<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE in the Cloud in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/4981792#M585808</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;Can anyone share a link for migrating CISCO ISE to Azure&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Dec 2023 20:45:01 GMT</pubDate>
    <dc:creator>yadulla hussainks</dc:creator>
    <dc:date>2023-12-19T20:45:01Z</dc:date>
    <item>
      <title>ISE in the Cloud</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/3703425#M507739</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm wondering if anyone has evaluated running ISE in AWS or Azure.&amp;nbsp; It would be cool to see ISE as a service offering, but i'm not asking about that right now.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Earlier this year AWS/vmware teamed up to announce vmware cloud, building esxi hosts on a bare metal ec2 boxes. It appears AWS would be able to handle the workloads quite easily, no nested virtualization, 2xcpu /w 18x2.3GHz core each, 512 GB RAM, and 15 TB nvme storage.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't looked as closely at Azure, but for some time they have offered nested hyper-v virtualization. I&amp;nbsp; have not run ISE on hyper-v myself which mean I'm less familiar with the requirements.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm wondering if any one has evaluated either of these as an options for customers that&amp;nbsp;can't/don't want any onsite hardware.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 18:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/3703425#M507739</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-09-08T18:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE in the Cloud</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/3703472#M507740</link>
      <description>&lt;P&gt;I have been playing around with Azure a while and even their smaller CPU builds can rack up the costs pretty quickly.&amp;nbsp; I would go for the reserved instances to get the savings that would be needed when running an ISE node 24/7.&amp;nbsp; At this point it would also be nice to have an ISE image that is not so RAM and CPU hungry.&amp;nbsp; I'd say ISE is quite bloated and greedy (due to Java and Oracle running under the covers).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If a typical customer migrating from ACS to ISE, who wants a bit of wired and wireless 802.1x and perhaps Guest services, might benefit from an ISE node that only needs 8 GB of RAM and 4 vCPU's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do the math on what it would cost to run one "small" ISE node in Azure (even with reserved instance pricing).&amp;nbsp; I have not done it but I have not had the need to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Sep 2018 02:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/3703472#M507740</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-09-09T02:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE in the Cloud</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/3703723#M507741</link>
      <description>Yeah, it doesn't seem as viable in Azure since it would have to be nested in another hyper-v capable VM.  Maybe for a 3515 deployment it could potentially work, but with 3595's you would have to use massive dv3/ev3 service, Standard_E32_v3 or larger.&lt;BR /&gt;&lt;BR /&gt;I don't see a great solution right now for deployments in environments where the compute is entirely cloud based.</description>
      <pubDate>Mon, 10 Sep 2018 06:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/3703723#M507741</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-09-10T06:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE in the Cloud</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/4981792#M585808</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;Can anyone share a link for migrating CISCO ISE to Azure&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 20:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/4981792#M585808</guid>
      <dc:creator>yadulla hussainks</dc:creator>
      <dc:date>2023-12-19T20:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE in the Cloud</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/4981812#M585811</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/ISE_on_Cloud/b_ISEonCloud/m_ISEonAzureServices.html" target="_blank" rel="noopener"&gt;Deploy Cisco Identity Services Engine Natively on Cloud Platforms&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only 'migration' strategy would be to build the cluster in Azure, restore a backup from your on-prem ISE cluster, then re-configure your network devices to point to the new PSNs.&lt;/P&gt;
&lt;P&gt;You should also be aware of this issue with Azure. This default behaviour will break EAP-TLS, so you would need to have MS support enable the workaround.&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/996062/azure-drops-my-udp-fragmentated-packets-when-they" target="_blank"&gt;https://learn.microsoft.com/en-us/answers/questions/996062/azure-drops-my-udp-fragmentated-packets-when-they&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 21:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-in-the-cloud/m-p/4981812#M585811</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-12-19T21:53:39Z</dc:date>
    </item>
  </channel>
</rss>

