<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best way to design Cisco ISE roles in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366454#M599681</link>
    <description>&lt;P&gt;what you have is not bad, you should look at it not just from node persona distribution point of view but more holistically.&lt;/P&gt;
&lt;P&gt;There are some great presentations in Cisco live on demand library, just search for "&lt;SPAN&gt;Cisco ISE Best Practices"&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 31 Jan 2026 05:37:49 GMT</pubDate>
    <dc:creator>Ambuj M</dc:creator>
    <dc:date>2026-01-31T05:37:49Z</dc:date>
    <item>
      <title>What is the best way to design Cisco ISE roles</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366281#M599675</link>
      <description>&lt;P&gt;Hello. Could you please tell me how to do this better?&lt;/P&gt;&lt;P&gt;What is the best way to design Cisco ISE roles: keep Primary/Secondary PAN and MnT separated “crosswise” on different management nodes or combine Primary PAN and Primary MnT on a single node from an HA and best practices perspective?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 10:32:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366281#M599675</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2026-01-30T10:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to design Cisco ISE roles</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366282#M599676</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1739732"&gt;@nastiakhon&lt;/a&gt;&amp;nbsp;it all depends on the environment, number of concurrent connections, features, redundancy etc. At a minimum you should have two nodes, with redundant personas (PAN, MnT, PSN) - refer to the performance and scale guide &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 10:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366282#M599676</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-01-30T10:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to design Cisco ISE roles</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366289#M599677</link>
      <description>&lt;P&gt;Yes, I read this article, but I still can't make the right decision.&lt;BR /&gt;Attached is a screenshot of my deployed environment.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nastiakhon_0-1769771745721.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/258829i6A0203CF3CEB8106/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nastiakhon_0-1769771745721.png" alt="nastiakhon_0-1769771745721.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 11:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366289#M599677</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2026-01-30T11:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to design Cisco ISE roles</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366295#M599678</link>
      <description>&lt;P&gt;I'll add that we have an automatic fileover configured for pan nodes.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 11:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366295#M599678</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2026-01-30T11:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to design Cisco ISE roles</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366297#M599679</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1739732"&gt;@nastiakhon&lt;/a&gt;&amp;nbsp;looks like you've configured the ISE cluster as a medium sized, with PAN and MnT roles on the same hardware, that will suffice for cluster size up to 150K active sessions (depending on VM/hardware resources). So if you do not have a larger deploy that will be fine.&lt;/P&gt;
&lt;P&gt;If you were designing a very large ISE cluster, you'd have to configured PAN and MnT personas on different nodes to support the scalability.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 11:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366297#M599679</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-01-30T11:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to design Cisco ISE roles</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366408#M599680</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1739732"&gt;@nastiakhon&lt;/a&gt;&amp;nbsp;Using separate boxes for PAN &amp;amp; MNT roles should be done only when necessary, if scale requires it, otherwise its add complication with no benefits. Take a look at this document and make your decision based on scaling numbers, MEDIUM means PAN &amp;amp; MNT roles on same box, while LARGE means PAN &amp;amp; MNT roles on separate boxes:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2025/pdf/BRKSEC-3234.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2025/pdf/BRKSEC-3234.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 20:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366408#M599680</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-30T20:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to design Cisco ISE roles</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366454#M599681</link>
      <description>&lt;P&gt;what you have is not bad, you should look at it not just from node persona distribution point of view but more holistically.&lt;/P&gt;
&lt;P&gt;There are some great presentations in Cisco live on demand library, just search for "&lt;SPAN&gt;Cisco ISE Best Practices"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Jan 2026 05:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-best-way-to-design-cisco-ise-roles/m-p/5366454#M599681</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2026-01-31T05:37:49Z</dc:date>
    </item>
  </channel>
</rss>

