06-06-2019 02:52 AM - edited 02-21-2020 11:06 AM
Hi,
According to ISE architecture for a large deployment, each persona requires a dedicated node, and some services call for dedicated nodes also (eg. PassiveID PSNs) whilst other services can be shared with existing RADIUS PSNs (eg. TrustSec Policy downloads).
Given the above, in a large ISE deployment with dedicated nodes, is a dedicated SXP PSN pair required, or can SXP service run on an existing RADIUS PSN with low utilisation?
In this instance, the SXP service is only required for integrating with ACI for policy plane integration. Assume 15-20k ISE-SGT mappings total to be in ISE which consists of RADIUS sessions + ACI learnt mappings.
Thanks,
Denis
Solved! Go to Solution.
06-06-2019 08:43 AM
From a technical perspective it will run, but as you have already pointed to, you have to be mindful of the load. SXP is a pretty chatty protocol as updates are near real time so the load it generates really depends on four things. The number of IP-SGT mappings, number of SXP connections, type of SXP connections (unidirectional vs bidirectional), and the frequency of change. If you're only looking at a couple of SXP speaker connections, then I would spin it up on a couple existing PSN's.
Worst case you find load is too high and spin SXP out to a couple of 3515/3615's.
06-06-2019 08:43 AM
From a technical perspective it will run, but as you have already pointed to, you have to be mindful of the load. SXP is a pretty chatty protocol as updates are near real time so the load it generates really depends on four things. The number of IP-SGT mappings, number of SXP connections, type of SXP connections (unidirectional vs bidirectional), and the frequency of change. If you're only looking at a couple of SXP speaker connections, then I would spin it up on a couple existing PSN's.
Worst case you find load is too high and spin SXP out to a couple of 3515/3615's.
06-06-2019 07:33 PM - edited 06-06-2019 07:40 PM
Thanks for the response Damien :)
I also want to confirm whether this is an officially supported setup or not?
Pretty sure yes as the overarching persona (PSN) is dedicated as per large deployment guideline, and only the underlying PSN services (SXP, RADIUS etc) are shared, however want to be certain on this.
Cisco TME's,
Are you able to add any further comments to this?
06-07-2019 07:14 AM
Yes this would be supported as @Damien Miller stated please watch the performance of the nodes. . Also please look at the performance and scale page https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148 and also the resources link to BRKSEC-3432
06-10-2019 10:35 PM
Thanks Jason
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide