacity (should you need it), but you'll have to configure everything twice, logs will be at two places, and similar.&lt;/P&gt;
&lt;P&gt;In both cases, if you expet max of 5k simultaneous sessions (if user is connected to site 1, he/she won't be connected to site 2 at same time), then you need 5k licenses, regardless of deployment type. Licenses are smart, so either way, they'll be on SA.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2023 08:14:16 GMT</pubDate>
    <dc:creator>Milos_Jovanovic</dc:creator>
    <dc:date>2023-08-11T08:14:16Z</dc:date>
    <item>
      <title>3615 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4902836#M583376</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;if i want to do basic 2 redundant implementation,&amp;nbsp;2 nodes at HQ (carrying all personas) and 2 nodes at DR (carrying all personas). What's the max active sessions? do I need double license count (one for HQ and one for DR) as the Admin persona at HQ and DR will be separated&lt;/P&gt;&lt;P&gt;Thanks and BR;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 09:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4902836#M583376</guid>
      <dc:creator>ibrahimbadr4669</dc:creator>
      <dc:date>2023-08-10T09:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: 3615 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4902843#M583378</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/965291"&gt;@ibrahimbadr4669&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;When it comes to scaling an capacity, you can check &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_self"&gt;Performance and Scalability Guide&lt;/A&gt;. What you've described correlates to Small deployment, in general. However, it is unclear to me if you want entire deployment to be a single deployment or you are looking int having independent deployments in HQ and DR.&lt;/P&gt;
&lt;P&gt;In case of a single deployment, then no, you can't have all roles on each device, as deployment can have maximum of 2 PAN and 2 MnT nodes, so you would need to rebalance them. Also, in this case, you deployment scale is 12.5k.&lt;/P&gt;
&lt;P&gt;In case of split deployment, then yes, you could have all roles on each pair of nodes. In this case, your cpaacity would be 2x 12.5k sessions.&lt;/P&gt;
&lt;P&gt;License-wise, it depends on what are your needs and use cases. If you expect to have maximum of e.g. 5k users in a given moment, then you need a license for 5k users, regardless if those users are connected to one or another deployment (also, regardless of single or split deployment).&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 09:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4902843#M583378</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2023-08-10T09:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: 3615 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4902878#M583379</link>
      <description>&lt;P&gt;we plan to have the following two nodes at HQ, and have the same setup at DR and the two deployment will be&amp;nbsp;&lt;SPAN&gt;independent, and when configure the radius&amp;nbsp;on the NAD, DR PSN order will be after the HQ PSN. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1- in the case the max session per site will be 12.5 or 2x12.5 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2-in case,&amp;nbsp;5k users license, do i need to purchase 10k count or just 5k count can work both site&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ibrahimbadr4669_0-1691663161686.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/193985i256CD7E62E50D507/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ibrahimbadr4669_0-1691663161686.png" alt="ibrahimbadr4669_0-1691663161686.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 10:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4902878#M583379</guid>
      <dc:creator>ibrahimbadr4669</dc:creator>
      <dc:date>2023-08-10T10:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: 3615 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4903027#M583381</link>
      <description>&lt;P&gt;Place one node at HQ, one node at DR site.&amp;nbsp; Configuration will sync.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The way you're planning it will require manual configuration at the DR site to keep the configuration in sync.&amp;nbsp; With Smart Licensing, they can share the same license pool.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 12:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4903027#M583381</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-08-10T12:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: 3615 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4903063#M583384</link>
      <description>&lt;P&gt;I read that the license is attached with the UDI of the primary and backup PAN, so if I do the &lt;SPAN&gt;independent&amp;nbsp;&lt;/SPAN&gt;deployment, I will have 4 independent primary/secondary PAN, if I have 5k users, is it mean that I will need 10k license (5k for HQ and 5k for the DR) ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 13:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4903063#M583384</guid>
      <dc:creator>ibrahimbadr4669</dc:creator>
      <dc:date>2023-08-10T13:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: 3615 ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4903613#M583390</link>
      <description>&lt;P&gt;It falls down to what I mentioned - what do you want to achieve, single or split deployment.&lt;/P&gt;
&lt;P&gt;In a single deployment, you can have bot redundancy and flexibility. Here is an example on what you can configure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Site 1, node 1 - PAN and PSN&lt;/LI&gt;
&lt;LI&gt;Site 1, node 2 - MnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 1 - sPAN and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 2 - sMnT and PSN&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This way, you are splitting mgmt roles, so you have redundancy and you also have capacity. Operations-wise, you have a single deployment to configure.&lt;/P&gt;
&lt;P&gt;Second deployment is split deployment or better said two deployments. Example could be:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Site 1, node 1 - PAN, sMnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 1, node 2 - sPAN, MnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 1 - PAN, sMnT and PSN&lt;/LI&gt;
&lt;LI&gt;Site 2, node 2 - sPAN, MnT and PSN&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This way, you have two independent deployments, with double capacity (should you need it), but you'll have to configure everything twice, logs will be at two places, and similar.&lt;/P&gt;
&lt;P&gt;In both cases, if you expet max of 5k simultaneous sessions (if user is connected to site 1, he/she won't be connected to site 2 at same time), then you need 5k licenses, regardless of deployment type. Licenses are smart, so either way, they'll be on SA.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 08:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3615-ise/m-p/4903613#M583390</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2023-08-11T08:14:16Z</dc:date>
    </item>
  </channel>
</rss>

