cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1362
Views
15
Helpful
4
Replies

2-Node ISE Deployment VM License

iagyte
Cisco Employee
Cisco Employee
Customer is migrating ACS functionality only. ISE requires Device Admin and Base licenses. From a VM perspective using a 2-Node ISE Deployment, how many VM's are required?

 

Node1: PAN-Primary, MnTSecondary, PSN
Node2: PAN-Secondary, MnT-Primary, PSN

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

2 nodes = 2 VMs and that requires 2 VM licenses.

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

2 nodes = 2 VMs and that requires 2 VM licenses.

In a 2-node deployment - for the PSN, does this work as ACT/ACT or ACT/PASSIVE?

Active/active.

 

Any active ISE node that has the the PSN persona enabled will actively service incoming endpoint requests.

Damien Miller
VIP Alumni
VIP Alumni
With ISE 2.4,

You will require 1 VM license per node, so in this case 2, they will be either R-ISE-VMS-K9= or R-ISE-VMM-K9 depending on if they require 3515 or 3595 capacity.

You will also require 1 TACACS node license for every VM you want processing TACACS requests. So I would recommend 2 x L-ISE-TACACS-ND=.

And then like in the past, you need 100 base licenses to enable TACACS. Here is a link to the ordering guide if you want the source.
https://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/guide_c07-656177.pdf
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: