<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Neno,Following are the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628030#M74679</link>
    <description>&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;Following are the answers to your questions:&lt;/P&gt;&lt;P&gt;1. maximum active users would be 3500 whereas the concurrent users will be maximum 1000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. sites are connected using MPLS where bandwidth is 256 + 512 mbps respectively.&lt;/P&gt;&lt;P&gt;3. Its around 30 - 40 ms.&lt;/P&gt;&lt;P&gt;Reagrds,&lt;/P&gt;&lt;P&gt;Manoj&lt;/P&gt;</description>
    <pubDate>Mon, 09 Feb 2015 04:08:29 GMT</pubDate>
    <dc:creator>Manoj Gupta</dc:creator>
    <dc:date>2015-02-09T04:08:29Z</dc:date>
    <item>
      <title>ISE Solution design questions?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628028#M74674</link>
      <description>&lt;P&gt;Is it possible to setup ISE in the following way:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3 Locations: Main campus, Site 1 (DR Site)&amp;nbsp;&amp;amp; Site2&lt;/P&gt;&lt;P&gt;4 ISE Appliances.&lt;/P&gt;&lt;P&gt;Main Campus: 2 Appliances:&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;Appliance 1: PAN(P) + MnT(P) + PSN (Just for fallback, Will be configured as Second Radius on all NAD's)&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;Appliance 2: PSN (Will be configured as First Radius server on&amp;nbsp;Main Campus&amp;nbsp;NAD's&lt;/P&gt;&lt;P&gt;Site 1 (DR Site): 1 Appliance&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;Appliance 1: PAN(S) + MnT(S) + PSN (First Radius server for local NADs,&amp;nbsp;Third Radius on all other NAD's)&lt;/P&gt;&lt;P&gt;Site&amp;nbsp;2: 1 Appliance&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;Appliance 1:&amp;nbsp;PSN (First Radius server for local NADs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to some constraints I am not able to test this setup in lab and when I look at the document, though not mentioned specifically theoretically it seems its possible to implement ISE in this way, any assistance comments or support is highly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628028#M74674</guid>
      <dc:creator>Manoj Gupta</dc:creator>
      <dc:date>2019-03-11T05:25:30Z</dc:date>
    </item>
    <item>
      <title>Before I can confirm if this</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628029#M74677</link>
      <description>&lt;P&gt;Before I can confirm if this design would work please answer the following questions:&lt;/P&gt;&lt;P&gt;- How many total active and concurrent endpoints do you plan to support&lt;/P&gt;&lt;P&gt;- What type of links are you using to interconnect all of the sites and what is the total (available) bandwidth&lt;/P&gt;&lt;P&gt;- What is the max round trip delay on the connections between the sites&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Feb 2015 23:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628029#M74677</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-08T23:09:34Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,Following are the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628030#M74679</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;Following are the answers to your questions:&lt;/P&gt;&lt;P&gt;1. maximum active users would be 3500 whereas the concurrent users will be maximum 1000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. sites are connected using MPLS where bandwidth is 256 + 512 mbps respectively.&lt;/P&gt;&lt;P&gt;3. Its around 30 - 40 ms.&lt;/P&gt;&lt;P&gt;Reagrds,&lt;/P&gt;&lt;P&gt;Manoj&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 04:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628030#M74679</guid>
      <dc:creator>Manoj Gupta</dc:creator>
      <dc:date>2015-02-09T04:08:29Z</dc:date>
    </item>
    <item>
      <title>Thank you for the info Manoj.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628031#M74681</link>
      <description>&lt;P&gt;Thank you for the info Manoj. Overall, your design is OK for the number of endpoints that you are planning on running. Ideally though, in a distributed deployment, you would dedicate 2 x ISE servers for the Admin/M&amp;amp;T personas and then 2 x ISE servers for the Policy Services personal. You can also make one of the nodes primary for Admin but backup for M&amp;amp;T and vice-versa for a better load distribution .So in your situation you could do:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Site A:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;ISE Server #1 - &lt;SPAN style="color:#FF0000;"&gt;&lt;STRONG&gt;Primary&lt;/STRONG&gt;&lt;/SPAN&gt; Admin and &lt;SPAN style="color:#008000;"&gt;&lt;STRONG&gt;Secondary&lt;/STRONG&gt;&lt;/SPAN&gt; M&amp;amp;T&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE Server #1 - &lt;SPAN style="color:#FF0000;"&gt;&lt;STRONG&gt;Primary&lt;/STRONG&gt;&lt;/SPAN&gt; PSN for Site A and &lt;SPAN style="color:#008000;"&gt;&lt;STRONG&gt;Secondary&lt;/STRONG&gt;&lt;/SPAN&gt; PSN for Site B&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Site B:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;ISE Server #1 -&amp;nbsp;&lt;SPAN style="color:#008000;"&gt;&lt;STRONG&gt;Secondary&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;Admin and&amp;nbsp;&lt;SPAN style="color:#FF0000;"&gt;&lt;STRONG&gt;Primary&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;M&amp;amp;T&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE Server #1 - &lt;STRONG&gt;&lt;SPAN style="color:#FF0000;"&gt;Primary&lt;/SPAN&gt;&lt;/STRONG&gt; PSN for Site B&amp;nbsp;and &lt;SPAN style="color:#008000;"&gt;&lt;STRONG&gt;Secondary&lt;/STRONG&gt;&lt;/SPAN&gt; PSN for Site A&lt;/P&gt;&lt;P&gt;Again, you won't have that many concurrent endpoints so you will be OK going with the design that you have outlined. However, if you want to follow the Cisco design guide and future proof your architecture then I would follow my suggestion &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Thank you for rating helpful posts!&lt;/I&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 04:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-solution-design-questions/m-p/2628031#M74681</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-09T04:20:51Z</dc:date>
    </item>
  </channel>
</rss>

