11-23-2017 02:52 AM
Dear ISE expert
I have a customer that can not go for distrubetd deployment because of latency issue.
He has some remote sites that can have up to 1000 users and is worried about having
all the users connecting within a short time and affecting bandwidth usage.
Please can you help identify the average bandwidth consumption for ISE AAA with posture and the average time it takes.
Many Tahnks
Babacar
11-23-2017 03:18 AM
I have posted BW/Latency guidance here: ISE Latency and Bandwidth Calculators
but specifically call out that the calculator does not cover bandwidth required for RADIUS or other services like Profiling and Posture since they are so variable depending on your config.
For example, each RADIUS transaction will be depend on EAP type, protocol selection, key sizes, and timers. Profiling will depend on probes enabled, and posture will depend on the checks performed, and more specifically the remediations configured. For example, it may be trivial to update a registry setting, but much more bandwidth to fetch AV signatures, and even more to download a Windows service pack, especially if no local remediation server or WAN caching not employed.
My general recommendation in these cases is to take what you believe to be a typical set of clients and then measure the load for that control set. You can then extrapolate against the larger community.
Often the bandwidth for RADIUS is not that high, but be sure to implement best practices for timers as called out in BRKSEC-3699 (find reference version of presentation @ ciscolive.com). By setting reasonable timers for interim accounting, reauth, etc, you will limit the noise. The session also calls out the need to set reasonable values for DHCP leases as there is an impact to profiling. Related to Posture, consider the type of assessments and remediation needed and where the remediation servers are located.
Craig
11-23-2017 04:23 AM
Many Thanks Craig.
BR
Babacar
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide